Author Topic: [Guide] avast! Proactive Protection  (Read 38033 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: [Guide] avast! Proactive Protection
« Reply #45 on: April 11, 2006, 10:41:08 PM »
Like which one? VBS scripts? PIF shortcuts on 2k/XP systems? Maybe WMF files?
How often do you think regular users use CMD or COM files? OCX are those badass ActiveX controls that everyone fear.

Blocker won't affect those that are already on HDD. I'm working with such stuff more since i work with AVs nearly all my time and i haven't got a single warning. Ok, i lied.
I got one about VBS file in some modified NVIDIA drivers (DHzer0Point, some color correction script which i allowed and it worked fine after that).

You should also fix the Default extensions list checkbox in Blocker. Some user reported that it gets checked by itself when you run Simple interface. Still need to verify that...
Visit my webpage Angry Sheep Blog

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: [Guide] avast! Proactive Protection
« Reply #46 on: April 12, 2006, 12:24:39 AM »
Quote
Like which one? VBS scripts? PIF shortcuts on 2k/XP systems? Maybe WMF files?
How often do you think regular users use CMD or COM files? OCX are those badass ActiveX controls that everyone fear.


Any of those. When installing an application, you must not prevent it from writing any of its files. When you do so, the results are pretty much undefined.

E.g. *many* Microsoft apps use VBS, CMD and OCX files internally.


Blocker with Silent mode is especially deadly combination. Coz it can block those files right away, and you can only watch... :)


If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: [Guide] avast! Proactive Protection
« Reply #47 on: April 12, 2006, 03:03:40 AM »
Any of those. When installing an application, you must not prevent it from writing any of its files. When you do so, the results are pretty much undefined. E.g. *many* Microsoft apps use VBS, CMD and OCX files internally.
I received some alerts when installing software but I answered 'yes' and everything goes fine.
In normal computer utilization, no alerts...

Blocker with Silent mode is especially deadly combination. Coz it can block those files right away, and you can only watch... :)
Fully agree with Vlk. I've tested an installation and it messed everything. Seems like PrevX, Process Guard or SSM blocking whatever in your computer to do anything... This is the only setting I will not make in anyway: block in silent mode.
The best things in life are free.

tsilo

  • Guest
Re: [Guide] avast! Proactive Protection
« Reply #48 on: June 16, 2007, 09:57:43 PM »
I was searching in this forum for Avast! optimal settings or something like that and found this thread, I know  big time passed nowone posted here, but I think this thread must be sticked.
I think there must be sticked such thread for users, who want set setting of Avast! such way. If last year something changed in Avast! settings  author can update or edit this thread :)
What do you think about it?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: [Guide] avast! Proactive Protection
« Reply #49 on: June 17, 2007, 12:27:52 AM »
What do you think about it?
There are better HIPS applications to be used... Behavior Block is not one of them... too noisy if you want protection. Users start to be bored and allow everything... no effective protection. More intelligent HIPS tools do it better, imho.
The best things in life are free.

Offline BJ_GeOrgE

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 350
  • prevention is better than cure
Re: [Guide] avast! Proactive Protection
« Reply #50 on: June 17, 2007, 05:16:44 PM »
rejzor,thnx for this great topic..i have a question,in the "blocker" settings,do i have to uncheck the box "default extension set" coz in the screeinshot the box is unchecked..thnx in advance.. :D


oops...i read the replies 3min after i sent the reply..i'm rly sry guys..dont count this question.. :D
« Last Edit: June 17, 2007, 05:30:21 PM by BJ_GeOrgE »
OS:Windows 7 Professional 64-bit SP1
Antivirus: Avast Free v8.0.1497/Firewall: Windows Firewall/On Demand: Malwarebytes Free Edition/Other tools: CCleaner