Author Topic: What does P2P Shield really do?  (Read 5879 times)

0 Members and 1 Guest are viewing this topic.

F4

  • Guest
What does P2P Shield really do?
« on: July 12, 2004, 10:52:22 AM »
Hi all,

I'm wondered how P2P Shield works, what makes me confuse is that I've tried to download so many malware form P2P network (for testing purposes) through KaZaa Lite.

But I haven't seen the P2P Shield works even if malware was saved on the disk P2P Shield didn't warn me at all untill I went to KaZaa's Shared Folder and then the Standard Shield sent me an warning windows.

What's wrong with this, Does P2P Shield really work?

My system :

Windows XP Pro
P2P Shield : high level
Standard Shield : normal level

This is some of log file form avast log viewer.

Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  
Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  
Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  
Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  
Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  
Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  
Sign of "Win32:Trojano-149 [Trj]" has been found in "D:\My Shared Folder\xxx.exe" file.  

sedina

  • Guest
Re:What does P2P Shield really do?
« Reply #1 on: July 12, 2004, 11:51:22 AM »
Hi, what is the name of executable file of KaZaa Lite you are using? Are there any scanned files note on avast! On-Access Scanner dialog (under P2P Shield)? thanks.

F4

  • Guest
Re:What does P2P Shield really do?
« Reply #2 on: July 12, 2004, 12:23:07 PM »
Hi,

> what is the name of executable file of KaZaa Lite you are using?

It is : C:\Program Files\Kazaa Lite K++\klrun.exe

KaZaa Lite K++ Version 2.4.1

> Are there any scanned files note on avast! On-Access Scanner dialog (under P2P Shield)

I didn't see anything special and I didn't see P2P Shield's log file.

Thanks



F4

  • Guest
Re:What does P2P Shield really do?
« Reply #3 on: July 12, 2004, 12:41:30 PM »
This is what I've noticed about Standard Shield.

Sometimes, especially when my computer running so many hours. when avast found a virus (I launched it for testing purposes) the on-access scanner message appearded firstly (blue-yellow box) but the Standard Shield's warning window took so long to appeared or sometimes it crashed and I have to restart my computer, this is so strange.

Thanks.


Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:What does P2P Shield really do?
« Reply #4 on: July 13, 2004, 08:43:42 AM »
We've seen this on some configuration and where we analyzed the problem it was -- guess what -- the alert sound!! Somehow the multimedia subsystem was locked at the moment it should've played the siren and timed out or something...

Try disabling the sound associated to the virus event. It may help (however odd this may sound)... :)

Vlk
If at first you don't succeed, then skydiving's not for you.

sedina

  • Guest
Re:What does P2P Shield really do?
« Reply #5 on: July 14, 2004, 04:12:47 PM »
please, can you check the name of process of running Kazaa? You can find it in Task Manger: On Aplication Tab select Kazaa, then right mouse click a select Go to process. Is this process KAZAALITE.KPP???
>I didn't see anything special and I didn't see P2P Shield's log file
So, it means that Last scanned field for P2P shield is empty???

thanks!

F4

  • Guest
Re:What does P2P Shield really do?
« Reply #6 on: July 15, 2004, 05:26:21 AM »
> please, can you check the name of process of running Kazaa? You can find it in Task Manger: On Aplication Tab select Kazaa, then right mouse click a select Go to process. Is this process KAZAALITE.KPP???

No, the process name is Kazaa.kpp

> So, it means that Last scanned field for P2P shield is empty???

Yes, I've tried it again and the result is the same it goes empty. P2P Shield doesn't scan files transfer via KaZaa Lite when it is saved to disk.

sedina

  • Guest
Re:What does P2P Shield really do?
« Reply #7 on: July 15, 2004, 09:34:13 AM »
Hi, there are various names for process's names for different versions of Kazaa Lite, so this is the problem. This version of Kazaa Lite is not guarded by avast!. I have fixed it, so next program update will patch it and everything should be fine. Sorry for this bug ;-(