The Real-Time Protection is a permanently active process. Any file that is used, copied or accessed is scanned via this module in real-time. This prevents malware from executing; every execution of a file that triggered a detection is automatically blocked with a notice to the user.
In the Real Time protection configuration, you can set up what file types are scanned, if archives should be scanned too and in addition if network attached storages and drives should be monitored.
The Real-Time protection is very detailed and can be customized completely to the user's needs.
- Click the Avira Icon in your system tray.
- Search for your Antivirus and click Open.
- Click the Setting icon in the lower left-hand corner of your Antivirus window.
- You can choose what to scan in section Scan → Files (all files, only executables, user-defined mixture) and you have also an influence on how many system resources are used to scan.
- The option Archives allows detailed configuration about the depth to be scanned:
- Drivers Network monitoring means that all files sent to or received from a drive/storage within the local network are scanned. This might be an option to check if someone encountered a slow system with active Real-Time Protection because it may consume a high amount of system resources.
- The subcategory Action on detection allows preconfiguring what action should be taken if a detection occurs:
- Interactive is the default value. This will lead to a window asking the user individually for every detection what should be done. You can either remove the file by deleting, moving it to quarantine, just renaming it or leaving as it is.
- Automatic allows setting up a standard action and a second solution if the first given one is not working properly.
- Further actions allow pushing events/notifications of the product into the standard “Windows Event Database”.
- Exceptions also work similar to the on-demand scanner. In addition to excluding files/folders, you are also allowed to exclude processes. Starting a program does not mean using every file, every time. The main part of the program is running as a so-called “process”. As those processes may load files that may contain known false-positives, the user is aware of the risks. If they are huge in size and can cause a massive consumption of system resources, setting up an exception can be a solution here.
- Heuristic offers the option to enable or disable heuristics for the on-demand scanner only and what mode of heuristic detection is used.
This is possible for every component of the product, making it easier to fit the user needs.
- Report - The logging has a small addition compared to our System-Scanner. It is possible to set up a maximum file size of this log file as all information about any action/detection/etc. of this module is continuously analyzed, causing the size to increase permanently.