Author Topic: Avast! BART CD gives inconsitent results  (Read 7960 times)

0 Members and 1 Guest are viewing this topic.

Offline finnmich

  • Newbie
  • *
  • Posts: 3
Avast! BART CD gives inconsitent results
« on: November 17, 2008, 03:08:33 PM »
Hi!

I am currently involved in a project on the topic of zero-day malware.
In this project we have used the BART CD as one of our tools, i will not go into detail on the experiments here.

When using the BART CD we scanned six different machines containing almost the same data on two different dates, with a month in between the scans.
On the second scan something strange happened, we scanned all machines with the BART CD but only two of these detected a special type of malware: WMA:Wimad [Drp]. Several hundreds of files were infected with this malware, and when we scanned the four first machines again, with the same CD, they also detected the malware.

It seems it is more or less random if this type of malware was detected.
avast! support suggested that: first scan probably deleted or unlocked something what was hiding the other infection., but no actions were performed on the file system.
The infected files were media files inside small .rar archives, no error messages were logged on the files in question.
The machines were not booted in between the scans.

Can anyone explain what has happened here? Is this some kind of bug? ???

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67247
Re: Avast! BART CD gives inconsitent results
« Reply #1 on: November 17, 2008, 09:40:23 PM »
The infected files were media files inside small .rar archives, no error messages were logged on the files in question.
Can you send the files to virus (at) avast (dot) com for analysis?
The best things in life are free.

Offline finnmich

  • Newbie
  • *
  • Posts: 3
Re: Avast! BART CD gives inconsitent results
« Reply #2 on: November 20, 2008, 11:51:42 AM »
I've sent some of the files to the email address you mentioned. Referred to this thread in the mail, haven't heard anything yet.

It would be nice to get a answer to this, as the results are very confusing to us.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11805
    • AVAST Software
Re: Avast! BART CD gives inconsitent results
« Reply #3 on: November 20, 2008, 02:33:28 PM »
You are right, there was a bug in the virus database - it was fixed about 10 days ago.

Offline finnmich

  • Newbie
  • *
  • Posts: 3
Re: Avast! BART CD gives inconsitent results
« Reply #4 on: November 24, 2008, 12:05:32 PM »
Thanks for the reply!
We really appreciate it :)