Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 18, 2013, 10:27:46 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662916
Posts
70572
Topics
145148
Members
Latest Member:
letyiamc
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Other Security Products
Avast Free AV
« previous
next »
Pages:
[
1
]
2
Author
Topic: Avast Free AV (Read 6343 times)
naren
Comodo's Hero
Offline
Posts: 3859
Avast Free AV
«
on:
January 03, 2012, 09:45:20 AM »
I am running Avast Free AV with Windows FW, UAC Enabled & Router on Win 7 64 Laptop. This system is family's system i.e everyone uses this system & are average or novices.
I am little confused with Avast's PUP settings. I always go with products default settings. Avast's default for PUP is disabled. On my XP laptop time to time I test few free AV's like Comodo & Avast. In my test I keep PUP enabled in Avast & when Avast detects anythings as PUP I check it with VirusTotal & I have observed that Avast's PUP detection is detected as Trojan by other vendors at VT.
As I said the users here are novices & average & I dont know if enabling PUP in Avast will increase false positives of legit programs. But given Avast's PUP detection as Trojan detection by others it seems PUP should be enabled & Avast should also enable it by default.
Whats your opinion for my family's laptop or average/novices system for PUP in Avast, Enable/Disable?
Thanxx
Naren
Logged
loveboy_lion
Comodo's Hero
Offline
Posts: 469
COMODO Is Good Hope We Make it The BEST !
Re: Avast Free AV
«
Reply #1 on:
January 03, 2012, 10:10:55 AM »
you may Enable PUP if you download lots of unknown software since some may be malware but the chance of false positive may also increase
Logged
MALWARE TIPS
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #2 on:
January 03, 2012, 10:17:24 AM »
Most of the AV's now enable PUP by default. Experts can always change it.
Why its disbled in Avast by default?
Is it coz enabling it gives FP's on legit programs? or Coz PUP are not malicious by nature?
Why Avast detects as PUP & many other as Trojan?
Thanx
Naren
Logged
loveboy_lion
Comodo's Hero
Offline
Posts: 469
COMODO Is Good Hope We Make it The BEST !
Re: Avast Free AV
«
Reply #3 on:
January 03, 2012, 12:00:53 PM »
More about PUP
http://forum.avast.com/index.php?topic=85834.0
Logged
MALWARE TIPS
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #4 on:
January 04, 2012, 06:43:57 AM »
I read the link. Its mentioned it will give fp on legit apps. But so do the malware signatures, they too give fps on legit apps.
And how can PUP detection give fp on legit apps? i.e yes there's always a chance of fp with any detection service but dont you think it also depends on quality of signatures?
Most of the AV detects PUP by default but they dont say that it will give fp on legit apps. They say that some consider PUP as malicious & some dont. So for average users sake PUP is enabled by default & experts can always change it.
Some legit apps may be kinda similar to PUP but that doesn't means they are PUP as there's other factors too which make the app good or trusted like digital signatures, etc.
I consider Avast the best AV for average users & think that PUP should be enabled by default. Coz under PUP detection it misses trojans & other dangerous apps.
I had mentioned this in Avast forum with few VT links but they also mentioned that it increases fps on legit apps.
How can PUP detection increase fps on legit apps? The quality of PUP signatures should be good, like they carefully provide signatures for malware with rare or no fps.
Thanx
Naren
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Avast Free AV
«
Reply #5 on:
January 04, 2012, 09:59:00 AM »
Well, there is not an universal malware name coding, so the names diverges between the companies. But, indeed, a PUP should be a PUP and not a trojan. If you can post a specific VT link, it will be easier to analyze.
I suggest you keep the avast PUP settings ON.
Quote from: naren on January 04, 2012, 06:43:57 AM
Coz under PUP detection it misses trojans & other dangerous apps.
It shouldn't. It's an avast mistake or error that the virus analyst should correct.
Quote from: naren on January 04, 2012, 06:43:57 AM
How can PUP detection increase fps on legit apps? The quality of PUP signatures should be good, like they carefully provide signatures for malware with rare or no fps.
They try to do so. But detection will always give fp as they become more generic to get malware families.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #6 on:
January 05, 2012, 06:17:32 AM »
The reason I have not enabled PUP coz I thought if its disabled by default then its behaviour/detection may be unacceptable i.e increased FP's on legit apps or FP prone, if it were to be the acceptable behaviour then they would have enabled PUP by default.
For me default settings means carefully selected set of settings comfortable/usable for any/every type of users. Change in default settings may have adverse effect or the behaviour may not be acceptable/comfortable especially for average/novices.
But I want to enable PUP as I already mention in my previous post according to me & my little tests disabled PUP means missing detection of few trojans or malware.
Especially I want to know if PUP enabled can give FP's on Windows Updates, System Files, Microsoft's Products & Laptop Manufacturer's Products like HP's Laptop's so HP's Products? These are mainly the area of my concern with PUP enabled on average/novices systems.
Thanxx
Naren
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Avast Free AV
«
Reply #7 on:
January 05, 2012, 01:04:17 PM »
Quote from: naren on January 05, 2012, 06:17:32 AM
Especially I want to know if PUP enabled can give FP's on Windows Updates, System Files, Microsoft's Products & Laptop Manufacturer's Products like HP's Laptop's so HP's Products?
No.
Generally, if something is detected with these software it will be autosandboxed or blocked by the Behavior Shield.
They are not the focus of PUP detection.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #8 on:
January 06, 2012, 04:46:43 AM »
Quote from: Tech on January 05, 2012, 01:04:17 PM
No.
Generally, if something is detected with these software it will be autosandboxed or blocked by the Behavior Shield.
They are not the focus of PUP detection.
Today I checked a thread in Avast forum & HP product or part of it was detected as PUP. I think Avast PUP detection is little problematic. I remember I have also seen a thread in wilders where Avast PUP detected safe & legit apps.
I will keep the default settings i.e PUP disabled.
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Avast Free AV
«
Reply #9 on:
January 06, 2012, 12:58:57 PM »
Naren:
In case of avast!, PUPs include things like:
* remote access tools (VNC, LogMeIn, TeamViewer etc)
* some admin tools (PsExec, PsKill etc)
* some cracks
Source:
http://www.wilderssecurity.com/showthread.php?t=315491
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #10 on:
January 07, 2012, 05:24:37 AM »
Quote from: Tech on January 06, 2012, 12:58:57 PM
Naren:
In case of avast!, PUPs include things like:
* remote access tools (VNC, LogMeIn, TeamViewer etc)
* some admin tools (PsExec, PsKill etc)
* some cracks
Source:
http://www.wilderssecurity.com/showthread.php?t=315491
This thread in wilders is started by me so I know it
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Avast Free AV
«
Reply #11 on:
January 07, 2012, 05:48:23 AM »
Quote from: naren on January 07, 2012, 05:24:37 AM
This thread in wilders is started by me so I know it
But seems you continue to spread the opposite...
http://www.wilderssecurity.com/showpost.php?p=1999643&postcount=17
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #12 on:
January 07, 2012, 07:14:29 AM »
Quote from: Tech on January 07, 2012, 05:48:23 AM
But seems you continue to spread the opposite...
http://www.wilderssecurity.com/showpost.php?p=1999643&postcount=17
No. Both the topics are same. You have directed to my last reply there. My last reply was PUP detects malware too but is disabled by default in Avast i.e I meant was I would like to see PUP enabled by default in Avast as PUP detects malware too.
And my question of PUP detecting legit apps too so I should keep it enable or disable is not different or opposite coz --
What I mean with all my discussions about PUP is that -- If PUP is enabled by dafault in Avast then I will definitely use it Coz I always like to go with the default settings for average & novices & for me default settings mean carefully selected set or fine tuned settings for majority so if Avast will include PUP in default then they will also change a little PUP criteria/detection/things to be detected so that it is comfortable & at the same time effective for average/novices.
Thanx
Naren
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Avast Free AV
«
Reply #13 on:
January 07, 2012, 09:17:54 AM »
Quote from: naren on January 07, 2012, 07:14:29 AM
As PUP detects malware too.
No, we're going in circles. The PUP does NOT detect malware, only PUP.
Quote from: naren on January 07, 2012, 07:14:29 AM
And my question of PUP detecting legit apps too so I should keep it enable or disable is not different or opposite coz --
The essence of PUP is being a program that depends: could be used for good/clean (admin tool) or could be used for bad/infected (crack). So, of course, PUP detection will find good/clean programs because PUP could be good/clean, depending of the situation.
Quote from: naren on January 07, 2012, 07:14:29 AM
If Avast will include PUP in default then they will also change a little PUP criteria/detection/things to be detected so that it is comfortable & at the same time effective for average/novices.
Naren, you can't change the fact that PUP could be used for good or for bad. It's not a matter of avast criteria. It's about the nature of PUP.
If it was a problem on avast criteria, avast (or any other antivirus) should change the virus signature and correct the problem.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
naren
Comodo's Hero
Offline
Posts: 3859
Re: Avast Free AV
«
Reply #14 on:
January 08, 2012, 06:00:50 AM »
Quote from: Tech on January 07, 2012, 09:17:54 AM
No, we're going in circles. The PUP does NOT detect malware, only PUP.
So why at VT app. 30 scanners detects a file as trojan & other dangerous names but only Avast detects it as PUP? So here 30 scanners are right or Avast?
Nowadays I am not doing any test as its little time consuming & coz of the low resources on the test system the system responds slow under VM. But if I test Avast again & find malware detected as PUP by Avast I will definitely post the links here.
Thanx
Naren
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.052 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com