Author Topic: 2nd layer protection for USB drives: MCShield  (Read 132321 times)

0 Members and 1 Guest are viewing this topic.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: 2nd layer protection for USB drives: MCShield
« Reply #195 on: January 25, 2014, 08:46:03 PM »
Thank you. I will report this ...

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: 2nd layer protection for USB drives: MCShield
« Reply #196 on: January 25, 2014, 11:58:14 PM »
On my Dell I5 Laptop - Windows 8.1 Pro 64 bit, display is 1600X900
I don't have that problem:



Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: 2nd layer protection for USB drives: MCShield
« Reply #197 on: January 26, 2014, 12:14:15 AM »
I see, thanks for SS.

Please just tell me the screen resolution so I can check what may be the problem.

Just got back

1680x1050  ;)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: 2nd layer protection for USB drives: MCShield
« Reply #198 on: January 26, 2014, 02:30:41 PM »
Thank you schmidthouse, ky331 and to you Bob, thank you all again. We do appreciate any feedback.  ;)


FYI:
dr_Bora has been reproduced the error. We are working on the problem...
« Last Edit: January 26, 2014, 02:34:46 PM by magna86 »

Offline ky331

  • Sr. Member
  • ****
  • Posts: 303
Re: 2nd layer protection for USB drives: MCShield
« Reply #199 on: January 26, 2014, 04:10:27 PM »
"dr_Bora has been reproduced the error."

Is there a preliminary conjecture as to what configurations cause the problem? --- what makes it happen on some particular systems but not others?
Lenovo T530 laptop, Intel Core i5-3320M @ 2.60 GHz, 8GB RAM, Windows 7 Pro SP1 (64-bit), avast! 17 Free, MBAM3 Pro, Windows Firewall, MVPS HOSTS file, OpenDNS Family Shield, Zemana AntiLogger Free, SpywareBlaster, IE11 & Firefox [both using WOT (IE set to WARN, FF set to BLOCK)], WinPatrol PLUS, uBlock Origin, MBAE, MCShield, CryptoPrevent, SAS (on-demand scanner). 
[I believe computer-users who sandbox (Sandboxie) are acting prudently.]

dr_Bora

  • Guest
Re: 2nd layer protection for USB drives: MCShield
« Reply #200 on: January 26, 2014, 04:36:31 PM »
Hello.
The problem is related to DPI settings on the PC ("size of text and other items").
We're looking into the possibilities... It's not really the simplest one to fix.

Just tell me this: did you guys change the settings yourself or was it done by Windows?

Offline ky331

  • Sr. Member
  • ****
  • Posts: 303
Re: 2nd layer protection for USB drives: MCShield
« Reply #201 on: January 26, 2014, 04:57:45 PM »
Looking at my Display setting,  I see it's set for Medium:  125% (which I believe equates to 120 DPI).   It's been so long, but I'd have to say I opted for that myself... my eyes are getting worse, so it's easier to see things when enlarged.

My video driver updated itself automatically about two months ago... I was not happy when it did so without checking with me first... I would NOT have permitted it, had I been asked.

I also accidentally adjusted my Display/Color settings about a month ago... and couldn't figure out how to get back the previous settings... and have settled on an acceptable variation.
Lenovo T530 laptop, Intel Core i5-3320M @ 2.60 GHz, 8GB RAM, Windows 7 Pro SP1 (64-bit), avast! 17 Free, MBAM3 Pro, Windows Firewall, MVPS HOSTS file, OpenDNS Family Shield, Zemana AntiLogger Free, SpywareBlaster, IE11 & Firefox [both using WOT (IE set to WARN, FF set to BLOCK)], WinPatrol PLUS, uBlock Origin, MBAE, MCShield, CryptoPrevent, SAS (on-demand scanner). 
[I believe computer-users who sandbox (Sandboxie) are acting prudently.]

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: 2nd layer protection for USB drives: MCShield
« Reply #202 on: January 26, 2014, 06:36:17 PM »
Hello.
The problem is related to DPI settings on the PC ("size of text and other items").
We're looking into the possibilities... It's not really the simplest one to fix.

Just tell me this: did you guys change the settings yourself or was it done by Windows?

I didn't change any settings that I'm aware of?  ???

Offline Simion

  • Advanced Poster
  • **
  • Posts: 976
Re: 2nd layer protection for USB drives: MCShield
« Reply #203 on: February 02, 2014, 03:53:17 PM »
MCShield v3.0.4.27

Quote
v 3.0.4.27: 2nd February 2014.

