[Guide] avast! Proactive Protection

Now as you might already notice i’m a great fan of proactive protection.
Proactive protection is undeniably a good thing. avast! is no exception to a certain level. Some features are disabled by default and some are not designed that well.
But in general this guide should increase security level by few % if not more :slight_smile:

This guide is recommended only for advanced users that know stuff mentioned here and what it does.

Please note that this guide is meant only for Windows XP and Windows 2000 (all editions supported by avast!). Please do not use these settings on Windows 98 or Windows Millenium systems since they won’t work as expected!

Switching to “Detailed Mode”

http://i14.photobucket.com/albums/a348/rejzor/normalprov.png

Left click on avast! tray icon (that spinning blue “a” icon near the clock).
In case if you haven’t already switched to “More detailed mode”…

Behavior Blocker Proactive protection

http://i14.photobucket.com/albums/a348/rejzor/stdshield.png

Select Standard Shield and click Customize button on the right.

http://i14.photobucket.com/albums/a348/rejzor/block_set.png

Now select Blocker tab.

Set all settings the same as shown on screenshot above, except field under number 2. This will come in next few lines…

Add entire line below into field number 2 (Additional Extensions):
SCR,VBS,VBE,WSH,PIF,CPL,BAT,COM,CMD,WMF,OCX

Extensions list is dated 2006.04.10

It is partially visible on screenshot how it should look like when entered in there.
These extensions are meant for regular user environments where you most probably won’t encounter or run such filetypes (which are all possibly dangerous).
If you work with VBS scripts day by day you may want to remove VBS extension from the list. Same applies for other. In general it should provide nice balance between protection and number of warnings.

When you’ll get warning about such possibly dangerous file you’ll get such message:

http://i14.photobucket.com/albums/a348/rejzor/blocker_test.png

This way you’ll be notified about possibly dangerous file being created on your hard drive. It will also detect whether these filetypes try to format your hard disk. By clicking “Deny” button you’ll stop the creation of that file/formatting. Clicking Allow will allow it’s creation/formatting. Best option for most would be Deny.

Web Shield Proactive protection

http://i14.photobucket.com/albums/a348/rejzor/webshldpro.png

Select Web Shield provider and click Customize….
Then select URL Blocking tab.

http://i14.photobucket.com/albums/a348/rejzor/webshldext.png

Check Enable URL Blocking and click Add button on the right.
Add following strings into the list, each in it’s own line (same way like shown below).

Extensions:
*.cmd
*.cpl
*.pif
*.scr
*.vbe
*.vbs
*.wmf
*.wsh

Extensions list is dated 2006.04.09

So when you’ll encounter such possibly dangerous files you’ll get similar warning inside your browser…

http://i14.photobucket.com/albums/a348/rejzor/webtest.png

In case it’s not blocked by Web Shield, there is very big chance that Behavior Blocker will block it.

Internet Mail Proactive protection

Now this last one is a bit special, so please be VERY specific about which way you’ll select. It’s very important!

I’m using POP3/IMAP based email client (like Outlook Express or Thunderbird)
So if you use POP3/IMAP based email client like Outlook Express or maybe Thunderbird you should leave things as they are. Even if you use just 1 POP3 email account and 5 others that are just webmails (to view with browser).
Just move the slider to High as shown on picture. Existing heuristics will take care for suspicious attachements and mails.

http://i14.photobucket.com/albums/a348/rejzor/intmail.png

I’m NOT using POP3/IMAP based email client (just webmail like Hotmail, Yahoo or GMail inside my browser)
In case if you DON’T use ANY POP3 mail at all, then you may still want to install Internet Mail provider.
It will most probably spot suspicious activities of mass mail worms that attempt to send large amounts of emails in small timeframe without user knowledge.
avast! will show Heuristics warning with option to Deny these activities.
This way you’ll also be notified about malware that slipped past avast! signature detection and Behavior Blocker/Web Shield.

Select Internet Mail provider and click Customize… button on the right side. Scroll through tabs all the way to the right and select Heuristics tab.

http://i14.photobucket.com/albums/a348/rejzor/heur1.png

Select Custom preset as shown on image.

Now select next tab named Heuristics - Advanced and set marked settings as shown on image below.

http://i14.photobucket.com/albums/a348/rejzor/heur2.png

This will set Internet Mail provider to very high sensitivity level. Setting such settings in case if you’re using any POP3 email client will most probably result in large amounts of warning messages! Make sure you selected the right way as described above!

NOTE: I currently don’t have image of Internet Mail heuristics warning, but will add it as soon as i find one.

