- Dec 27, 2016
- 1,480
Beautiful configurations already shared above. Let me share my settings on home PC as well.
I've my own reasons to allow or avoid 'test all files', 'follow links', 'test whole files' etc. in different scan modes. It will definitely vary by user requirements and scenarios.
General -
Web Shield
I've my own reasons to allow or avoid 'test all files', 'follow links', 'test whole files' etc. in different scan modes. It will definitely vary by user requirements and scenarios.
General -
- Reputation Services
- CyberCapture (allow me to decide)
- Hardened Mode (moderate)
- scan for PUPs
- Need NOT have 'Aggressive Hardened mode' with VDS and SmadAV (anti-exe, AV for USB)
- Action for all detections in any mode: ASK (except for malicious websites)
- Always scan by content (not by extension) (except for Full Scan)
- Scan all files
- Use code emulation
- Test whole files
- Follow links during scan
Special Scan > Explorer Scan
- Scan all files (all types)
- Test whole files
- Follow links during scan
- Extract all packers
- Scan all files (I try to make Quick Scans thorough and less quicker)
- Use code emulation
- Follow links during scan
- Extract Packers (only famous extensions)
- (unchecked) scan all files
- recognize by content
- (unchecked) test whole files
- extract packers (only famous extensions)
- Scan all files (I scan folders mainly if I need to execute some files, need a clean chit before)
- Use code emulation
- Follow links during scan
- All packers
- Scan > recognize by content (cannot trust extension manipulations)..
- Scan all files
- extract packers (only famous extensions)
- Use code emulation
- Test whole files
- (Additional) Warn when downloading files with poor reputation (large Avast community = large DB)
- Scan all files
- DO NOT test whole files (default)
- Scan for PUPs
- Use separate settings for Public (ask), Private (auto-decide) network
- Show notifications about newly created (any) rules
- some custom system rules
- log all blocked packets (difficult but helpful for analysing)
- Assign memory/CPU/time restrictions for unsigned sandboxed processes (I've tested a rogueware that made my VM crawl at 100% CPU usage even in sandbox, hence this rule)
- (occasional) Drop administrative rights of apps