AJWhite1970 Posted May 21, 2015 Posted May 21, 2015 Hi Silent mode is enabled, shows in both the console and also I have silent\gaming mode ticked on my taskbar. I'll have a dig through the ini files and see if I can find it in there. It's also taking a dislike to my portable version of firefox even though I have it's file path in the exclude folder. I'm sure these are just minor quirks as I get to grips with it's settings. And yes, potentially replacing 1000 Sophos licences with this if I feel it's on a par Andrew
bossman Posted May 21, 2015 Posted May 21, 2015 @AJWhite1970 We currently 100% servers and 98% clients sorted and its working very well, had to make a few exclusions to our workstation template for one of our 3D software packages as 2 of its components register as "Malware" hehe! Apart from that all is running pretty smoothly and as you have stated finding my way around the interface and what can and can't be done, loving it though as its for free!!! Hats off to Avast for this, really appreciated, excellent project and I hope it remains free!
AJWhite1970 Posted May 21, 2015 Posted May 21, 2015 Pretty much got this setup as I want it now, ready to roll it out to a lab for student testing... One thing I can't find is if there is a silent scripted install that I can use, preferably from the downloaded full installer rather than from the slimline on-line version? I've seen a few hacks with AutoIT but not seen a script. Anyone cracked this yet? Andrew
SpaceInvader83 Posted May 22, 2015 Posted May 22, 2015 Has anyone else noticed Avast flooding the Application log? Lots of Event1, bcc errors (new synchronize delay 360)
AJWhite1970 Posted May 22, 2015 Posted May 22, 2015 Has anyone else noticed Avast flooding the Application log? Lots of Event1, bcc errors (new synchronize delay 360) Yes, over 700 of them on one test PC yesterday and lots more this morning... Andrew
tj2419 Posted May 22, 2015 Posted May 22, 2015 Has anyone else noticed Avast flooding the Application log? Lots of Event1, bcc errors (new synchronize delay 360) Yes just checked and i have that too. Might be linked to my issue. Anyone had it where the devices will link and show up in the dashboard but not carry out a remote task such as a scan or update? Thanks
bossman Posted May 22, 2015 Posted May 22, 2015 @spr @AJWhite1970 @tj2419 No Event 1s here and the BCC errors are linked to your DC time not Avast, I have the BCC warnings but I sync my time through the Atomic clock app on our DC and this is why. Must be a connectivity issue from your clients to Avast update servers, I have had to put the URLs of Avast into a policy which does not inspect and decrypt HTTPS from avast.com plus a couple of others. No problems so far (Fingers crossed)
AJWhite1970 Posted May 22, 2015 Posted May 22, 2015 Just checked and all my DC's and workstations are within a second of each other, like you I sync through an atomic clock. Just to double check which rules you use, these are the ones I have whitelisted through my unauthenticated proxy:- iabs.u.avast.com avast.com.edgesuite.net a1639.g1.akamai.net Anything I have missed? Andrew
bossman Posted May 22, 2015 Posted May 22, 2015 @AJWhite1970 I do have a destination exception in Smoothwall, IP address 5.45.58.139 as for the other URLs I do have: business.avast.com I also have a policy which doesn't decrypt and inspect https and I have added all those addresses plus the one I have mentioned to it. Hope this helps 1
AJWhite1970 Posted May 23, 2015 Posted May 23, 2015 Thanks, just added the two extra ones now, will see if it makes a difference. How did you roll out the client to all your stations? Andrew
bossman Posted May 23, 2015 Posted May 23, 2015 @AJWhite1970 Manually installed by technicians after removing Kaspersky using the removal tool, long job over 2 weeks but worth it in the end, I made a mistake when reporting about the BCC event id 1 yesterday, it is down to the Avast and the team are working on this, its nothing to worry about as it is the synchronizing agent which the Avast agent uses to communicate. I will be speaking with one of the engineers after school hols next week so may have an update, I have heard that they working on delivering an MSI so we can mass deploy, I was going to use PDQ deploy but just gave the technicians the task and so far they have made a very good job of it. Labour intensive I know but we had to make sure the Kaspersky was taken off entirely as it doesn't allow another AV to install fully unless. Will keep posting if I come up with something in the meantime
AJWhite1970 Posted May 24, 2015 Posted May 24, 2015 Cheers I've finished writing and testing my script to remove Sophos Enterprise 10 using PDQ Deploy so its just the automated roll-out of the client that's holding me back now (1000 PC's, three sites...) Very interested if you hear anything after half term Andrew
Edu-IT Posted June 18, 2015 Posted June 18, 2015 Does the software build up a definition of safe programs in the cloud, or, will it scan the .exe's on each PC it's not too sure about?
