Author Topic: Possible bug - issue - with scanning?  (Read 3843 times)

0 Members and 1 Guest are viewing this topic.

Kobra

  • Guest
Possible bug - issue - with scanning?
« on: June 16, 2004, 11:24:39 PM »
I was running some tests on Avast today again. So I purposely downloaded a few trojan-droppers on my test machine to infect it.  Avast did reasonably well, missing a few things.  However, one of the main things it missed was the actually dropper itself. While picking up the trojans it dropped at the time, it missed the vehicle, leaving the vehicle on the computer, and in ram to keep dropping.

However, when I went to send a sample of the dropper to Avast, the email plugin Heuristics picked it up and blocked it.

I did notice a wierd, apparently debugger related message when I tried to manually scan the file, it said "UnnamedStream_1" and failed to recognize the dropper within.  Attached is the screenshot.



Comments? Anything going wrong here?   I know exactly how to remove this trojan dropper, so removal isn't an issue. I just want Avast to be able to find protocols like this, and deal with them, because right now its not!

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re:Possible bug - issue - with scanning?
« Reply #1 on: June 17, 2004, 12:16:19 AM »
It's the e-mail heuristic - it didn't flag the file as infected, just as suspicious; I'd say it's simply because it has an .exe extension; check your heuristic settings for the e-mail provider to make sure.

UnnamedStream_1 comes from the NTFS Stream archiver module - it's an NTFS stream extracted from the file. Don't ask me how it got there... I noticed it occasionally in files saved from Outlook Express attachments. When I traced the code, the Windows API really returned information about an additional stream (it disappeared on reboot, however).

Kobra

  • Guest
Re:Possible bug - issue - with scanning?
« Reply #2 on: June 17, 2004, 12:29:38 AM »
Ahh, an ADS.. Ok, shoulda known..

As for that Trojan Launcher, i'll send it in via email, its quite malicious, and enjoys downloading trojans to your box.  ;D

I sent in a further 22 samples yesterday, hopefully you guys got them.  Confirmed them to be malicious samples with KAV, RAV and DrWeb sweeps on them.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:Possible bug - issue - with scanning?
« Reply #3 on: June 17, 2004, 08:45:00 AM »
As a antivirusvirus "expert" you should know,that if you want to transport such objects you need to put them in container (usually ZIP archive with password "virus",or even stronger archive like 7-zip),so mail servers don't interfer with the sample while its being sent over multiple machines.
Visit my webpage Angry Sheep Blog

Kobra

  • Guest
Re:Possible bug - issue - with scanning?
« Reply #4 on: June 17, 2004, 06:16:22 PM »
As a antivirusvirus "expert" you should know,that if you want to transport such objects you need to put them in container (usually ZIP archive with password "virus",or even stronger archive like 7-zip),so mail servers don't interfer with the sample while its being sent over multiple machines.

Duh, you don't think I know that? LOL  I've sent out about 1200 samples in the last month, to various investigators and av companies.

Obviously in this case, I was too lazy to zip it, which was fine really, it tested Avasts outbound scanning to make sure it was working right.  :P

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:Possible bug - issue - with scanning?
« Reply #5 on: June 17, 2004, 07:01:10 PM »
Yeah yeah excuses :P
Visit my webpage Angry Sheep Blog