Review - Biozfear's Custom Avast! Free approach

Would you try this custom approach and why?


  • Total voters
    4
Status
Not open for further replies.
P

Plexx

Thread author
Review is by no means targeted at the general users. Such custom settings were tweaked for the advanced user who knows what he/she is doing. Please bear this in mind.

For the purpose of this review (since it is a comparison with another custom approach), MBAM and EEK were updated on the same day as the mentioned approach (1st of July), then Avast was updated to latest version and signatures. Once updates were done, Cloud and automatic updates were disabled for a fair comparison. Links were tested on the 1st of July.

Custom settings: Refer to attachment screenshot and scan settings below. Note as well that the rest of the settings that are not on screenshot and text below are the same as the other custom approach.

Code:
Quick scan

Sensitivity | Medium heuristics, Scan for PUP, Follow links during scan
Packers | DOS, Win32, Droppers
Performance | Normal scan priority, Check "speed up scanning using persistent cache"
No Report files or Exclusions

Full system scan

Sensitivity | High heuristics, Use code emulation, Scan for PUP, Follow links during scan
Packers | All packers
Performance | High scan priority, Check "store data about scanned files in the persistent cache"
No Report files or Exclusions

Select folder to scan - (used for malware packs).

Scan | Scan all files
Sensitivity | High heuristics, Use Code Emulation, Scan for PUP, Follow links during scan
Packers | All packers
Performance | High scan priority, Uncheck the below options in Persistent cache
No Report files or Exclusions

Links (refer to attachment): Out of 19 links, 9 bypassed Web shield: plugnrex and jackpotcity. Note that jackpotcity is actually an online casino powered by Microgaming and is considered by most AV vendors as a PUP/PUA.

Malware packs:
collection of 66, 39 and 49 packs from MT. Unpacked and placed together: Total of 154 files
Detection:
123/154 - 79.87%

Note that the above scan used was Folder Scan.

Since I did not see any activity from File System Shield, I decided to go to disabled all shields apart from File System Shield and executed support_251.exe and 1726989408.isr 04.exe from malc0de which was dated 1st of July (not available in the original links). No reaction was observed with the 2 infections.

I then re-enabled all shields and from the leftovers, executed 20 of them in which 2 of them were Security Shield and Live Security Platinum fake AVs.
By the first infection, Security Shield, suddenly it stopped responding (which I suspect it was File System Shield doing. I then left Live Security Platinum fake av as the last sample and this time Avast didnt get 'killed'. Used rkill to kill the fake av processes and then did a full scan with Avast. Result was 9 files detected, but only 5 could be removed (including the PUP jackpotcity). Autoit script with decompressed bomb was the files that couldnt be removed by avast (no action available). This was the same exact scenario in the previous custom test but I forgot to mention the name, so apologies for this.

Restarted in safemode and ran MBAM. Finally started windows as normal and did a final scan with EEK.

[attachment=1602][attachment=1607]

Machine is now completely clean, apart from the need to manually uninstall all leftovers from Jackpotcity since Avast only deleted the main EXE.

Final verdict:

Once again a simple approach to maximize Avast's potential prior to version 6. Unfortunately the cleaning capabilities are somewhat to be desired and there should be an improvement. The file that bypassed the webshield from plugnrex was actually detected by Avast in full scan but I expected File System Shield to reach and it didn't. By the time a scan is done, system was already infected.

I expected File System Shield to interact more or at least do its job more than expected, but unfortunately it was not the case. Without sanbox and Behaviour shield enabled, File System Shield is not ran at it's full potential.

Based on all the above, my rating is 3 stars.

On the other approach, I did say:
It is to note that the upcoming review of the other custom settings will also be graded as 3 unless it surpasses the results of this review.

Unfortunately I did not see a huge difference, therefore my rating remains as 3 stars.

It is to note that Avast Free is still a great product, however to maximize its full potential, the user will have no choice but to use nearly all the shields, while Mail/IM/P2P shields can be fully optional. This leaves nearly no room for a good custom secure approach on it's own.

Note that this is only my opinion. Other users might have other opinions and I will respect that.
 

malwarekiller

New Member
Mar 30, 2012
688
First thing is,there are no other shields...so please the 0-day components [autosandbox]are only effective when all shields are installed...without behaviour shield and file shield both present..avast wont be able to run filerep and the SB...now can u please send the undetected files at virus@avast.com for analysis:D

Again,avast doesnt detect casino and games thingy [direct statement from avast HQ]

These type of tests are just garbage..file shield will detect threats normally in real time but u need to check of all packers and do some more tweaks in your case...and i saw the results i got the all shields and full protection...u are probably crippling avast with your absolute garbage...on those packs see my scores with avast...and they are almost perfect...u probably are mis-configuring or these detection results are due to lack of shields


try turning up the heuristics,enable code emulation,scan for PUP,uncheck follow links,check scan all packers in select folder scan and try scanning via select folder scan..does that find more malware?

I am just finishing things up with eset [same custom config as u] and it has almost bashed the computer like or worst than avast has done in your review. i will post it shortly:)
 
D

Deleted member 178

Thread author
malwarekiller said:
First thing is,there are no other shields...so please the 0-day components [autosandbox]are only effective when all shields are installed...without behaviour shield and file shield both present..avast wont be able to run filerep and the SB...

That is quite poor

Again,avast doesnt detect casino and games thingy [direct statement from avast HQ]

means a malware packed with these PUPs will bypass the shields?

These type of tests are just garbage..file shield will detect threats normally in real time but u need to check of all packers and do some more tweaks in your case...and i saw the results i got the all shields and full protection...u are probably crippling avast with your absolute garbage...on those packs see my scores with avast...and they are almost perfect...u probably are mis-configuring or these detection results are due to lack of shields

They don't want the AV, BB, SB modules, just the Web Shields, they want a kind of Panda URL Filter on steroid. what is wrong with that?

try turning up the heuristics,enable code emulation,scan for PUP,uncheck follow links,check scan all packers in select folder scan and try scanning via select folder scan..does that find more malware?

of course, it does, but again it is not the purpose of their test.

I am just finishing things up with eset [same custom config as u] and it has almost bashed the computer like or worst than avast has done in your review. i will post it shortly:)

i think this kind of setting is made to be run alongside another security solution, in case of Earth it run alongside the Win8 buit-in security.


Personally i will do this setup only if i will be unable to find a decent url filter/webshield, but With Emsi IS, i have it so i donr need... (just for answering the poll ^^)
 
P

Plexx

Thread author
This was a follow up to Earth's config.

Once again I ask you to look at the screenshots. PUP is enabled etc. Only thing that is different is I have checked follow links.

Next time, please read the review properly...

When you refer to Sandbox and behaviour shield, I posted this:
Unable to fully identify and maximize Avast's File System shield capabilities without Behaviour shield and Sandbox enabled.

Also, I have sanbox disabled since I do not like it.


Finally, if Avast wont do anything about Online Casinos, why it would detect as PUP?

Regardless, one word of advice: Read before posting.

It is fine if you post constructive feedback but your feedback is leaning towards personal opinion than anything. Please respect the forum etiquette and the users.

If you do not like such review, simply don't view it or don't comment.

Thanks
 

malwarekiller

New Member
Mar 30, 2012
688
yes if any malware or PUP is packed with the casino and games will be detected but casino game type riskwares wont be detected at all..and if u are taking them from malc0de most are riskwares and no malware see reply from milos: http://forum.avast.com/index.php?topic=99331.msg792025#msg792025

If u say the about 0-day thingy...yes SB and Filerep is related with the shields...thats how the product has been designed and it wont function without it...security is more embedded into your system u know...disturbing it may even junk your system.

yes u can run avast as second line of defense but the avast guys at the forum still say the second line of defense is still not made fully
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top