bossman Posted June 18, 2015 Posted June 18, 2015 @Edu-IT It downloads the software to each PC client which is kept updated from the cloud, it runs locally on each workstation like any other software installed and each user can run a scan from the icon on the desktop or a scan can be set from the online console for each computer.
pete Posted June 24, 2015 Posted June 24, 2015 (edited) Are there any updates on the excessive dumping into the application log? On a fresh install, I have 232 "warnings" in the last 7 days and 214 of them are coming from Avast's "bcc" in the last 24hrs. I'm seeing (Source bcc, EventID 01): "new synchronize delay" every 5-7 minutes(which I'd prefer to be: a) less frequent and b) "information", not warning. "BCC registration success" is also a "warning" for some odd reason, when it should really be an "information". Having multiple events assigned the same EventID makes filtering for useful information (and shipping to a logserver) problematic. On the plus side, it behaves itself out of the box much better than McAfee* does (even after McAfee has been tweaked to be less annoying). *yes, strapping a dead badger to your laptop may be more effective than McAfee, you're preaching to the choir here. Edited June 24, 2015 by pete
bossman Posted June 24, 2015 Posted June 24, 2015 @pete I too see the Event ID 01 which refers to the Avast bcc (New synchronize delay 360) but haven't had any more on this from Avast Will keep trying though, Question? Do you have any problems when streaming video from BBCIPlayer with Avast webshield? I have put in the Exclusions for the URL but it seems to want to check the media stream as its running causing it to judder every now and again and cause syncing problems. Cheers
Edu-IT Posted June 24, 2015 Posted June 24, 2015 No fix for that yet, but, it's being worked on. (BCC error)
Edu-IT Posted June 25, 2015 Posted June 25, 2015 @bossman I've found iPlayer won't work at all in IE since I've moved to Avast.
pete Posted June 25, 2015 Posted June 25, 2015 @pete Question? Do you have any problems when streaming video from BBCIPlayer with Avast webshield? I have put in the Exclusions for the URL but it seems to want to check the media stream as its running causing it to judder every now and again and cause syncing problems. Cheers I've just tested it and maybe*. BBC iPlayer, Napoleon: Episode 3. SD stream: some initial stuttering. HD stream: much more noticable. Internet use at the time was low and the proxy wasn't labouring. It's scanning sa.bbc.co.uk at the time. *I say maybe because it's running in a VM on a laptop with another VM open and high-ish CPU use.
pete Posted June 25, 2015 Posted June 25, 2015 (edited) Program Files - bcc.cfg under C:\Program Files\AVAST Software\Avast\conf and it's also under Program Data - C:\ProgramData\AVAST Software\Avast\var Append the following in both cfg files: use_proxy=0 - off / 1 - on proxy_port=8000 proxy_ip=10.10.10.10 etc. proxy_auth=0 - NONE, 1 - BASIC , 2- NTLM proxy_user=username:password Poking around a couple of test clients, I see that the bcc.cfg in Program Files is correct, but the one in ProgramData isn't (missing proxy info). Has anyone worked out how it uses the config files and if one has precedence? ProgramData bcc.cfg contains: [bc] base = bcons-core.ff.avast.com:80 registrator = http://{}/register handler = http://{}/handle install_id = server_id = client_id = key = tick = 120000 Program Files bcc.cfg In Unicode format (other bcc.cfg isn't) [bc] base = bcons-core.ff.avast.com:80 registrator = http://{}/register handler = http://{}/handle install_id = use_proxy = 1 proxy_port=8080 proxy_ip=Our.Pro.xy.IP proxy_auth=0 The proxy details in the second bcc.cfg above were set when the installer was downloaded (you specify the proxy when downloading via the web console and it builds a package with the right info). The IDs & keys in the ProgramData bcc.cfg were created when the client first talked to the web console. Which implies it uses both, but I have a sneaking suspicion (because it's not honouring the "update AV every six hours" setting) that I need to manually put proxy settings into the ProgramData bcc.cfg. If I manually trigger an update, it works fine (uses proxy). The automated update appears not to be working. As far as I'm aware I have all the proxy exceptions/auth exceptions set that anyone's mentioned in-thread. Edited June 25, 2015 by pete
bossman Posted June 26, 2015 Posted June 26, 2015 @pete We don't have the proxy details in the config file as you can see: Program Files bcc.cfg: [bc] base = bcons-core.ff.avast.com:80 registrator = http://{}/register handler = http://{}/handle install_id = 65eb9c1683d2499d85401cd11dc14352d36d0690ef474c54a09350ecd7d33d7b ProgramData bcc.cfg contains: Is Empty It seems to me that once it has registered each client is given a separate key: Our config is online which when you look at the client Avast application under updates we see the proxy details: All our clients are updating unless they are not on which Avast console alerts me to,
pete Posted June 26, 2015 Posted June 26, 2015 Hmm, I'm going to be ever-so-annoyed if adding the proxy details to the installer beforehand has actually broken automatic updating. The client applicaton does show proxy details (and uses them when I manually trigger),clients register fine and grab the config without issue, but I'm wondering why both bcc.cfg files are populated when yours aren't. @bossman, are your clients updating roughly every 6 hrs? When you downloaded the installer did you create one with the proxy info embedded or did your techs add the proxy info when installing it manually?
bossman Posted June 26, 2015 Posted June 26, 2015 (edited) @pete I created a template for clients and one for servers which I then populated with our proxy settings, downloaded the installer and we manually installed but didn't enter the proxy settings. When the client installer had finished it runs a preliminary scan and then in the Avast online console it comes up as requiring activation which I preceded to activate and then as it is activating I change the client to the template in the dropdown box to the client one as it would normally use the default. Updates are approximately every 12 - 24hrs I hope this has cleared it up, I also now have a deployment package via PDQ deploy which just works lovely. Only thing I have had problems with is the IPlayer URL's not showing on the client. Update: I have found our proxy settings in here: C:\Program Files\AVAST Software\Avast\setup\Proxy.ini Edited June 26, 2015 by bossman
pete Posted June 29, 2015 Posted June 29, 2015 Ours are checking in with the console fine (or rather, console says "I've seen that device recently") but they're not updating definitions automatically. I've left them running over the weekend just to see if it was something odd and this morning they're sat on definitions from 26-06-15. If I manually update the client, the console doesn't know/reflect that there's been an update, even after 30 mins or so. But the "last seen" timestamp is being updated. If I trigger an update via the console, it doesn't do anything until I manually update the client. Looking in the SW logs, I can't see anything being blocked.
bossman Posted June 29, 2015 Posted June 29, 2015 (edited) @pete Below is a sample of Server and Client settings in the console: Server: Client: As you can see from the dates first installed to present day all correct and the last seen was today at approximately the same time, both units have the latest updates of the program which was released as per the date, all Computers and Servers are the same except one HP Netbook which hasn't been used by a student for the past week. Have you spoken to Avast support? Below are all the URL's I have in the "No Https Inspection" and "Custom Allowed" policies business.avast.com avast.com.edgesuite.net iabs.u.avast.com a1639.g1.akamai.net avast.com Edited June 29, 2015 by bossman
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now