
UNSOLVED
My first experience with Avast! 5
Well, curiosity got the best of me, and so I "bit-the-bullet" and upgraded to avast 5 (from 4.8).
My System specs: Windows XP SP3
Reasonable Precautions: I backed up some personal files (my income tax return that I'm currently preparing, and my Microsoft Money files) that I wouldn't want to have to recreate from scratch.
Paranoid Precautions: I downloaded a copy of the (older) Avast 4.8 setup engine
http://www.avast.com/free-antivirus-download#tab4 (choose your language),
and avast 4.8 removal tool http://www.avast.com/en-gb/uninstall-utility
just in case of total disaster (i.e., the need to revert to 4.8).
Better to be prepared than sorry!
(Addendum: for the avast 5 removal tool, should you want/need it, see http://forum.avast.com/index.php?topic=54385.0 )
Avast's Quick-Start Guide (for reference, including detailed installation instructions) can be downloaded from
http://www.avast.com/documentation/quick-start-guide-free-en-ww.pdf
Download the new Avast 5 (Version 5.0.377) - 38.29 Meg, from
http://www.avast.com/lp-upgrade-4-5
(which, at present, takes you to CNET Downloads).
Resident Protection: I have, and decided to keep running, SpyBot’s TeaTimer, Microsoft’s Windows Defender, and WinPatrol. I realized doing so might bombard me with prompts to allow/accept system changes. For those who wish to take a simpler (/ safer) approach, you might consider temporarily disabling any resident defenses that might “impede” avast’s installation.
Go offline: I turned-off my wireless adapter card, so as to insure my system would be offline --- and therefore, protected --- even as avast was automatically uninstalling the older version 4.8
The Installation process: I clicked to run the Setup Engine. (Note: I’m using XP. I presume that Vista and Win7 users should opt to Run as Administrator ???)
I accepted the Open File – Security Warning, and chose to RUN the Setup Engine.
(I received a query about avast 4’s removal, from TeaTimer, which I permitted).
UNLIKE the indication in the Quick-Start Guide, there was no choice of language offered. I presume this means I downloaded an English-only installer.
The first option offered was to participate in the avast community, “to anonymously forward some security-related information to avast (on an as-needed basis)”. This box was pre-checked, I accepted it, and clicked on NEXT.
I was then offered the option to install Google Chrome (an alternative browser). Avast “recommends” this --- but it is not required. To avast’s credit, neither the YES nor NO box was pre-checked! So the user must explicitly opt-in or opt-out here. I opted-out (chose NO), and clicked NEXT.
The installer created a System Restore point, and then installed avast 5.
[I received one query about avast 5 from TeaTimer, one from Windows Defender, one from WinPatrol, and one from my Comodo (2.4) firewall, all of which I allowed. ]
A new, ORANGE avast icon was placed on my desktop. [This is not a critical icon, as you will eventually be able to access the same feature from your system tray, or from your START menu. I eventually deleted this desktop icon, after rebooting].
At this point the installation was complete, and it was strongly suggested I reboot. (Wish me luck)
The first reboot: I anxiously kept my fingers crossed as the system was rebooting. All seems to have gone well.
I received several prompts (permission requests) from my Comodo firewall… but that’s certainly to be expected.
[While on the matter of my firewall, I discovered that it still was showing several permissions for the older Avast 4 components. I decided to manually remove them all.]
The old 4.8 BLUE ball in the system tray has been replaced by a new ORANGE one for 5.0.
I then received my first virus database update. Avast 5 spoke to me in a higher/woman’s voice, rather than the lower/male’s voice of version 4.
Checking in WinPatrol, I see that Avast 5 added one startup program AvastUI.exe (User Interface), which presumably places the orange ball in the system tray; and one startup service AvastSvc.exe, which “Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler”.
Following in the order of the Quick Setup Guide, I checked my registration (Right-click on the Orange A-ball, select registration information) to confirm that avast 5 had carried-over my registration from avast 4. [For first-time users, you can register (for free) online.] You will need to re-register avast every 12 months.
You can open the avast user interface (“program”) by LEFT-clicking on the orange avast ball in your system tray [or RIGHT-clicking on it, and selecting Open avast! user interface]. A minor difference here (from version 4.8) is that avast 5 seems to remember (and open) the last interface screen you had viewed (rather than starting with any “main” screen).
The Quick-Start Guide instructions, pages 9-10, are very informative for showing details. Being straight-forward, I will not repeat them here. But I do recommend you read and “feel these out” for yourself.
Concerning the various “shields”, and their automated activity/response, the default when a virus/PUP/suspicious file is encountered, is first try to Move it To the Chest… if that fails, try to delete it… and if that also fails, to take no (further) action. Realizing that an extreme false positive could have detrimental effects --- and since I know I personally won’t panic at a “virus” alert, and will investigate it further to make my own determination, I opted to change these to first ASK me, and if that “fails” then place the file in the Chest. I believe these choices are safer, provided one is willing to do the necessary research. For those who wish, these changes can be made by clicking on REAL-TIME SHIELDS, selecting one (e.g., the File System Shield), click on EXPERT settings, the ACTIONS tab, and choosing (based on my example) first ASK, then MOVE TO CHEST. You’ll need to do this three-times (per shield): for VIRUS, for PUP, and for SUSPICIOUS. I changed these settings for the FILE SYSTEM, MAIL, P2P, and IM shields.
[The WEB shield can be set for ASK or ABORT (ABORT is the default);
the NETWORK and BEHAVIOR shields don’t have any settings.]
My first “glitch” was when I attempted to access the scanners: THEY WEREN’T THERE!!! Fortunately, after I rebooted (and allowed another firewall permission), they (Quick Scan, Full System Scan, Removable Media Scan, Selected Folder Scan) all appeared.
[I also initially had a problem with manually requesting an update --- which likewise was corrected after the second reboot… perhaps also related to the firewall permission.]
Firewall permissions: If Comodo is any "standard of measure" for other [outgoing] firewalls, one needs to grant internet access to avast.setup , AvastSvc.exe (both IN and OUT), and AvastUI.exe . [As best an I can tell, my glitches (above) were the result of my not giving (or accidentally removing) permission for AvastUI.exe ]
A Full system scan (on this laptop) took 1 hour and 6 ½ minutes, to test 30.5 gigabytes of data. I’m not sure why, but the average scan speed --- which avast continually displays/updates --- got progressively slower as the scan proceeded. As expected --- since I strive to keep my computer "squeaky clean" --- nothing was detected.
Avast 5 introduces a “persistent cache”: an area where it stores information on all the files it scans. By (optionally) accessing its cache on a subsequent scan, it can distinguish between those files that have changed (and therefore must be scanned again) vs. those files that haven’t changed (and so don’t need to be re-scanned). To enable this feature, open avast, click on SCAN COMPUTER, select the desired type of scan (e.g., full system), click on Settings, then Performance. Under the Persistent Cache settings, check the box for Speed up scanning using the persistent cache, and then click OK. After doing so, a second Full scan of the same system was reduced to only 19 ¾ minutes! (testing 30.35 gigs)
Scanning for PUPS (Potentially Unwanted Programs) is another scan option. By default, this is OFF. Easy enough to turn on, if you wish. My third Full scan, this time including PUPS, dropped to only 16 1/2 minutes [due to the persistent cache].
Avast partially “failed” the EICAR test: EICAR is a well-established “test pattern” [a SAFE file] that anti-virus programs are supposed to pick-up-on as if it were a virus. Avast’s resident shield did not pick up on a copy I already had on my system, neither under NORMAL, nor even under HIGH, sensitivity. However, it’s web shield did block access to EICAR, when I tried to download another copy of the file(s):
http://www.eicar.org/anti_virus_test_file.htm
---
Addendum:
Here's another neat new feature of avast 5, enabled by default [and which can be accessed in avast, under REAL TIME SHIELDS, select a particular shield, then EXPERT SETTINGS, and finally SENSITIVITY]:
Avast 5 now offers "code emulation":
If the box "use code emulation" is checked and avast! detects some suspicious code in a file, it will attempt to run the code in a virtual environment to determine how it behaves. If potential malicious behavior is detected, it will be reported as a virus. Running the code in this virtual environment means that if the code is malicious it will not be able to cause damage to your computer.
Responses (0)
Solutions (0)
