Author Topic: C'mon, why not taking advantage of Behaviour Blocker ?  (Read 3519 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
C'mon, why not taking advantage of Behaviour Blocker ?
« on: April 09, 2006, 11:34:34 AM »
You got the engine there but you don't use it properly at all. :o
I mean it's really completelly useless, intrusive and far from what it suppose to do.
With just a small tweaking you could get very nice proactive protection but you simpy don't put any work into it :'(
I said this before and nothing was done, so i'll do it again in hope you'll realize this for version 4.8 or even before.

avast! should check what selected (or default ones) extensioned files DO, not what happens to THEM.
For example avast! now checks if lets say file SCR gets created, modified, deleted or renamed. But in fact it should check what SCR file does to the system. I mean it's not nearly common that SCR file creates other EXE files on hard disk.
Or VBS/BAT file deleting files located in system directory.
Or PIF files execution on Windiows XP/2000 systems. It's clearly a malware since no one uses this kind of stuff except for malware.

Now Behaviour Blocker warns you when SCR file is copied to HDD, but it should warn us not when SCR file is created on HDD but when SCR file tries to create new files on HDD. Screensavers don't do that...

You can maintain it with just few lines of rules on how behaviour blocker should act.
Back it up with nicer warning message (more like the ones used when virus is detected), exclusion system and updatability via VPS and you get an excellent stuff. Protection of critical registry entries could also be an option that i'd be glad to see.

You'll say that i'm nagging about this stuff just because i want to have heuristics/proactive protection but lets face it, engine is there, waiting to be twaked/improved but it hasn't moved anywhere since version 4.1 (don't know how it was before that). If done properly it could work nearly as good as Kaspersky's new Proactive Defense (which does pretty much the same thing).

But it's your choice...
Visit my webpage Angry Sheep Blog

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: C'mon, why not taking advantage of Behaviour Blocker ?
« Reply #1 on: April 09, 2006, 11:47:50 AM »
Of course, a new blocker is one of the highlights of avast 5.
If at first you don't succeed, then skydiving's not for you.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: C'mon, why not taking advantage of Behaviour Blocker ?
« Reply #2 on: April 09, 2006, 11:49:07 AM »
But avast! 5 is almost ~1 year away... :-\

Btw i was forced to use only extensions:
SCR,VBS,PIF,CPL,BAT,COM

in order for Behavious Blocker to be non intrusive and partially working with everything checked. These extensions are not suppose to be on my PC, thats why it works ok.
But checking dll,vxd and exe creates bunch of warnings that are in 99% cases completelly harmless.
« Last Edit: April 09, 2006, 11:52:12 AM by RejZoR »
Visit my webpage Angry Sheep Blog

John-

  • Guest
Re: C'mon, why not taking advantage of Behaviour Blocker ?
« Reply #3 on: April 09, 2006, 12:01:51 PM »
Hello,

I don't know if this is the right post to ask this question,...
BUT e.g. someone makes a .BAT file that says: Delete *.* files on drive c:\
What will Avast do?  -> I haven't enabled the option which prevents files from being deleted,.... in the resident shield!

I sometimes use a .bat file to make common tasks,...
But imagine this when someone wants to make a joke out of you,..and sets this code in the BAT file?


cheers
« Last Edit: January 23, 2016, 10:24:59 AM by EverlastingGaze »

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: C'mon, why not taking advantage of Behaviour Blocker ?
« Reply #4 on: April 09, 2006, 12:23:32 PM »
Well from what i've seen avast! won't do anything. But it will warnif YOU try to delete that BAT file. Thats why i complain so much because this is completelly unlogical and doesn't protect PC from being trshed but more protects malware from being deleted...
Visit my webpage Angry Sheep Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: C'mon, why not taking advantage of Behaviour Blocker ?
« Reply #5 on: April 09, 2006, 03:59:48 PM »
I've posted some other old features of avast that could (should) be improved here:
http://forum.avast.com/index.php?topic=20352
The best things in life are free.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: C'mon, why not taking advantage of Behaviour Blocker ?
« Reply #6 on: April 09, 2006, 04:11:30 PM »
Vlk, any chance to see at least "Silent Mode" for current blocker (Deny everything)?
This shouldn't present too much work would it?

I'm using "SCR,VBS,PIF,CPL,BAT,COM,CMD" at the momemnt and it appears to be fine, though you have to Deny everything manually. I can deal with that but i dubt that my sister will... Silent Mode would be nice (you'd just see that black and white popup above the taskbar and automatically blocked action.

I tried downloading EICAR.COM and it got blocked right away because it has COM extension (i guess the same will apply for all other extensions that are not used often in normal user environments). Quiet nice considering that default extensions are completely useless :)
Visit my webpage Angry Sheep Blog