It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda RMM
formerly Managed Workplace

Configuring Avast Business Antivirus Policies: Enabling and Configuring Sandbox

  • Last updated on

Sandbox is available for Workstations only, not Servers.

Sandbox lets you run applications in a safe virtual environment, isolated from the rest of your device's system. This feature is useful when you want to run suspicious or untrusted applications without risk.

  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. In the Tools section, move the slider to enable Sandbox.
  6. Click Apply Changes.

Configuring Avast Business Antivirus Policies: Configuring the Location of Sandbox Storage

Sandbox is available for Workstations only, not Servers.

Sandbox storage is a file space completely isolated from the rest of your system and other Sandboxes.

When you run an application in Sandbox, all necessary files are always copied to Sandbox storage where they can be modified as needed without affecting the original files. Any new files created during virtualization are also saved to Sandbox storage.

By default, Sandbox storage is created in the same drive as the original file. If there is insufficient space on the pre-selected drive or you encounter disk performance issues, you may need to select a different drive or browse for another location.

  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Sandbox Storage tab.
  7. Select a drive by doing one of the following:
    • Click the The same drive as the modified file check box.
    • Click the drive check box, then select a drive from the drop box.
  8. Click Apply Changes.

Configuring Avast Business Antivirus Policies: Configuring Sandbox Web Browser Options

Sandbox is available for Workstations only, not Servers.

Enabling the Save trusted downloaded files setting saves files downloaded while browsing the web inside the virtualized window onto your device. This only applies to download processes which are identified as safe. If you clear this box, downloaded files are deleted when you close the Sandboxed browser.

Enabling exclusions options excludes your personalized data in web browsers from being deleted when you close Sandbox. Enable each box according to your preferences, or enable All settings and components to exclude all listed components plus browser extensions and add-ons.

In the Maintenance section, you can manage storage settings.

Enabling Cache web browser files (sandbox will not be automatically deleted) saves only the virtualized files for web browsers, improving the browser's performance in Sandbox.

Enabling Automatically cleanup Sandbox storage lets you specify how often cached contents are deleted.

  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Web Browsers tab.
  7. To save trusted downloaded files outside the Sandbox location, click the Save trusted downloaded files outside the sandbox check box.
  8. To choose settings and components that will not be virtualized when the web browser runs in the Sandbox, check any of the following check box:
    • All settings and components (extensions, add-ons, etc.)
    • Bookmarks
    • History
    • Cookies

    Excluded settings and components are not deleted when you end the session.

  9. To save virtualized web browser files, click the Cache web browser files (sandbox will not be automatically deleted) check box.
  10. To clean up Sandbox storage on a recurring basis, with the Cache web browser files (sandbox will not be automatically deleted) check box enabled, click the Automatically cleanup  sandbox storage check box, then do one of the following:
    • Click the Once every check box and type the number of days between cleanups.
    • Click the Once every check box and select a day of the week.
    • Click the Every first check box and select a day of the week.

    If you click the Every first check box, the Sandbox is cleaned up the first of the month, on the first occurrence of the day that you choose in the box. So, if you chose Tuesday in that box, the Sandbox storage is cleaned up the first Tuesday of every month.

  11. Click Apply Changes.

Configuring Avast Business Antivirus Policies: Setting Which Applications Are Virtualized in Sandbox

Sandbox is available for Workstations only, not Servers.

Virtualizing processes is useful when you run questionable applications in Sandbox regularly. You can configure Sandbox to always virtualize a specific application or several applications contained within a folder.

If Avast Business Antivirus marks a file as suspicious after scanning but you need to use the file regularly, we recommend that you exclude the file from all scans and shields using the Configuring Avast Business Antivirus Policies: Excluding Files, Folders, or URLs from Scans and Shields procedure, then set the file to be started in Sandbox automatically each time it runs using the procedure below.

