Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: REDACTED on February 09, 2015, 11:54:56 AM

Title: Avast and Eicar
Post by: REDACTED on February 09, 2015, 11:54:56 AM
Hi.

I was testing Avast with the http://www.amtso.org/check-desktop site and when trying to download one of the files Avast showed an alert (blocked a harmful webpage or file) but I could still download the file to my desktop.

Title: Re: Avast and Eicar
Post by: Eddy on February 09, 2015, 06:13:40 PM
PUP is not malware.
It is potentially unwanted.
avast is telling you this if you have pup detection enabled, but it still is your choice if you want to download/install it.
Title: Re: Avast and Eicar
Post by: REDACTED on February 09, 2015, 06:27:15 PM
It also happens with the cloud test file.

Title: Re: Avast and Eicar
Post by: Eddy on February 09, 2015, 06:32:22 PM
And what is your question/problem ?
Title: Re: Avast and Eicar
Post by: REDACTED on February 09, 2015, 07:33:30 PM
And what is your question/problem ?

Why is the file allowed to download?  ::)
Title: Re: Avast and Eicar
Post by: Eddy on February 09, 2015, 07:36:25 PM
I already told you.
Title: Re: Avast and Eicar
Post by: Pondus on February 09, 2015, 07:39:42 PM
Maybe why ..... filerepmalware = file with low reputation / new file / few users ...... not confirmed malicious

Title: Re: Avast and Eicar
Post by: REDACTED on February 09, 2015, 07:42:49 PM
Avast UI -> Settings -> Active Protection -> Web Shield (Customize) -> Actions -> PUP

Try to change these settings.
Maybe it can affect the behavior of Avast in the desired direction.
Title: Re: Avast and Eicar
Post by: essexboy on February 09, 2015, 07:52:16 PM
With PUP settings enabled this is the result.  No file downloaded

Title: Re: Avast and Eicar
Post by: REDACTED on February 09, 2015, 08:16:38 PM
With PUP settings enabled this is the result.  No file downloaded

I had PUP enabled but I see you're using IE (I'm using Palemoon).
So I tried it with IE and like in your screenshot the file couldn't be downloaded... this is strange.
Title: Re: Avast and Eicar
Post by: DavidR on February 09, 2015, 08:42:52 PM
As far as I'm aware the Palemoon browser isn't supported (64bit version of based on Mozilla Firefox).
Title: Re: Avast and Eicar
Post by: REDACTED on February 09, 2015, 10:07:37 PM
As far as I'm aware the Palemoon browser isn't supported (64bit version of based on Mozilla Firefox).

It's a 32 bit FF based.
But what do you mean "not supported". Is the download blocking dependant on the browser?
Title: Re: Avast and Eicar
Post by: DavidR on February 09, 2015, 11:05:44 PM
Not supported in that the web shield can't monitor the web traffic - hence it gets downloaded as you found, instead of being intercepted early in the download.

So the download is browser and web shield dependant - e.g. currently the PaleMoon is unsupported by the web shield.

It might be 32bit firefox based, but PaleMoon is 64bit.
Title: Re: Avast and Eicar
Post by: REDACTED on February 09, 2015, 11:44:48 PM
Not supported in that the web shield can't monitor the web traffic - hence it gets downloaded as you found, instead of being intercepted early in the download.
I see... I think.

It might be 32bit firefox based, but PaleMoon is 64bit.
Nope, although there's a x64 version.
Title: Re: Avast and Eicar
Post by: abruptum on February 09, 2015, 11:46:29 PM
Guys,I don't know what you are talking about.
I'm using Pale Moon (x86) as default browser and Web Shield is working flawlessly.
If I remember correctly File Shield is not working with Pale Moon.It works with FF,Chrome and IE.
Title: Re: Avast and Eicar
Post by: REDACTED on February 10, 2015, 12:06:48 AM
I'm using Pale Moon (x86) as default browser and Web Shield is working flawlessly.

Could you test with the link in my first post? Particularly the PUA test (number 3).
Title: Re: Avast and Eicar
Post by: abruptum on February 10, 2015, 12:24:14 AM
Sorry,YandexDNS Safe is blocking your link.I'll try it tomorrow with different DNS.
It looks like File Shield is not working since you were able to download the file.
It is past midnight in Croatia and I'm going to bed.
Title: Re: Avast and Eicar
Post by: bob3160 on February 10, 2015, 02:21:53 PM
Is PaleMoon using https everywhere ??? If so, Avast can't scan any website.
Title: Re: Avast and Eicar
Post by: REDACTED on February 10, 2015, 02:33:47 PM
Is PaleMoon using https everywhere ???

It isn't.
Title: Re: Avast and Eicar
Post by: bob3160 on February 10, 2015, 02:35:19 PM
Is PaleMoon using https everywhere ???

It isn't.
Ok thanks.
Title: Re: Avast and Eicar
Post by: abruptum on February 10, 2015, 02:51:07 PM
@Jomm
I can confirm your findings.I was able to download PUP file after Web Shield warning.
Title: Re: Avast and Eicar
Post by: REDACTED on February 10, 2015, 03:12:06 PM
@Jomm
I can confirm your findings.I was able to download PUP file after Web Shield warning.

Many thanks.
Title: Re: Avast and Eicar
Post by: DavidR on February 10, 2015, 04:02:53 PM
Sorry,YandexDNS Safe is blocking your link.I'll try it tomorrow with different DNS.
It looks like File Shield is not working since you were able to download the file.
It is past midnight in Croatia and I'm going to bed.

Here there is another issue as can be seen from the OPs first image the web shield is detecting a PUP - unless the file system shield settings are also set to scan for PUPs (off by default) ? then it won't alert.

@Jomm
I can confirm your findings.I was able to download PUP file after Web Shield warning.

Many thanks.

OK, reading further into this problem, the web shield issues an abort command to try to stop the download completing.

Unfortunately some browsers don't obey that and see it as a failed download and continue to completion.