For the time being anyway the behaviour shield will be running in passive mode, so making any change as far as I’m concerned could be a moot point. If you are part of the avast community then that data will be sent to avast, the idea being so that they can gather information and tweak the filters/rules to prevent poor detections.
If you took part in the beta trial you would have seen that many who change it to Ask suffered many problems (system freeze), as some of the detections/decisions could be happening early in the windows boot. Whilst this issue was largely resolved in the beta testing, personally I really don’t want to be potentially interrupting the boot and suffer any problem at all.
I also don’t believe you should go tweaking avast within an inch of its life and find you have gone an inch too far until you have got more used to the program settings as they are in the default. I fee the avast developers are much cleverer than I in these matters, so I tend to leave the default settings unless I know exactly what any change is going to do.
Unfortunately not, even in the avast Help Center, there is this basic information posted by one Avast Team:
avast! Behaviour Shield, general information from an interview Softpedia - Ondrej Vlcek
[b]Ondrej Vlcek:[/b] The Behaviour Shield that we shipped in version 5.0 is a new component that is going to be further developed moving forward. For example, in version 5.1, we will be adding more sensors that will allow for even finer-grain filtering.
For now, the Behavior Shield is focused on exploits coming via typical mechanisms (browser, PDF reader, and flash vulnerabilities, for example). It also closely monitors all kernel-mode code (drivers) loaded into the operating system, and is able to detect zero-day rootkits.
There may well be some more snippets in the forums, but there is no collated information on it.
“What may be of special interest, also, is that this is how it’s going to work even in the free version (which means that the core functionality of the sandbox will likely be moved to the free AV).”
I also qualified that point, that this was during the beta trials. What I do is monitor the BehaviourShield.txt file that contains what would probably be the same applications as if you had set it to Ask.
C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\report\BehaviourShield.txt (for XP)
Then I add these applications into the Behaviour Shield, Expert Settings, Trusted processes section. Once that is one they shouldn’t feature in the report again.