Author Topic: ashServ.exe need internet access?  (Read 9373 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: ashServ.exe need internet access?
« Reply #15 on: March 09, 2008, 09:56:46 PM »
What port does the mail scanner monitor?
The default ones are 110 (pop3, inbound), 25 (stmp, outbound), 143 (imap).
The best things in life are free.

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: ashServ.exe need internet access?
« Reply #16 on: March 09, 2008, 09:58:29 PM »
Port 25 (and port 110 for incoming).  Port 25 is the port that spambots use for sending outbound mail and they normally include their own SMTP component so it has nothing to do at all with whatever mail client you use (or whether you use a mail client at all).

nmaynan

  • Guest
Re: ashServ.exe need internet access?
« Reply #17 on: March 09, 2008, 10:17:19 PM »
The protection the mail scanner can give you is like this. If you get infected with an undetected spambot, it will send mail out on the port that the mail scanner monitors. The mail scanner icon will appear on the task bar. Now you will know that something is sending mail.

So I can pick up a spam bot in ways not related to using the email client things like Outlook?

To get this protection, just activate the Internet Mail module or do I need to activate the outlook module too?

You only have to look at the forums to find many occurrences of people whose computer is sending out spam.


So not only should you enable the Internet Mail provider you should set its sensitivity to High. As oldman said you don't need to enable outlook/exchange.

Should I set Standard shield, network shield, and web shield to HIGH also? I've been keeping them at Standard setting because i read somewhere that High can impact system performance or something of that nature.
« Last Edit: March 09, 2008, 10:18:59 PM by nmaynan »

nmaynan

  • Guest
Re: ashServ.exe need internet access?
« Reply #18 on: March 09, 2008, 10:21:01 PM »
What port does the mail scanner monitor?
The default ones are 110 (pop3, inbound), 25 (stmp, outbound), 143 (imap).

now wouldn't a firewall with Outbound protection alert me to if things are occurring on these ports? (I'm just trying to learn all I can about this stuff). Or does the Internet Mail module do something the firewall can't do for me?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: ashServ.exe need internet access?
« Reply #19 on: March 09, 2008, 10:30:37 PM »
now wouldn't a firewall with Outbound protection alert me to if things are occurring on these ports?
A good firewall well configurated with outbound monitoring (not Windows one).
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: ashServ.exe need internet access?
« Reply #20 on: March 09, 2008, 10:33:50 PM »
Leave the Standard Shield on Normal, that gives the best compromise between protection and performance. The sensitivity setting on the Network Shield has no effect (aesthetics so the providers have the same look) as it has only one task to do and no different level of scanning.

A firewall might alert you depending on what one you have, but the avast scan would be happening before it get to your firewall, providing another layer in your defence (avast scans in localhost proxy before sending any email, so if it is intercepting spam it isn't being sent).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: ashServ.exe need internet access?
« Reply #21 on: March 09, 2008, 10:37:02 PM »
In your case - not using a mail client at all - the outbound notification/blocking offered by a firewall would be enough. 

However, less knowledgeable folks are often fooled by requests for outbound access by such process names as explorer.exe and svchost.exe which are the processes often compromised by spambots.  In these circumstances, when outbound permission has been granted at the firewall, the Internet Mail provider will still report the excessive mail sending performed by the spambot.       

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: ashServ.exe need internet access?
« Reply #22 on: March 09, 2008, 10:45:13 PM »
I should qualify my last post ...

The most common recent spambots we have seen here are those that have compromised the space of svchost.exe.  That Windows process does have valid cause for outbound access (though not to port 25).  So the outbound firewall would need to provide the discrimination of not just outbound access but outbound access by port to completely avoid the kind of successful infections we have seen.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: ashServ.exe need internet access?
« Reply #23 on: March 09, 2008, 10:47:08 PM »
In other words... Internet Mail provider could help and make things easier...
The best things in life are free.

nmaynan

  • Guest
Re: ashServ.exe need internet access?
« Reply #24 on: March 09, 2008, 11:30:57 PM »
In your case - not using a mail client at all - the outbound notification/blocking offered by a firewall would be enough. 

However, less knowledgeable folks are often fooled by requests for outbound access by such process names as explorer.exe and svchost.exe which are the processes often compromised by spambots.  In these circumstances, when outbound permission has been granted at the firewall, the Internet Mail provider will still report the excessive mail sending performed by the spambot.       

Thank you so much guys  ;D

Currently I have my firewall set to only allow svchost for UDP 53, 67, 123 Out. And UDP 68, 123 IN. I block Explorer entirely because I don't use Help and Support etc. So coupled with the fact that I do not use a mail client, it sounds like I have nothing to worry about. However, some extra protection prolly won't hurt. And I've learned so much from our discussion. I can help others who use mail clients iwith their Avast configurations.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: ashServ.exe need internet access?
« Reply #25 on: March 10, 2008, 01:06:48 AM »
No problem.

A belated welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security