[Guide] avast! Proactive Protection

sorry…what do you mean containing type. that she did a copy and paste from a txt file to a trillian message? Did the warning stopped after you gave the ok? I don’t want to get too many pop outs when i chat. that’s why i’m asking. Sorry.

Isn’t just clicking the buttom Customize at left?
Did you click the buttom ‘Details’ in the first window of the avast! settings and you’re seeing all providers or not?

It was just a message like ‘goodnight, it’s late here’.

It was just a message like 'goodnight, it's late here'.

that’s strange. Well…I’ll guess I’ll see what will happen the next time i’ll use Trillian. Thanks

Well i don’t know why would Trillian need to write into any of the listed filetypes. They are all possibly malicious. Tell us what exactly says on the warning message or or simply make a screenshot of it.

Also please read the guide regarding Detailed view. It’s written there from the beginning, you just have to read it.

OCX blocking will block ActiveX stuff only at install point and will not obstruct it while using it. WIndows Update will work as usual once it’s installed.

Ok, Let’s try this again…

Hi RejZoR…

I’m missing something…do you have the Professional version?
On my “On-Access Scanner” window, I only have two choices for the sensitivity level, Normal and high. How do you get custom?

Best Regards…

It is there for all providers mentioned in this thread, however, if you don’t expand the information displayed you won’t see it.

Click on the Details… >> button to expand.

RejZoR,

For the Internet Mail provider proactive detections (regarding mass mailing worms specifically) you can also add additional ports to the avast4.ini file to cover other common e-mail ports.

Example:

[MailScanner]
PopRedirectPort=110,995
SmtpRedirectPort=25,587

I don’t know if there are any additional ports that would be useful to add or not, or if any worms can use encrypted ports or not but I just thought of this so decided to post it anyways just in case it could be of any use.

Very knowledgeable and professional directions, by the way.

Edit: I wonder if it is possible to add those additional ports through the GUI on the Redirect tab, as opposed to modifying the avast4.ini file?

Cheers,
Dave

If fact, it will be better to add them by the GUI.
To change some parts of the avast4.ini file, it’s necessary to stop the providers, make the changes, save the file, start the providers again.
On contrary, when you shutdown the computer, the non-changed settings at GUI will be saved over the avast4.ini file… :stuck_out_tongue:

For the Internet Mail provider proactive detections (regarding mass mailing worms specifically) you can also add additional ports to the avast4.ini file to cover other common e-mail ports.

Example:

[MailScanner]
PopRedirectPort=110,995
SmtpRedirectPort=25,587

A word of warning on this recommendation (and Tech’s very sensible suggestion that changes be made via the GUI).

If you are a user of a secure SMTP service - such as GMail using port 587 - then this recommendation will cause avast to prevent creation of a secure session. This recommendation should come with a warning that it be used by those not really trying to use the port.

Hi DavidR…

Ah, I see…got a little ahead of myself. Pardon my brusqueness earlier, just that I don’t post here to hear my head rattle. I have questions at times and like to help out others when I can too.

Thanks :slight_smile:

Hello! I did the customization but at start up Avast! gave me a warning with the same window you showed. It asked me to allow or block the writing of a file called ebd.chk by process wuaulct.exe.
Why? the file was in a microsoft windows folder. now i’m really tired of getting this warning. Is it a virus Avast didn’t detected before? What should I do?

Just a blooper trying to do too many things at once my apologies

Here is a link to a site that should help answer some of your questions?
Wuauclt.exe is a process managing automatic updates for Windows
Hope it helps

http://help.lockergnome.com/index.php?showtopic=30026

Sorry I post the wrong URL the first time oops

No problem! I googled for it and find out what exactly it is. So I wasn’t overly concerend. but those warnings were aggravating. I couldn’t rememeber the default settings so I jsut uninstalled and installed Avast again.
I think I’ll not mess with it in the future.

http://forum.campersheaven.de/images/newsmil/lol2.gif

no worries emy80 you just had to untick Standard Shield/Customise/Blocker/
Blocked Operations/Untick Open file for writing :wink:

Thats impossible. If you followed the guide you shouldn’t get that message. CHK extension is not even on the list!

I think the problem is that he didn’t uncheck default extension set. As I understand it must be unchecked otherwise you get a lot more warnings.

Yes, but people obviously don’t read. I even used images for that matter…

http://i14.photobucket.com/albums/a348/rejzor/block_set.png

Now select Blocker tab.

Set all settings the same as shown on screenshot above, except field under number 2. This will come in next few lines…

This is what i wrote in the guide on first page…

Well…there is a CH? in the default extension. My guess is that changing the Bloker action triggered that thing. I did an on-line scan with Trend Micro disabling the Standard Shield and the Web Shield.
First thing I got was a error message of Microsoft. I took a screenshot. Then the scan resulted clean. I just uninstalled and installed Avast again. i have the automatic update enabled so maybe that’s why. The wuaulct.exe was running under a svchost.exe process pertaining the Updates. I checked it with Process Explorer.
I don’t know why. I just decided to leave the default settings.

[edit] I’m really sorry. i guess I really didn’t unchecked the default setting. I’m realy sorry for this. I wasn’t saying that your guide is bad. i just guess, since i’m not an expert it’s better if i leave the default setting, so i’ll know for sure I haven’t damaged the program. I’m sorry.