Author Topic: Avast leaves virus on system after unpacking  (Read 4544 times)

0 Members and 1 Guest are viewing this topic.

sowen

  • Guest
Avast leaves virus on system after unpacking
« on: December 31, 2003, 10:51:08 AM »
I run a full system scan (all disks, all files) on the computer running my mail-server. The eicar virus was contained in an email which I had been using to test.

Avast correctly detected the virus in my email (very impressive, because it's in SMTP/uuencode format :)).

Later in the scan, Avast found the virus again in
       C:\WINDOWS\Temp\_avast4_\unp21303\eicar.com

Now I know I could exclude the c:\windows\temp\_avast4_ directory, but it seems to me that Avast should clean up after unpacking virusses, rather than leaving virusses on the system.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Avast leaves virus on system after unpacking
« Reply #1 on: December 31, 2003, 10:56:45 AM »
Hmm, the proper cleanup of temp files is something we fight all the time... Avast now features about 20 independent unpackers and to keep them all clean up things propertly is not easy...

I'd need more info: are you sure that this particular eicar is related to the one you sent via email? (I mean, you are appearently doing a lot of experiments so I want to make sure that it's really the MIME unpacker...). Maybe a retry of that 'test' would be useful...


Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

sowen

  • Guest
Re:Avast leaves virus on system after unpacking
« Reply #2 on: December 31, 2003, 10:58:37 AM »
I'll retry the test this evening. Or, rather, I'll let my system do it, as I'll probably be out of it on champagne!  :D

Although if it isn't the scan, then another part of Avast is leaving the virus on the system.
« Last Edit: December 31, 2003, 10:59:31 AM by sowen »

sowen

  • Guest
Re:Avast leaves virus on system after unpacking
« Reply #3 on: December 31, 2003, 11:06:26 AM »
An update on that: I just checked the c:\windows\temp\_avast4_ directory, and there are several files with names beginning with 'unp', plus a file called 'clnr0.dll'.

I checked the contents of all the 'unp' files, and they all begin with the letters "PK", so my guess is the PKZIP unpacker isn't cleaning up properly.
« Last Edit: December 31, 2003, 11:07:18 AM by sowen »

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Avast leaves virus on system after unpacking
« Reply #4 on: December 31, 2003, 11:28:02 AM »
Actually if they begin with PK it doesn't mean it's the ZIP unpacker at all... :P I mean, the unp* files are the unpacked files, not the containers (that the unpacker is unpacking). I.e. these are ZIP files that were originally contained in a parent container.

Maybe you could identify the files by opening them in WinZIP... (their contents could ring the bell)

Vlk
If at first you don't succeed, then skydiving's not for you.

sowen

  • Guest
Re:Avast leaves virus on system after unpacking
« Reply #5 on: December 31, 2003, 11:43:41 AM »

Well I was just guessing ;)

The files are apparently valid PKZIP files, as I can open them with WinZip, but all are empty (i.e. contain no files). Perhaps they got cleaned during the scan last night.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Avast leaves virus on system after unpacking
« Reply #6 on: December 31, 2003, 11:45:06 AM »
Were you testing ZIPed eicars (and their deletion)?

After all, it might've been be the ZIP unpacker then :-X
If at first you don't succeed, then skydiving's not for you.

sowen

  • Guest
Re:Avast leaves virus on system after unpacking
« Reply #7 on: December 31, 2003, 11:50:38 AM »

Yes, I was testing the eicar virus in a zip. I can't seem to reproduce the problem however. :-\

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Avast leaves virus on system after unpacking
« Reply #8 on: December 31, 2003, 11:54:05 AM »
Try attaching a ZIPped eicar to an email and upon detection, tell avast to delete it. See what happens.

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

sowen

  • Guest
Re:Avast leaves virus on system after unpacking
« Reply #9 on: December 31, 2003, 12:52:36 PM »

Nope, I can't seem to reproduce this one, using either email attachments or by creating tasks and schedules. Perhaps it will happen again during the night-time scan, when nobody's watching. ::)