Exlusions on CyberCapture for entire folder?

Hello,

Is it possible to exclude whole folders, including subfolders from being sandboxed with CyberCapture?
I tried and it still sandboxes executables in that folder. These folders being my software development folders it hinders (.NET) development. :frowning:

Thanks

– Ytrog

As you’re a developer, read here:

https://www.avast.com/faq.php?article=AVKB229
https://www.avast.com/faq.php?article=AVKB228

Those links don’t really help if you don’t want to get sandboxed right in the debugger as is happening to me. The problem is that I launch my program from Visual Studio and it gets sandboxed.

Well, either disable CC or set exclusions.

Which I did. I excluded the folders my Visual Studio projects are in. It didn’t work.

Disabling the entire feature was what I did when I first encountered the problem. ::slight_smile:

  • Which Avast…? (Free/Pro/IS/Premier)
  • Which version…?
  • OS…? (32/64 Bit…? - which SP/Build…?)
  • Other security related software installed…?

Avast Free Antivirus
Version: 17.2.2288 (build 17.2.3419.64)
OS: Windows 7 Enterprise, 64 bit, SP 1 (strange, I have updates on)
Other security (non-standard): EMET 5.52.6156.38091

Update to the latest version (17.3.2291): https://forum.avast.com/index.php?topic=199715.0

Aren’t we talking about Behavior Shield instead of CyberCapture?
CC only manages PE executables downloaded from web.

I had been thinking this, it could be the Behaviour Shield as the CyberCapture function as far as I can remember is to stop a file from running put a block on it, send the sample to avast for deeper analysis.

Whereas the Behaviour Shield can send it to the virus chest in 2 of 3 options.

It was a blue border around my console program having the title “CyberCapture”. See screenshot. I made this after updating to 17.3.2291

That is certainly somewhat strange, as Lisandro mentioned, we thought that the CyberCapture function only dealt with executables downloaded from the internet. Whilst we understood that this restriction to only that would be expanded at some point, but I hadn’t seen anything to say that its scope had changed.

This is certainly the first that I have seen outside of executables downloaded from the internet.

This needs feedback from avast developers.

I make mine these David words. Anyway, have you uploaded the executables and then downloaded them to use?

I have reported the topic to see if we can get some clarity.

Reply from the devs: He needs to make sure that he has * at the end of the path to ensure the exclusion works such that if I want to exclude all files in D:\test I need to add exclusion as D:\test*

So this I take it is also confirmation that the CyberCapture function doesn’t only dealt with executables downloaded from the internet and has been expanded ?

If so it would be nice to know its scope now, what files and areas are covered ?

DR: First of all it is not CyberCapture, but DeepScreen (sandbox)

Pretty damn confusing then having the “CyberCapture” Blue tab at the top of the window.

I’ve got the following official clarification:

Deepscreen (sandbox) is now also called CyberCapture (it's displayed in the blue border around scanned app's windows). It's because both DeepScreen and CyberCapture are enabled/disabled by the same checkbox in the UI. So the user's issue is that the files are getting into Deepscreen rather than CyberCapture.

Thanks for that.

Should we also be changing the DeepScreen reference in the avastUI > Settings > Exclusions and calling it CyberCapture to avoid confusion.

Also we still don’t have clarification on the expansion of CyberCapture scans as it would appear it doesn’t only dealt with executables downloaded from the internet and has been expanded.

It would be nice to know its scope now, what files and areas are covered ?