pete Posted June 29, 2015 Posted June 29, 2015 Regarding the web console, mine is similar, but if I go to the "Products" tab for the devices it shows the antivirus definitions are lagging behind and that can be confirmed by looking on the client. I haven't spoken to Avast support yet (I discovered that if you sign up for Avast Business with an email address containing "admin", the Avast forums kick you out because it's a restricted username), so I'll create second user on the console and use that instead. My no inspection/custom allowed are the same as yours (they're a bit looser than that actually).
Edu-IT Posted June 29, 2015 Posted June 29, 2015 Are people setting any specific settings on the servers policy?
pete Posted June 29, 2015 Posted June 29, 2015 ^ Haven't really started looking yet (needs to behave on clients first). I'd probably turn off DeepScreen (or set a lot of "don't scan this" exceptions, the same as I've done with the incumbent). Microsoft usually have a recommended "don't come crying to us if you're on-access scanning these things" list for most products. https://technet.microsoft.com/en-us/library/bb332342.aspx <-- Exchange 2013, for example. And incidentally, Avast Support is pretty good.
Edu-IT Posted June 29, 2015 Posted June 29, 2015 Indeed, support so far is great, I've found. @bossman I'm working with them on the BBC iPlayer thing. Did you raise a case too?
bossman Posted June 29, 2015 Posted June 29, 2015 @Edu-IT No I haven't as we don't use it that extensively, in fact it was a one off that we required it so didn't see the urgency, too many other things going on at the moment. It's good you have raised the issue with them though, hopefully they may be able to point you in the right direction and thus you will be able to pass on that knowledge. Have fun
pete Posted July 2, 2015 Posted July 2, 2015 Just in case anyone's not noticed, dates are off-by-one in the web console. Fix hopefully coming soon. The client dates are correct, but the web console will show activation/detection dates one day behind.
Tesla Posted July 7, 2015 Posted July 7, 2015 Can't seem to run the browser add on check, says it cant connect to the internet, i have added the relevant proxies (the only one i could find, mind, was the one on the updates tab)...
MattDLEA Posted July 7, 2015 Posted July 7, 2015 Do people have this running on there servers? or it it just purely client pc's
Tesla Posted July 7, 2015 Posted July 7, 2015 currently on a couple of client pcs just to see how it goes.
bossman Posted July 7, 2015 Posted July 7, 2015 (edited) @MattDLEA Have you seen my post above yours? Edited July 7, 2015 by bossman
bossman Posted July 13, 2015 Posted July 13, 2015 Hi All, Just a quick update, came in this morning and for some unknown reason after a couple of months of running Avast on the servers with a specific template it seems to have quarantined a specific RM file which relates to the RMMC and this would not allow us to access the user properties in the RMMC, I have removed Avast from this server and re-installed the user manager legacy, until I can guarantee it will not start quarantining other files which are genuine I will not re-install, must have been the latest updates which caused it, Will relay this to Avast but in the meantime the clients seem to be fine, Watch out if you decide to install on Servers keep an eye open Regards Bossman
Edu-IT Posted July 13, 2015 Posted July 13, 2015 That's interesting but unhelpful! Let me know the outcome. I'll hold off for now.
pete Posted July 13, 2015 Posted July 13, 2015 Watch out if you decide to install on Servers keep an eye open Regards Bossman I may or may not be using you as my server canary Clients-wise it's been fine here and while DeepScreen is a bit annoying* it only does what McAfee would silent churn in the background doing without informing you. *I have unlock.exe from Joeware in a non-standard path on my Win 7 VM. This triggers DeepScreen because of one or more of the following: 1) It's running from an elevated prompt 2) It's in a non-standard path 3) It's not (AFAIK) signed 4) It makes a network connection So I expect it to to trigger. But then I expect Avast to add it to a persistent "I scanned this and it was cool, I'll store the hash value so I know next time". It seems to do this for a short time, but if I reboot or wait a couple of days I get the same prompt (even though the executable hasn't changed). 1
bossman Posted July 13, 2015 Posted July 13, 2015 @pete "I thwort I saw a puddycat!!" "I did! I did!" It seems ok on vanilla servers without any other software ontop, I thought it might kick up a fuss on the RM servers but as I said it has been installed on Servers for a couple of months with hardly a ripple until today, anyway nothing too major all sorted again, will test further with different templates. KTF
MattDLEA Posted July 13, 2015 Posted July 13, 2015 Put this on a client PC that was running ranger. It quarantined a Ranger service ( which then looked me out of that pc ) Im sure its just a few exceptions that need adding but didn't have the time this morning ( and to be honest was expecting it to happen with Ranger been installed
pete Posted July 13, 2015 Posted July 13, 2015 (edited) I'm assuming RM sign their executables? I've got e-safe and securus installed on PCs (currently conducting a play-off here) and it hasn't choked or quarantined either yet. Edited July 13, 2015 by pete spelling
bossman Posted July 13, 2015 Posted July 13, 2015 @pete Yes they do, it has something to do with remote accessing the Postgres SQL database and the AD at the same time utilising the Usermanager UI, it seemed fine for the last couple of months and then wham! It seems the last updates refined the file scanning, been running deepscan so will probably lighten this on the template before I re-install Avast, only affected the DC though as this is where the executable is run from, We will keep trying! God loves a trier
Edu-IT Posted July 13, 2015 Posted July 13, 2015 (edited) Did you send them the files to test in the lab? I'm part way through deploying to desktops. Is there any way to bulk assign to the correct policy? I thought I could go into the actual settings and click > add device and it add it to the right group but seems there's no add device button now? Edited July 13, 2015 by Edu-IT
bossman Posted July 13, 2015 Posted July 13, 2015 @Edu-IT I have a bulk installer for pushing the client install out using PDQ Deploy but one has to manually activate all of them in the online console as they appear and then once activated add them to your client or Server template, that's how I did it, I don't know if anyone else has done it differently? I set my templates up first as a clone of the default one with minor adjustments for both the client and servers, I have 3 templates one for clients, one for Servers and one for our TS servers. They all seem to be working apart from what happened today but I won't let that spoil the party
Edu-IT Posted July 13, 2015 Posted July 13, 2015 I've figured it now, with the help of their fab support. If you go here https://business.avast.com/#network/devices then press the option to show the groups pane. Create all the different groups and link them to a policy, you can then drag the clients into the right group and they'll pick up the right policy. To begin with I was going in and editing each client. 1
bossman Posted July 14, 2015 Posted July 14, 2015 @Edu-IT By jove I think he's got it!! Nice one bud! 1
AJWhite1970 Posted July 14, 2015 Posted July 14, 2015 Never has one small icon made so much difference. Good spot, just made my life easier!!! 1
AJWhite1970 Posted July 27, 2015 Posted July 27, 2015 Sophos licence runs out in a few weeks so decision time!!! Really like Avast and really tempted to switch (even taking into account how much of a git sophos is to uninstall...). Just before I do, would one of you be kind enough to post your workstation policy settings so I can double check mine and make sure I haven't done anything silly on my test PCs? Happy to receive as a pm if you don't want to share publicly. Cheers Andrew
Edu-IT Posted July 27, 2015 Posted July 27, 2015 I've left mine as they were by default with the exception of adding in a few exclusions specific to our school software. The only other change I made was to run the app in silent mode.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now