Author Topic: Possible bug - Continuous access denying after cleaning infected ZIP archive  (Read 6190 times)

0 Members and 1 Guest are viewing this topic.

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Bug report from Japanese forums:
Even after cleaning infected ZIP archive by File System Shield (on-access), denying access to cleaned ZIP archive continues.
* "Scan all archive" in the File System Shield enabled
With on-demand scan this symptom does not happen.

If we open file properties, change file name or save File System Shield settings, we can access cleaned ZIP again.
Windows 7 x64 (Original poster's computer)
avast! Free Anti-virus

I confirmed this symptom. I know we shouldn't use infected ZIP file, so I already told this to Op.
Original Post (in Japanese forums):
http://forum.avast.com/index.php?topic=66271.0


Edited: deleted another wrong bug report
« Last Edit: November 17, 2010, 01:41:39 AM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Well I would ask why enable scanning zip/archive files in the file system shield in the first place. Archived files are inert by their nature and until they are opened, their contents extracted and any executable run, then they present no immediate risk.

Long before that happens the file system shield would have scanned any newly created file (the act of extraction to your hard disk) and also scanned any executable before it is allowed to run.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Thanks for the reply.

Well I would ask why enable scanning zip/archive files in the file system shield in the first place. Archived files are inert by their nature and until they are opened, their contents extracted and any executable run, then they present no immediate risk.

Long before that happens the file system shield would have scanned any newly created file (the act of extraction to your hard disk) and also scanned any executable before it is allowed to run.
Yeah mostly agreed.
If I were Op I don't scan all archives on-access, though I want avast to scan all archive on-demand (i.e. default full scan).
You may feel we (I?) are some kind of paranoia... there are some people worry something or other which seems groundless fear. ;)

Since I got a bug report on Japanese forum, I thought I should at least report it here.
« Last Edit: November 21, 2010, 04:55:27 AM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Could you please add some more details? Such as:
- what was inside of that ZIP archive (only one infected file, multiple infected files, one infected and other clean files, nested archives with infected files, ...)
- what was the detection (name) on the infected file?
- what exactly does it mean "cleaning" - delete, move to chest... or repair?
- the "All archives" option in the File System Shield (which I wouldn't really recommend to use, but doesn't matter) only enables archive unpacking... so was also the ZIP extension added to "Scan when opening" or "Scan when writing"? (or was the "Scan all files" option checked in one of those windows?)
- was the initial detection triggered when accessing (e.g. opening) the ZIP file, or when writing (e.g. copying) it?

bong2x

  • Guest
@NON
do mean like this (see picture)
in that case the explanation is, there is an update in every software. protected to avoid the corruption.
and no anti virus can take that off.

regards!!!

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Thanks for the reply.

@igor
I asked OP to add these information. As far as my confirmation, details as follows:

Inside of the zip archive:
One or two infected file(s) (eicar / real malware) and one clean file (plain text file).

Detection Name:
Eicar / Win32:Small-NEG [Trj]

Action:
Delete / Move to chest.

Quote
- the "All archives" option in the File System Shield (which I wouldn't really recommend to use, but doesn't matter) only enables archive unpacking... so was also the ZIP extension added to "Scan when opening" or "Scan when writing"? (or was the "Scan all files" option checked in one of those windows?)
Firstly I checked "Scan all files", next added ZIP extension to "Scan when opening" option ("Scan all files" unchecked).
Now I uncheck both options, but alert continues... ???

It seems avast continues to scan added extensions even if I uncheck "Scan with custom extensions" :(
If I delete added extensions, avast stops to scan it.


Initial detection trigger:
Accessing. No alert when copying (I didn't add extensions to "Write" section).


@bong2x
do mean like this (see picture)
Unfortunately not.
This related to on-access scan, not on-demand (right-click) scan.
« Last Edit: November 17, 2010, 11:59:36 AM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Reply from the Op came.

Inside of the zip archive:
One infected file + one clean file
Two infected files + two clean files (in a directory)

Detection Name:
Win32:Parite

Action:
Move to Chest / Delete / Repair

Settings:
Only "All archives" option enabled.
No additional extensions added (both opening and writing), "Scan all files" unchecked.

Initial detection trigger:
Opening ZIP archive.
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Is there any news or required information, igor?
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Sorry for bumping up this old topic, but this issue still persists with 6.0.1000... :-\

Please fix this...
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。