Author Topic: Question  (Read 9527 times)

0 Members and 1 Guest are viewing this topic.

qaz79

  • Guest
Question
« on: March 30, 2006, 01:16:20 AM »
What does Unable to scan: The file is a decompression bomb mean?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Question
« Reply #1 on: March 30, 2006, 03:04:02 AM »
What does Unable to scan: The file is a decompression bomb mean?

Decompression bomb is just something that unpacks to an unusually big amount of data even though it's rather small (i.e. has a high compression ratio, for example). It's nothing to worry about, you are just informed that avast! will not try to unpack the archive (you may not even know that it's an archive, but it seems like it is) because it may take VERY long to process.
(quoted from Igor: http://forum.avast.com/index.php?topic=15389.msg131213#msg131213)

Decompression bomb is a file that may be rather small, but decompresses to an enormous amount of data (when processed as a packed archive). Such file are not malicious per se, but they may block an antivirus program when it tries to scan them.
This kind of files is rather hard to detect (and avoid) precisely - so, it is possible that there are some false alarms. It's not a big problem in this case, however - the "decompression bomb" announcement actually means something like "The file has a very high, maybe even suspicious, compression ratio and the AV is not going to scan the archive content".

I'd suggest to ignore these files.
But you can change values into avast4.ini file to configure how avast should work with these files.
Click 'Settings' in my signature for more info  ;)
The best things in life are free.

qaz79

  • Guest
Re: Question
« Reply #2 on: March 30, 2006, 03:12:21 AM »
how did that happen? it never appeared before.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Question
« Reply #3 on: March 30, 2006, 03:29:01 AM »
how did that happen? it never appeared before.
Which is the file being shown as a decompression bomb?
Maybe a new one, that wasn't in your system before?
The best things in life are free.

qaz79

  • Guest
Re: Question
« Reply #4 on: March 30, 2006, 03:51:40 AM »
they are one of the bonic project's that i'm running. it's called climateprediction.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Question
« Reply #5 on: March 30, 2006, 03:59:34 AM »
they are one of the bonic project's that i'm running. it's called climateprediction.
And them? Are the new ones? These could explain they were not a problem before.
Anyway, decompression bombs could not be such a problem... you may have set the proper configuration if you get rid from this alert. You need to change avast4.ini file. Click 'Settings' in my signature.
But you can just ignore the message the most of the time, specially if you trust the source of the files...
The best things in life are free.

qaz79

  • Guest
Re: Question
« Reply #6 on: March 30, 2006, 04:30:48 AM »
so then i don't need to move it to the virus cheats?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Question
« Reply #7 on: March 31, 2006, 03:17:30 AM »
so then i don't need to move it to the virus cheats?
Most probably not.
You can:
1. Check these files against JOTTI and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com
2. If they are false positives, you can add these files to the exclusion lists.

Well, they're not infected as far I can see. Decompression bombs is a prevention test, not a virus itself.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Question
« Reply #8 on: March 31, 2006, 02:00:47 PM »
so then i don't need to move it to the virus cheats?
Whislt you may not need to send it to the virus chest (after checking with Jotti, etc.) if it is a false positive detection.

If it is indeed a false positive, add it to the exclusions lists (Standard Shield, Customize, Advanced and Program Settings, Exclusions) and check scan it periodically using the ashQuick scan (right click scan), when it is no longer detected then remove it from the exclusions.
Also see (Mini Sticky) False Positives
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

qaz79

  • Guest
Re: Question
« Reply #9 on: March 31, 2006, 09:21:49 PM »
JOTTI said that those files where clean. Should I send it to avast?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Question
« Reply #10 on: March 31, 2006, 09:50:55 PM »
JOTTI said that those files where clean. Should I send it to avast?
No need for this.
There are two exclusion lists: one in program settings, for the on-demand scanning.
And other in Standard Shield settings, for the on-access protection (residents).
Wildcards are allowed  8)
The best things in life are free.

qaz79

  • Guest
Re: Question
« Reply #11 on: April 01, 2006, 01:54:08 AM »
I just got infected with a MS06-001 WMF Exploit. I tried moving it to Virus Chest and Repair because it is being used by another program. How do I get rid of it?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Question
« Reply #12 on: April 01, 2006, 02:10:10 AM »
When reporting something like this please help us to help you.
- What OS are you using? is it up to date?
probably not as the wmf vulnerability has been patched by MS, so a visit to windows update is in order.

- What was the virus name, what was the file name, where was it found
  example (C:\windows\system32\infected-file-name.xxx)?
I would have thought it would have first gone through the web shield, which should have caught it (if standard shield can detected so should web shield), so it would be interesting to know how it got on your system.

If you have XP try scheduling a boot-time scan from within avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

qaz79

  • Guest
Re: Question
« Reply #13 on: April 01, 2006, 02:17:56 AM »
Windows XP Home Edition Service Pack 2

Program and Vps are up to date

Malware name MS06-001 WMF Exploit

Malware type Virus/Worm

File name C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\SLKZ8ZC3\M3BqQ1JFVXl0Sm9BQUhRSjNzRUFBQUNR[1].wmf

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Question
« Reply #14 on: April 01, 2006, 02:57:06 AM »
I just got infected with a MS06-001 WMF Exploit. I tried moving it to Virus Chest and Repair because it is being used by another program. How do I get rid of it?

Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.

Access denied means, generally, that the file is in use by another process (program) and cannot be repaired/cleaned/moved/handled by avast!
The best things in life are free.