I'm not that impressed. If they'd put 5% effort into Behavior Shield and making it even function at all, we'd be looking at 99,99% figures since the release of v5. But instead it's just a waste of shield space for 3 major versions because it does NOTHING to the end user. Tested it yesterday (for the 20th time this year), installed only Behavior Shield, left only rootkit and malware-like behavior enabled to avoid excess blocking of every random protected thing and set it to block. Executed like 50 samples of known malware. Not a single thing was even analyzed, let alone being blocked. Which means avast! 7 doesn't have any malware-like behavior rules. At all.
I don't even know why does it have a name Behavior Shield. It should be called "Just some scanning shield with no real purpose". Because that's what it is. And as much as i like avast! and how much i've been supporting it for the last years, this is really pissing me off. Every other vendor that introduced behavior blocker in their program also showed off some excellent results (i've tested them myself as well. But avast!, nothing for the last 3 years, since the v5 when we got the Behavior Shield. This module should have been hidden from the day 1 because it is apparently designed to only monitor things but is instead giving users a false sense of security (knowing how behavior blockers are effective in general). One of the biggest disappointments with avast! in years really and it still keeps on disappointing me. And frankly i'm not really sure what was avast! team thinking when they designed this module. I just can't understand their logic...
Only thing that's really holding avast! afloat is cloud (file reputation) and Auto Sandbox. Where Auto Sandbox is again like Behavior Shield just a dumb module that just sandboxes stuff for 15 seconds and terminates them without any verdict at all even though interface suggests it will maybe sometimes give some verdict. But it never does. I'd understand not giving a verdict for some stuff because it just can't make one, but not giving any verdict in all my tests ever since v7 was released (and trust me i tossed loads of malware at it), nothing.