- fixed an issue that caused the scanner to crash on certain locked files;
- updated Vietnamese language.

http://www.mcshield.net/

juuki

  • Guest
Re: 2nd layer protection for USB drives: MCShield
« Reply #204 on: March 12, 2014, 06:31:17 PM »
The quarantine and occasional detections that AVs make in there... Yes, I agree that this is not perfect and the other programmer and I discussed the encryption many times, but we never got to making it. You know, real life, jobs and stuff like that. Hopefully, we'll get to it one day.

Is the quarantine safe? Well, malware in that folder can't start by itself. So, unless you go there and start clicking on files you know to be malicious, you won't have any problems.

If MCshield detect any malware and quarantine it, avast detect that quarantine file and delite it.
As encryption havent add to program is there any other way to avoit this "conflict"?

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: 2nd layer protection for USB drives: MCShield
« Reply #205 on: March 12, 2014, 06:58:25 PM »
Hi juuki,

If MCshield detect any malware and quarantine it, avast detect that quarantine file and delite it.

Just to clarify. Any malware with intent to be transmitted via removable drives.  :)



As encryption havent add to program is there any other way to avoit this "conflict"?

Encryption is added to MCS's Quarantine. Are you sure you have the latest version installed?

Avast shouldn't touch MCS's Quarantine. If "Quarantine" conflict does exists (there is always a possibility for avast to detects malicious files in MCS's Quarantine based on his heuristics check), little can be done I think except to clear the MCS Quarantine folder as I do not see that as a problem. :)


« Last Edit: March 12, 2014, 07:00:06 PM by magna86 »

juuki

  • Guest
Re: 2nd layer protection for USB drives: MCShield
« Reply #206 on: March 12, 2014, 08:19:52 PM »

Encryption is added to MCS's Quarantine. Are you sure you have the latest version installed?


I have last version (as you can see in attachment, left is last downloaded version from theit website and right is my installed version).
Encryption is not added to MCS. Have no idea where you get that information.


Avast shouldn't touch MCS's Quarantine. If "Quarantine" conflict does exists (there is always a possibility for avast to detects malicious files in MCS's Quarantine based on his heuristics check), little can be done I think except to clear the MCS Quarantine folder as I do not see that as a problem. :)

Avast scan all changes made so when MCS send file to quarantine Avast also scan that quarantine folder.

In my case i insert USB. MCS detected 4 malware, i delite 3 and 1 is ingored.

Here is log:
Code: [Select]
MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.4.27 / DB: 2014.3.10.1 / Windows 7 <<<


12.3.2014. 17:05:17 > Drive F: - scan started (no label ~1960 MB, FAT flash drive )...


>>> F:\AVTORUN\Desktop.ini > ignored (user request). (MD5: f05d6580608901fa2aea2a1e711a8ff4)

> F:\AVTORUN
> F:\AVTORUN\Desktop.ini (MD5: f05d6580608901fa2aea2a1e711a8ff4)
> F:\AVTORUN\slovenec.exe (MD5: eb722f24b9affb0ecaf41cff09d0b241)

>>> F:\AVTORUN - Malware (folder) > Deleted. (14.03.12. 17.07 AVTORUN.45284)

> F:\ZNOJE
> F:\ZNOJE\Desktop.ini (MD5: f05d6580608901fa2aea2a1e711a8ff4)
> F:\ZNOJE\misejaja.exe (MD5: d6f30cf036932f1511c6a66e886a3868)

>>> F:\ZNOJE - Malware (folder) > Deleted. (14.03.12. 17.07 ZNOJE.314628)

> F:\NATASA
> F:\NATASA\Desktop.ini (MD5: f05d6580608901fa2aea2a1e711a8ff4)
> F:\NATASA\pazhin.exe (MD5: d5a130c139ebb1b133916823a065f3b5)

>>> F:\NATASA - Malware (folder) > Deleted. (14.03.12. 17.07 NATASA.118917)

>>> F:\xfl3hx.exe - Suspicious > Renamed. (MD5: 8b1fad2127a9920b4cf2cd6ff9306ce5)


=> Malicious files   : 6/6 deleted.
=> Malicious folders : 3/3 deleted.
=> Suspicious files  : 1/1 renamed.

