free avast modules, which are you using?

Discussion in 'other anti-virus software' started by mantra, Jul 6, 2011.

Thread Status:
Not open for further replies.
  1. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    a placebo shield u clearly dont use and i assume have based ur opinions on other peoples reports when it was still passive, which it no longer is and def does work.
     
  2. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
    On my x64 W7 SP1 machine, I use AIS with web based email, also I never IM or P2P. I use Google Chrome sandboxed in AIS's manual sandbox 100% of the time. I despise gadgets and browser add-ons, so I axed WebRep and the desktop gadget thingy.............I only installed:

    Firewall
    File Shield
    Network Shield
    Behavior Shield
    Safe Browser
    Virtualization (manual sandbox)

    Due to my usage, I have no need for the IM, P2P, or Mail shields. The Script Shield doesn't work on my x64 machine and in fact, vlk has gone on the record and said that the Script Shield will be phased out soon: http://forum.avast.com/index.php?topic=81113.msg663063#msg663063

    I chose not to install the Web Shield because I only browse with my browser virtualized in AIS's sandbox. I found that the Web Shield slowed my page loading a little bit, so I axed it.
     
  3. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    it doesnt show much activity really, but it is working for me on x64 for programs like HP Update

    but i also dont really find the script shield that useful, tho i am curious to see what they replace it with.
     
  4. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Too broad, you need to be more specific. I'm comparing Web Shield and File System by the way.

    How am I wrong? The list of Packers are identical.

    You've completely forgotten the rest of my setup. I don't run untrusted installers without sending them online to VirusTotal, Comodo Instant Malware Analysis, and Comodo File Verdict Service. If that's not possible, I will scan them with all of my scanners, and even run them virtualized.
    Then again, you've been ignorant of my second sentence as well.
     
  5. i_g

    i_g Registered Member

    Joined:
    Aug 30, 2006
    Posts:
    133
    Well, you said that Web Shield and FileSystem Shield are duplicit and therefore unnecessary - and to me it sounded like a general advice, i.e. your particular setup, e.g. having an additional antivirus installed, doesn't seem relevant to me (as it may affect you, but probably not those asking about the avast! shields).

    The list of unpackers is identical, yes - but I'm talking about archives that avast! is unable to unpack. I don't know any particular format from memory right now, but there is definitely a number of less-widespread archives that are not covered.
    So, imagine you download a malicious tool created in "My Great Installer 1.0". WebShield cannot unpack that archive, so it only scans the outer shell of the file (i.e. the file itself, without unpacking its compressed content); it doesn't have any signature for that, so it doesn't detect anything.
    So, you run the installer and it unpacks itself to your disk, extracting the content (new files).
    Now, these new files might be detected by avast! (or possibly not, sure, but maybe so) - but they certainly will not be if FileSystem Shield is missing, because there is nobody to scan them.
     
  6. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I said very similar engines, and duplicate detections do exist.

    Which Panda, and all my other scanners may be able to. Then there's behaviour analysis. Also, I've never made that assumption.
     
  7. toxinon12345

    toxinon12345 Registered Member

    Joined:
    Sep 8, 2010
    Posts:
    1,200
    Location:
    Managua, Nicaragua
    It is able to block actions/events, but not a sequence of actions (a behavior)

    i would call it a HIPS
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.