V
Vanguard
Just noticed today that the tray icon for CA's EZ-AntiVirus 6.4.0.4 has
a red X. Hovering over its tray icon showed the popup saying,
"Real-Time: Boot:OFF File:INACTIVE Email:ON". All real-time protection
settings were enabled. Rebooting didn't help. Eventually I disabled
all its real-time protections, rebooted (required), re-enabled all its
protection settings, rebooted (again required), and now the red X is
gone and all protections are enabled. So EZ-Antivirus wasn't complying
with its settings.
On re-enabling all the protection settings and rebooting, I got a
message from MSAS saying a new LSP (layered service provider) was added
to the TCP layer. That is expected because EZ-Antivirus uses an LSP.
However, I did *not* get this warning when MSAS was installed about a
week ago. So it could be MSAS disabled the LSP for EZ-Antivirus and
never prompted me to choose an action on what to do about the LSP.
It looks like the Winsock checkpoint for the Internet agent is where
LSPs get detected. However, the "Manage allowed/blocked" configuration
option is disabled. So I can't see that the LSP for EZ-Antivirus that I
just allowed is in its allow-list. Also, it seems stupid that the only
events I can see in the logs are for blocks. I would also want to see
what I allowed (since something allowed maybe should not have been
allowed). Does the "Tools -> Real-Time Protection -> View Security
Agent Events" menu show both allowed and blocked events?
I wanted to reset its management lists on every checkpoint to start from
scratch. In fact, at this point, and since it is dubious what MSAS did
during its install regarding disabling of anything that it may not have
alerted to the user, I want to reset everything so it will should alert
me on everything it detects again. That is, I have to discard every
allow and block rule to have MSAS start from scratch. Do I have to
review all 59 checkpoints to check on their "Managed allowed/blocked"
list?
a red X. Hovering over its tray icon showed the popup saying,
"Real-Time: Boot:OFF File:INACTIVE Email:ON". All real-time protection
settings were enabled. Rebooting didn't help. Eventually I disabled
all its real-time protections, rebooted (required), re-enabled all its
protection settings, rebooted (again required), and now the red X is
gone and all protections are enabled. So EZ-Antivirus wasn't complying
with its settings.
On re-enabling all the protection settings and rebooting, I got a
message from MSAS saying a new LSP (layered service provider) was added
to the TCP layer. That is expected because EZ-Antivirus uses an LSP.
However, I did *not* get this warning when MSAS was installed about a
week ago. So it could be MSAS disabled the LSP for EZ-Antivirus and
never prompted me to choose an action on what to do about the LSP.
It looks like the Winsock checkpoint for the Internet agent is where
LSPs get detected. However, the "Manage allowed/blocked" configuration
option is disabled. So I can't see that the LSP for EZ-Antivirus that I
just allowed is in its allow-list. Also, it seems stupid that the only
events I can see in the logs are for blocks. I would also want to see
what I allowed (since something allowed maybe should not have been
allowed). Does the "Tools -> Real-Time Protection -> View Security
Agent Events" menu show both allowed and blocked events?
I wanted to reset its management lists on every checkpoint to start from
scratch. In fact, at this point, and since it is dubious what MSAS did
during its install regarding disabling of anything that it may not have
alerted to the user, I want to reset everything so it will should alert
me on everything it detects again. That is, I have to discard every
allow and block rule to have MSAS start from scratch. Do I have to
review all 59 checkpoints to check on their "Managed allowed/blocked"
list?