____________________________________________

::::: Scan duration: 2min 15sec ::::::::::::
____________________________________________

after that Avast automaticly scan MCS quarantine, detect and delite that three malware.

Here is Avast FileSystemShield log:
Code: [Select]
* avast! Real-time Shield Scan Report
* This file is generated automatically
*
* Started on: Wednesday, March 12, 2014 4:20:49 PM
*

12.3.2014. 17:07:22 C:\ProgramData\MCShield\Quarantine\14.03.12. 17.07 AVTORUN.45284\slovenec.exe|>[UPX] [L] Win32:MalOb-IJ [Cryp] (0)
File was successfully moved to chest...
12.3.2014. 17:07:28 C:\ProgramData\MCShield\Quarantine\14.03.12. 17.07 ZNOJE.314628\misejaja.exe [L] Win32:Evo-gen [Susp] (0)
File was successfully moved to chest...
12.3.2014. 17:07:29 C:\ProgramData\MCShield\Quarantine\14.03.12. 17.07 NATASA.118917\pazhin.exe|>[UPX] [L] Win32:MalOb-AI [Cryp] (0)
File was successfully moved to chest...

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: 2nd layer protection for USB drives: MCShield
« Reply #207 on: March 12, 2014, 09:38:36 PM »
Hi juuki,

Quote
Encryption is not added to MCS. Have no idea where you get that information.
Juuki believe me, I know.  ;D
Encription is added to MCShield Quarantine since version 2 (2.2.3.15) in October 2012.
public info: official site > changelog


Quote
In my case i insert USB. MCS detected 4 malware, i delite 3 and 1 is ingored.
I understand.

By logs my guess are that MCS has attempt to set and pack the malicious files in his Quarantine but avast! has block that operation. avast! has the routine to scan all new detected USB devices. Conflict may arises when AV (in this case avast!) wants to be the first in scanning, thereby not allowing access to the disk. MCShield attempts to access to disk as well to preform scanning and glitch occurs.

I would recommend as solution to disable that routine to allow MCShield that part of job if you will.  That should be the solution for your problem. Or . . set the MCS's Quarantine folder %path% as an exception in avast!. Quarantine is located in programdata folder.

Code: [Select]
%ProgramData%\MCShield\Quarantine
Anyway, I will preform some additional testing and report to dr_Bora.

Or you can use our contact support form.
http://www.mcshield.net/contactus.html

Thank you for your feedback.


juuki

  • Guest
Re: 2nd layer protection for USB drives: MCShield
« Reply #208 on: March 13, 2014, 04:36:54 PM »
By logs my guess are that MCS has attempt to set and pack the malicious files in his Quarantine but avast! has block that operation. avast! has the routine to scan all new detected USB devices. Conflict may arises when AV (in this case avast!) wants to be the first in scanning, thereby not allowing access to the disk. MCShield attempts to access to disk as well to preform scanning and glitch occurs.

MCS detect and send malicious files in quarantine. After that Avast detect that "new" files in quarantine and delite it or send it to ist quarantine.
Avast dont block any MCS operation.

Also Avast dont scan new detected USB devices, thats why is needed this 2nd layer protection for USB devices. So there is no conflict between Avast and MCS.

I would recommend as solution to disable that routine to allow MCShield that part of job if you will.  That should be the solution for your problem. Or . . set the MCS's Quarantine folder %path% as an exception in avast!. Quarantine is located in programdata folder.

Code: [Select]
%ProgramData%\MCShield\Quarantine

As solution i add exclusion in Avast (File System Shield) MCS Quarantine folder:
Code: [Select]
C:\ProgramData\MCShield\Quarantine\ selected R and W not X so if any file from quarantine folder try to execute it will be scanned by Avast.

Anyway, I will preform some additional testing and report to dr_Bora.

I try test myself with this settings but MCS cant detect EICAR test file so i have no idea how to test it, and will it work.

Thank you for your feedback.

No problem, im always here to help ;)

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: 2nd layer protection for USB drives: MCShield
« Reply #209 on: March 13, 2014, 11:09:07 PM »
Also Avast dont scan new detected USB devices, thats why is needed this 2nd layer protection for USB devices. So there is no conflict between Avast and MCS.
Not really true. avast! DOES scan any accessed file in the USB devices. Like MCS, it does not scan ALL the files in the USB drive.
I also use MCS as a 2nd layer.
The best things in life are free.