Author Topic: Is this decompression bomb something to be worried about?  (Read 1836 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Is this decompression bomb something to be worried about?
« on: December 26, 2016, 06:08:58 PM »
I just did a clean install and ran a quick scan, and it said that this couldn't be scanned: Users/Me/Appdata/Local/TileDataLayer/Database/EDB.chk|>>[] because it was a decompression bomb. I've never seen this kind of thing before, and I wiped all my drives when doing the clean install. Is this something to worry about?

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89292
  • No support PMs thanks
Re: Is this decompression bomb something to be worried about?
« Reply #1 on: December 26, 2016, 06:21:59 PM »
Short answer no.

Longer answer:
- Decompression Bomb, a file that is highly compressed, which could be very large when decompressed. This used to be a tactic long ago to swamp the system.

The name really is the most dangerous thing about this and I wish they would change it or simply not report it, a real PITA.

These highly compressed files are generally 'archive' files which are inert, don't present an immediate risk until they are unpacked. If you happen to select 'All packers' in your on-demand scans then you are more likely to come across this type of thing. Personally it is a waste of time scanning 'all packers' and that is why it isn't enabled by default.

A search for Decompression Bomb, should have returned many such topics.

You could have saved some hassle and time by asking the question before using the nuclear option.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: Is this decompression bomb something to be worried about?
« Reply #2 on: December 26, 2016, 07:42:15 PM »
Short answer no.

Longer answer:
- Decompression Bomb, a file that is highly compressed, which could be very large when decompressed. This used to be a tactic long ago to swamp the system.

The name really is the most dangerous thing about this and I wish they would change it or simply not report it, a real PITA.

These highly compressed files are generally 'archive' files which are inert, don't present an immediate risk until they are unpacked. If you happen to select 'All packers' in your on-demand scans then you are more likely to come across this type of thing. Personally it is a waste of time scanning 'all packers' and that is why it isn't enabled by default.

A search for Decompression Bomb, should have returned many such topics.

You could have saved some hassle and time by asking the question before using the nuclear option.

Ah okay, thanks. I didn't do a clean install because I found this, rather I just found it after doing the clean install. Anyways, I guess thats why I saw it this time, since I had never checked the "All packers" option before. So I should just leave it alone? If it has a chance to be dangerous i'd rather just remove it.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89292
  • No support PMs thanks
Re: Is this decompression bomb something to be worried about?
« Reply #3 on: December 26, 2016, 08:32:09 PM »
You're welcome.

Leave the All packers at the default settings, avast does have four archive types that will be scanned, typically these are self-extracting archives.

For the others archive files are essentially inert and or dormant. Should a program try to open an archive, then the avast File System Shield (resident, on-access) scanner will scan the unpacked files.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security