Additional help

In case you don’t understand something or you might have a question about anything related with my Proactive settings, please ask here in this thread.
I’ll try to do my best to help anyone. Alwil tech support team is already very busy with other things so we shouldn’t bother them with these things as they are my unofficial tweak settings.

I hope these settings will serve you well in upcoming avast! adventures in world of internet! 8)

RejZoR

PS: Is there any chance someone would make this thread as Sticky?


Thanks for those setting, RejZor. :slight_smile: I am sure those will help many.

I only use web-based email and before now had the settings on high for much the same reasons as you state here. Now, I have increased this with your custom settings as they make sense in quick detection of some spambot should one ever make it into my system. I have always had Internet Mail provider running for this reason.


Exactly, default settings are quiet relaxed because they are meant to be used with POP3 clients. These my settings are super sensitive and will spot any kind of outbound mail sending right away.

RejZor… I have a question. :slight_smile:

I use Outlook Xpress for my email.
I have it pull my mail (which can also be accessed thru the Isp’s website)

but I also have it pull mail from a Gmail account.

Which option would I choose? ???

edit: fixed stupid typos

If you use ANY kind of POP3 based email client then use the first one (just move the slider to High). You should also use first method if you use POP3 and webmail.
As long as you use any kind of POP3, even if just for 1 POP3 mail account and 5 webmail based, you have to go with first mode.

Updated the Internet mail part to be more clear. Hope it’s better marked now :slight_smile:

I note that the default settings in Blocker in Standard Shield (at least in mine) are not to tick any of the four boxes in ‘blocked opearions’. Does that mean Blocker is not active? Sorry if this is a silly question, but I didn’t look at some of the options before until I read your posts here.

Yes, if you UNCHECK all checkboxes in Blocker page you will DISABLE Behaviour Blocker. Checking just one of them will enable it with certain degree of protection.
Formatting protection is hovever the most non intrusive setting and should always be checked.

Great Guide RejZoR thank you
Hope Alwil make this thread Sticky

RejZoR,

thanks for this interesting and valuable thread (I would vote for it being made sticky - but what value my vote?).

In response to a recent thread that highlighted the unfortunate vulnerabillity of non-scanning of http imports by the rendering of html in email clients I switched on power mode with AEC.

After reading this thread I also implemented the recommendation (as a POP3 user) to set the sensitivity of the Internet Mail scanner to high.

I then followed up with sending some relatively large attachments (6-8Mb) through my Hotmail account using a POP3<>WebDav converter (that had no problems prior to the changes I mentioned). In this case the mail is being scanned by avast outbound and the port 80 traffic to Hotmail is also being scanned. Anyway the net result was consistent transmission failure on repeated attempts. I need to do so more testing to confirm, but it appears to me that the transmission is successful only if the mail scanner sensitivity is left at medium.

I just report this in case any others experience similar issues … if I find anything definitive I will report back.

I hope that the Awill staff will include the rules for the Standard and the Webshield in the new version of avast!.
Of course it’s not difficult to add them manually, but it’ll provide some nice extra protection out-of-the-box. With a whole load of rules, it might can get a little like Panda’s TruePrevent. Or am I wrong?

This thread will soon end up into oblivion… and if RejZoR needs to post some new extension list entries we all would like to see them and be informed as soon as he posts them… so…

Alwil, please make this thread sticky. It doesn’t cost anything :wink:

@RejZoR - thanks for all the effort ! :wink: :: thumbs up ::

I’ve emailed Support to confirm our request that this excellent thread be made a ‘sticky’.

Thanks RejZoR.

If I add *.ocx and *.cab (related to ActiveX) to the URL Blocking so will it provide any proactive protection against some ActiveX-based adware/spyware?

Yes, adding OCX also works. I’ve tested with Creative AutoUpdate and OCX file was intercepted. Web Shield however did not block it.

I think it’s enough if you use it just in Behavior Blocker.

I’ve also updated the blocker extension list (now includes OCX extension)!

About OCX extension, won’t it block Windows Updates?

Ok I enabled the default Blocker and ticked the 1st and 4th options. Amusingly, the first Trillian message that I received from a buddy got a Writing alert! I allowed it and it was just a straightforward message in text format, hardly needing to be blocked. Does that not sound strange?

Hi RejZoR…

I’m missing something…do you have the Professional version?
On my “On-Access Scanner” window, I only have two choices for the sensitivity level, Normal and high. How do you get custom?

Best Regards…

hi! since I use Trillian as well, what does it meas? That everytime you recive a message you’ll get a warning? Or was that an attached txt file you friends was sending you? Thanks

It was just an ordinary message containing type, nothing else; that’s why the alert seemed so strange. Unfortunately I failed to screenshot it before I allowed it :o My messager was a girl I wouldn’t keep waiting :slight_smile: