Unsolved
This post is more than 5 years old
5 Journeyman
•
15.6K Posts
•
45K Points
0
77049
January 21st, 2010 12:00
My first experience with Avast! 5
Well, curiosity got the best of me, and so I "bit-the-bullet" and upgraded to avast 5 (from 4.8).
My System specs: Windows XP SP3
Reasonable Precautions: I backed up some personal files (my income tax return that I'm currently preparing, and my Microsoft Money files) that I wouldn't want to have to recreate from scratch.
Paranoid Precautions: I downloaded a copy of the (older) Avast 4.8 setup engine
http://www.avast.com/free-antivirus-download#tab4 (choose your language),
and avast 4.8 removal tool http://www.avast.com/en-gb/uninstall-utility
just in case of total disaster (i.e., the need to revert to 4.8).
Better to be prepared than sorry!
(Addendum: for the avast 5 removal tool, should you want/need it, see http://forum.avast.com/index.php?topic=54385.0 )
Avast's Quick-Start Guide (for reference, including detailed installation instructions) can be downloaded from
http://www.avast.com/documentation/quick-start-guide-free-en-ww.pdf
Download the new Avast 5 (Version 5.0.377) - 38.29 Meg, from
http://www.avast.com/lp-upgrade-4-5
(which, at present, takes you to CNET Downloads).
Resident Protection: I have, and decided to keep running, SpyBot’s TeaTimer, Microsoft’s Windows Defender, and WinPatrol. I realized doing so might bombard me with prompts to allow/accept system changes. For those who wish to take a simpler (/ safer) approach, you might consider temporarily disabling any resident defenses that might “impede” avast’s installation.
Go offline: I turned-off my wireless adapter card, so as to insure my system would be offline --- and therefore, protected --- even as avast was automatically uninstalling the older version 4.8
The Installation process: I clicked to run the Setup Engine. (Note: I’m using XP. I presume that Vista and Win7 users should opt to Run as Administrator ???)
I accepted the Open File – Security Warning, and chose to RUN the Setup Engine.
(I received a query about avast 4’s removal, from TeaTimer, which I permitted).
UNLIKE the indication in the Quick-Start Guide, there was no choice of language offered. I presume this means I downloaded an English-only installer.
The first option offered was to participate in the avast community, “to anonymously forward some security-related information to avast (on an as-needed basis)”. This box was pre-checked, I accepted it, and clicked on NEXT.
I was then offered the option to install Google Chrome (an alternative browser). Avast “recommends” this --- but it is not required. To avast’s credit, neither the YES nor NO box was pre-checked! So the user must explicitly opt-in or opt-out here. I opted-out (chose NO), and clicked NEXT.
The installer created a System Restore point, and then installed avast 5.
[I received one query about avast 5 from TeaTimer, one from Windows Defender, one from WinPatrol, and one from my Comodo (2.4) firewall, all of which I allowed. ]
A new, ORANGE avast icon was placed on my desktop. [This is not a critical icon, as you will eventually be able to access the same feature from your system tray, or from your START menu. I eventually deleted this desktop icon, after rebooting].
At this point the installation was complete, and it was strongly suggested I reboot. (Wish me luck)
The first reboot: I anxiously kept my fingers crossed as the system was rebooting. All seems to have gone well.
I received several prompts (permission requests) from my Comodo firewall… but that’s certainly to be expected.
[While on the matter of my firewall, I discovered that it still was showing several permissions for the older Avast 4 components. I decided to manually remove them all.]
The old 4.8 BLUE ball in the system tray has been replaced by a new ORANGE one for 5.0.
I then received my first virus database update. Avast 5 spoke to me in a higher/woman’s voice, rather than the lower/male’s voice of version 4.
Checking in WinPatrol, I see that Avast 5 added one startup program AvastUI.exe (User Interface), which presumably places the orange ball in the system tray; and one startup service AvastSvc.exe, which “Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler”.
Following in the order of the Quick Setup Guide, I checked my registration (Right-click on the Orange A-ball, select registration information) to confirm that avast 5 had carried-over my registration from avast 4. [For first-time users, you can register (for free) online.] You will need to re-register avast every 12 months.
You can open the avast user interface (“program”) by LEFT-clicking on the orange avast ball in your system tray [or RIGHT-clicking on it, and selecting Open avast! user interface]. A minor difference here (from version 4.8) is that avast 5 seems to remember (and open) the last interface screen you had viewed (rather than starting with any “main” screen).
The Quick-Start Guide instructions, pages 9-10, are very informative for showing details. Being straight-forward, I will not repeat them here. But I do recommend you read and “feel these out” for yourself.
Concerning the various “shields”, and their automated activity/response, the default when a virus/PUP/suspicious file is encountered, is first try to Move it To the Chest… if that fails, try to delete it… and if that also fails, to take no (further) action. Realizing that an extreme false positive could have detrimental effects --- and since I know I personally won’t panic at a “virus” alert, and will investigate it further to make my own determination, I opted to change these to first ASK me, and if that “fails” then place the file in the Chest. I believe these choices are safer, provided one is willing to do the necessary research. For those who wish, these changes can be made by clicking on REAL-TIME SHIELDS, selecting one (e.g., the File System Shield), click on EXPERT settings, the ACTIONS tab, and choosing (based on my example) first ASK, then MOVE TO CHEST. You’ll need to do this three-times (per shield): for VIRUS, for PUP, and for SUSPICIOUS. I changed these settings for the FILE SYSTEM, MAIL, P2P, and IM shields.
[The WEB shield can be set for ASK or ABORT (ABORT is the default);
the NETWORK and BEHAVIOR shields don’t have any settings.]
My first “glitch” was when I attempted to access the scanners: THEY WEREN’T THERE!!! Fortunately, after I rebooted (and allowed another firewall permission), they (Quick Scan, Full System Scan, Removable Media Scan, Selected Folder Scan) all appeared.
[I also initially had a problem with manually requesting an update --- which likewise was corrected after the second reboot… perhaps also related to the firewall permission.]
Firewall permissions: If Comodo is any "standard of measure" for other [outgoing] firewalls, one needs to grant internet access to avast.setup , AvastSvc.exe (both IN and OUT), and AvastUI.exe . [As best an I can tell, my glitches (above) were the result of my not giving (or accidentally removing) permission for AvastUI.exe ]
A Full system scan (on this laptop) took 1 hour and 6 ½ minutes, to test 30.5 gigabytes of data. I’m not sure why, but the average scan speed --- which avast continually displays/updates --- got progressively slower as the scan proceeded. As expected --- since I strive to keep my computer "squeaky clean" --- nothing was detected.
Avast 5 introduces a “persistent cache”: an area where it stores information on all the files it scans. By (optionally) accessing its cache on a subsequent scan, it can distinguish between those files that have changed (and therefore must be scanned again) vs. those files that haven’t changed (and so don’t need to be re-scanned). To enable this feature, open avast, click on SCAN COMPUTER, select the desired type of scan (e.g., full system), click on Settings, then Performance. Under the Persistent Cache settings, check the box for Speed up scanning using the persistent cache, and then click OK. After doing so, a second Full scan of the same system was reduced to only 19 ¾ minutes! (testing 30.35 gigs)
Scanning for PUPS (Potentially Unwanted Programs) is another scan option. By default, this is OFF. Easy enough to turn on, if you wish. My third Full scan, this time including PUPS, dropped to only 16 1/2 minutes [due to the persistent cache].
Avast partially “failed” the EICAR test: EICAR is a well-established “test pattern” [a SAFE file] that anti-virus programs are supposed to pick-up-on as if it were a virus. Avast’s resident shield did not pick up on a copy I already had on my system, neither under NORMAL, nor even under HIGH, sensitivity. However, it’s web shield did block access to EICAR, when I tried to download another copy of the file(s):
http://www.eicar.org/anti_virus_test_file.htm
---
Addendum:
Here's another neat new feature of avast 5, enabled by default [and which can be accessed in avast, under REAL TIME SHIELDS, select a particular shield, then EXPERT SETTINGS, and finally SENSITIVITY]:
Avast 5 now offers "code emulation":
If the box "use code emulation" is checked and avast! detects some suspicious code in a file, it will attempt to run the code in a virtual environment to determine how it behaves. If potential malicious behavior is detected, it will be reported as a virus. Running the code in this virtual environment means that if the code is malicious it will not be able to cause damage to your computer.


ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 23rd, 2010 17:00
Annie [and others]:
1) We should all keep in mind that there's no urgency to "get rid of" avast 4.8. All indications are that it will be fully supported for at least another two to three months --- and I'm willing to bet for significantly longer ( 6 months ???). Current 4.8 users can easily "sit it out" during this time, using 4.8 for their protection, until all "flaws" in 5.0 have been discovered and fixed.
2) I believe that there are currently three quality free anti-virus programs that I'd recommend to anyone: avast, avira antivir, and Microsoft Security Essentials. While each may have its avid aficionados, I don't believe there's any definitive measure through which to assert that one is any better or any worse, overall, than the others. In other words, if you have switched to MSE, and are happy with it (as you and BB seem to be), there's no reason to go back to avast "just because". Users tend to develop a certain "comfort zone" [familiarity] around the products they use. That's one of the reasons why I'm reluctant to "tinker around" with avira or MSE... I feel like avast has become "my friend". Another thing to consider is that removing an anti-virus is not always the simplest matter --- that's why most anti-virus programs now offer dedicated removal tools to help clean-up things that their uninstaller might have neglected. Well, the more programs you install, and uninstall INcompletely, the more "cluttered" your registry can become over time. So I don't know that I'd suggest "experimenting" with anti-virus programs. Once you've found something that works for you, I'd stick with it, until that program no longer meets your needs.
While asserting that no one of avast, antivir, or MSE is better or worse overall than the other two, we can nonetheless point to particular strengths and weaknesses that each one has:
a) avira tends to boast the top detection rates --- even when compared to PAID alternatives --- though not by much (is 99.2% significantly better than 98.7% ??).
So why is avira not the clear-cut choice? Because:
a1) - unless i'm mistaken, avira tends to have more false-positives than some of the other anti-virus programs. (and this could partially explain avira's higher detection rate, which can be boosted by f/p's).
a2) - the free version of avira does not include web nor e-mail scanning capabilities. By this, we mean that avira will not "pre-scan" e-mail attachments before you open them. However, should you actually open an infected attachment, avira's resident shield should then find the problem and prevent it from infecting your system.
a3) - the free version of avira has a nagging advertisement to purchase its paid version, EVERY time you get a database update. at least they're honest about it: they explicitly say, if you don't want to see this advertisement anymore, then all you have to do is pay up!
a4) -there is a long history of the free version of avira having problems with its update servers. (Some people say this has been fixed.)
b) MSE offers virtually-guaranteed compatibility, simplicity, and significantly fewer false-positives than any of the others. So when it finds something, you can be reasonably certain it's the real thing. The downside:
b1) reportedly, its scan speeds and quarantine processing are significantly slower than the other programs.
c) avast offers its seven distinct resident shields (including an e-mail shield that avira lacks), as well as the option for a boot-time scan [which can locate viruses before they have a chance to load themselves into the operating system]. However:
c1) more flexibility means more complexity, in terms of what a user can (and perhaps, should) adjust in its settings.
c2) the new version, 5.0, is clearly not living up to expectations, in terms of all the complications/headaches people are having installing/running it.
dalem29
2 Intern
•
2.2K Posts
0
January 24th, 2010 06:00
As the orange ball turns...the days of our lives flash before our eyes... :emotion-2:
Sorry about that! It is still revolving this morning indicating my system is sercure. Not sure about the automatic updates. With 4.8 it sought the Internet right away and looked for an update as soon as I got connected. Then Threatfire would look for updates next. I was able to do a manual update on A5 this morning to version 100124-0. So perhaps a bit of tweaking is in order or the auto update server could be overloaded for the time being. Will browse the Avast forums later today and see whats going on and also see if my full scan time went down because of using the persistent cache.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 24th, 2010 06:00
Dale,
you can double-check your update settings.
in avast, go to SETTINGS (located in the upper-right-hand corner), then the UPDATES tab.
be sure that ENGINE AND VIRUS DEFINITIONS is set to AUTOMATIC UPDATE.
as for PROGRAM, I prefer to set that one to ASK ME WHEN AN UPDATE IS AVAILABLE, so that I can install it when I choose to.
Under UPDATE PARAMETERS, check the appropriate box to indicate whether you're connecting only at times, via a dial-up modem; or if you're PC is "permanently" connected to the internet. If "permanently" connected (e.g., a cable connection), it should check automatically every time you boot-up your PC. I would suspect things could be delayed/deferred for dial-up modems, until it checks for and confirms your connection.
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
January 24th, 2010 07:00
As usual, good advice from ky331, with which I mostly agree.
Some random thoughts:
1) New programs always have birthing pangs, and I always wait for the dust to settle before trying them.
2) A reminder that the free versions of avast! and AntiVir are for home/personal use only. If you use your PC for professional work, as I do, you should be using the paid versions (although technically you can still use the free version). MSE has no such restriction of which I am aware.
3) A few years back when I was trialling the free AV versions, I was installing/uninstalling them at the drop of a hat, generally using only Add/Remove in Control Panel. I suspect this lead to many glitches, since this was before AV uninstall tools were generally available.
4) Since then, I always perform the following prior to changing AVs or even versions
- Run on-demand scans to ensure my system is clean
- Defrag and do a cleanup with CCleaner
- Backup my system with Acronis True Image
- Uninstall old AVs/versions using Removal Tools (if available) in Safe Mode, if possible, as per the strong advice here: Uninstall Tools for Major Antivirus Products :(Highly recommended read for anyone changing their AV/version)
- Reboot
- Disable all my resident defenses, including Winpatrol, Windows Defender, and firewall HIPS, prior to installing the new AV/version offline. I find it hard to believe that any of the reputable AV vendors are going to download malware with their installers.
Since adopting this strategy, my AV changes have been glitch-free, although I've not tried the latest avast.
FWIW, when I purchase my next computer, I intend to start with MSE. With all my non-resident passive defenses (WOT, SpywareBlaster, OpenDNS, "safe surfing" etc) I'm not sure all those extra bells and whistles are necessary.
iroc9555
2 Intern
•
1K Posts
0
January 24th, 2010 07:00
Good morning or afternoon to you all.
Good booting today, still the warning triangle for a couple of seconds.:emotion-18:
Dale. My A5 updated automatically to v. 100124-0 around 10:15 am my time (USA Easter time plus 00:30) after rebooting (I was doing something early on that needed a reboot, not related to Avast) Now in Avast Update section it says "release date: (today) at 7:22:38 am". Do not know if it is Czech time or Zulu time, definitively not my time. I was catching my Zzzz at 7:22 and the PC was off and when I booted the PC around 9:30 am, Avast looked for updates but did not do anything. I imagine that Avast servers are busy.
BTW when I installed the first time over 4.8, I did not see any folders from 4.8. I do not know about the registry though. Did not check. Anyway since that first install did not work, I had to use Revo to uninstall A5, and then used Avast tool to remove 4.8, just in case. It did not find anything from 4.8.
Regards.
dalem29
2 Intern
•
2.2K Posts
0
January 24th, 2010 07:00
Just wondering since I installed Avast 5.0 on top of 4.8 if the new version deleted all traces of the previous one. I usually run the clean up file but in this case wanted to preserve the registration.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 24th, 2010 07:00
Dale,
Did the new avast version 5 delete ALL traces of the older version 4.8 ? I have my doubts, as I found some avast4 remnants in at least two other programs:
1) My comodo (2.4) firewall still had permissions for avast 4.8 to access the internet; and
2) WinPatrol still shows an avast4 Control Service (under the Services tab) --- but its status is listed there as DISABLED.
Let me emphasize that I cannot fault avast for these, as avast has no reason to know that I'm using Comodo nor WinPatrol --- and even if it did, it should have no authority to tamper with these separate program's databases.