  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Virtualized Processes tab.
  7. To automatically virtualize an application, type the path to the application, then click Add.
  8. To automatically virtualize any application in a folder, type the path to the folder, then click Add.
  9. Repeat steps 7-8 until all applications and folders are added.
  10. Click Apply Changes.
To stop virtualizing a process in Sandbox
  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Virtualized Processes tab.
  7. Next to the process you want to stop virtualizing, click  exclusion_delete.jpg.
  8. Click Apply Changes.

Configuring Avast Business Antivirus Policies: Specifying Locations that Can't be Accessed by Virtualized Applications

Sandbox is available for Workstations only, not Servers.

Harmful applications running in Sandbox can attempt to capture sensitive data copied to the virtualized environment. To prevent malware from accessing this data, a list of common system locations is blocked by default. Click the Allowed check box next to any file or program that you want to access during virtualization.

You can also add your own locations to block or allow. Type the folder location manually into the text box or click Browse, click the relevant folder, then click OK.

  1. Click Service Delivery > Policies > Avast  Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Privacy tab.
  7. In the Private Pre-set  Locations click one of the following check boxes for each location:
    • Blocked
    • Allowed
  8. For user-defined locations, type a file path, click either the Blocked or Allowed check box, then click the Add button.
  9. Repeat step 8 until all locations are defined.
  10. Click Apply Changes.
To Remove a Block from a Location so it can be Accessed by Virtualized Applications
  1. Click Service Delivery > Policies > Avast  Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Privacy tab.
  7. Next to the process you want to stop virtualizing, click exclusion_delete.jpg.
  8. Click Apply Changes.

Configuring Avast Business Antivirus Policies: Specifying Locations that Won't Be Virtualized

Sandbox is available for Workstations only, not Servers.

All files acquired during a Sandbox session are deleted when you close the sandboxed application. If you want to keep certain files, you can save them to a specified folder. We recommend using caution when saving files from sandboxed applications to excluded locations. If the application running in Sandbox is malicious, saving a file to a location on a device could be harmful.

Consider the options you have set up for your Sandbox when you add exclusion locations. For example, if you set your options to delete the contents of folders on exit, you might want to exclude the folder where you save files you download from the Internet.

Folder locations can include wildcard characters ? and *. The asterisk replaces zero or more characters, and the question mark replaces a single character. For example:

  • To exclude a folder and its sub-folders, add * to the end of the folder name, for instance C:\example* .
  • To exclude all folders labeled in a certain way on any of your hard drives, include ?:\ in front of the path, for instance ?:\example*.
  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Exclusions tab.
  7. Type a file path.
  8. Click Add.
  9. Repeat steps 7-8 until you have added all the paths you want to exclude.
  10. Click Apply Changes.
To Remove an Exclusion from a Virtualized Location
  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Exclusions tab.
  7. Next to the exclusion you want to remove, click exclusion_delete.jpg.
  8. Click Apply Changes.

Configuring Avast Business Antivirus Policies: Allowing Virtualized Applications to Access the Internet

Sandbox is available for Workstations only, not Servers.

You can control which applications can access the Internet when they are running in the Sandbox or are automatically virtualized by CyberCapture.

  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Internet Access tab.
  7. To give all applications the same access, click one of the following check boxes:
    • Allow all virtualized applications to access the internet
    • Block internet access for all virtualized applications
  8. To customize which applications can access the Internet, check the Allow certain  virtualized  applications  to  access  the  internet check box, then do either of the following:
    • If you want to let all web browsers access the Internet, check the Web browsers check box.
    • To let another application access the Internet, type its file path, then click Add. Repeat this step until you've identified all the applications you want to access the Internet.
  9. Repeat step 8 until you have added all the paths you want to exclude.
  10. Click Apply Changes.
To Remove Permission For a Virtualized Application to Access the Internet
  1. Click Service Delivery > Policies > Avast Antivirus.
  2. Click the name of a policy.
  3. Click the Workstation Settings tab.
  4. Click the Active Protection tab.
  5. Click the Customize link in the Sandbox section.
  6. Click the Internet Access tab.
  7. Next to the application you want to prevent from accessing the Internet, click exclusion_delete.jpg.
  8. Click Apply Changes.