------------------
Having said that, my advice to you, given all the problems other people have been having with avast5, and given that your system seems to be working well at the moment, is to LEAVE WELL-ENOUGH ALONE! If i were you, I would not risk tampering with anything at this point, unless/until some (serious) problem arises.
iroc9555
2 Intern
•
1K Posts
0
January 24th, 2010 08:00
Ky331.
My Comodo also had those remains from 4.8, but it has a "purge application" to delete any permission given to a program not in the system. so when I did the purge, Comodo deleted all related to 4.8.
dalem29
2 Intern
•
2.2K Posts
0
January 26th, 2010 06:00
The automatic updates on V5 worked this morning. I followed some suggestions that worked for a user in a thread on the Avast forums. Adjusted the settings thusly:
Engine and Virus Definitions------------Automatic Update
Program--------Ask When An Update Is Available
Update Parameters--------Left Both Options Unchecked
Proxy Settings--------Auto Detect
iroc9555
2 Intern
•
1K Posts
0
January 26th, 2010 13:00
If you fall off a horse, What do you do? You go back on again.
A5 has a file in C:\Program Files\Alwil Software\Avast 5\Setup\avast.setup that installs and uninstalled when Avast loads or when it looks for updates. So it is not there right now if you look for it. What happened, in my case, was that Avast.setup was being purged by Comodo, or by me:emotion-4: when I purged Comodo to get rid of rules for non existing apps in my sys. Since I was not around the PC when the second update was happening and by default Comodo will not allow an unanswered alert, the update was not successful and since that rule was blocked the manual update was also denied. What I do not understand yet is why after I rebooted the PC, Avast did not load completely?, or Why did Comodo not allow Avast.setup being Avast a trusted application?:emotion-42:
The thing is that today. I had Avast.setup not purged and Avast did its update. I am still keeping my fingers crossed.
Dalem.
I have my settings the same I had in 4.8. BTW I also read that thread in the Avast Forum:
http://forum.avast.com/index.php?topic=54158.0
1. Automatic definition updates.
2. Ask for program update.
3. Always connected to Internet
4. Each 240 min.
5. Direct connection.
Regards.
dalem29
2 Intern
•
2.2K Posts
0
January 29th, 2010 06:00
Program update 5.0.396 for A5 available this morning.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 29th, 2010 08:00
Dale,
the avast program updates at present are being pushed-out to address the numerous problems that many people have been confronting, as noted on the avast forums. This latest update claims "It will solve most of the stability issues related to version 5.0.377". Since 5.0.377 is version that I initially installed, and since it seems to be behaving on my system, I choose not to accept any (minor) program "updates"... until things seem to settle down more. Why tamper with what's working (for me) --- if it ain't broke, don't fix it.
EDIT: Those wishing to read the latest can consult the following multi-page thread: http://forum.avast.com/index.php?topic=54581.0
You'll note that while some people are claiming things have indeed been fixed, others are still experiencing problems.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 30th, 2010 08:00
for the avast 5 removal tool, should you want/need it, see http://forum.avast.com/index.php?topic=54385.0
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 30th, 2010 10:00
Hernan,
I think we may now have an "official" answer to the question about avast taking its time on boot up, until it's fully-protecting things:
see here: http://forum.avast.com/index.php?topic=54728.0
where the user notes "On every single startup, 2 avast! shields (Web Shield and Mail Shield) don't activate until I wait for about 15 seconds...."
To which moderate Vlk responds "The problem is that these two shields (Web and Mail) are implemented by means of a system service (each of the shields has a custom service). Now, the start of services is somehow synchronized (when a service is starting, no other services can start at the same time) - this is implemented by means of so-called "service manager lock".
On some systems, some services start slowly, which delays the start of the avast shield services."
The e-mail shield taking time to initiate certainly doesn't bother me. As for the web shield, I don't use my browsers until avast is fully active... although I realize that some of my autostart programs might be checking for web updates...
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 30th, 2010 11:00
XP SP3 here: WinPatrol's services tab shows the avast antivirus, mail scanner, and web scanner all currently running; with the antivirus set for automatic startup, but like you, mail/web are each set to manual startup