Author Topic: Can avast! correctly scan GHOST backups?  (Read 4875 times)

0 Members and 1 Guest are viewing this topic.

Offline larrymcg

  • Full Member
  • ***
  • Posts: 100
Can avast! correctly scan GHOST backups?
« on: August 19, 2010, 01:13:34 AM »
Using avast! 4.8 Home (4.8.1368).

I have seen lots of posts about avast finding trojans, etc. in Norton Ghost backups.
Can avast correctly read the backups?  I think they are compressed and in a proprietary format  (.v2i and .iv2i files).
If avast just reads the blocks in these files and looks for something of interest, isn't avast essentially scanning garbage?

--Larry

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Can avast! correctly scan GHOST backups?
« Reply #1 on: August 19, 2010, 02:40:53 AM »
Indeed, these packers aren't into the ones supported by avast. But I think avast scanners have a particular way to scan these files as any other proprietary format.
Generally, these backup files could be added to the exclusion lists.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89116
  • No support PMs thanks
Re: Can avast! correctly scan GHOST backups?
« Reply #2 on: August 19, 2010, 02:59:22 AM »
I have Drive Image 7.1 which was bought out by Symantec and combined with Norton Ghost, it also uses the .v2i file format and avast has no problem in scanning that file and I haven't had any false positive detections. But it doesn't unpack it, so there might be an occasion where a highly compressed file type scanned in its raw state might throw up an anomaly and give a signature match.

Before I do my weekly Drive Image 7.1 image backup I run my avast scan and that ensures I have a clean state so my v2i image backup file should be clean. Because these files are very large so would take time to scan I exclude the location/partition/drive Folder where I store my last 5 image backups (F:\Drive-Images\*.v2i) from scans. The * being a wildcard for the multiple file names.

By specifying the file type *.v2i you are reducing any possible security hole if you were to exclude the whole folder/drive that you store them.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline larrymcg

  • Full Member
  • ***
  • Posts: 100
Re: Can avast! correctly scan GHOST backups?
« Reply #3 on: August 19, 2010, 06:07:51 AM »
Those two replies are not totally clear to me but.  It's my opinion that the only thing it makes sense to scan is the data, not some compressed or otherwise modified version of the data.  To me, compression is a (admittedly simple) form of encryption.  Looking at the encrypted data is a useless action and you can't draw any conclusions about what the data actually is unless you know how to decrypt (i.e., decompress) it first.

So, why would anyone think there is validity to avast's claim that a Ghost backup image contains a trojan or virus?

I assume that scanning, for example, ZIP files makes sense since avast could get to the unZIPped version of the data.  Right?

--Larry

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Can avast! correctly scan GHOST backups?
« Reply #4 on: August 19, 2010, 01:21:46 PM »
So, why would anyone think there is validity to avast's claim that a Ghost backup image contains a trojan or virus?
It could be (most probably) a false positive.
But, look, avast should scan all files, regardless they are encrypted or compressed. At least to check if it is inert. If it does not do that, how could it be sure it's a Ghost file? A lot of malware use compression techniques to by pass antivirus.

I assume that scanning, for example, ZIP files makes sense since avast could get to the unZIPped version of the data.  Right?
Yes, you're right.
The best things in life are free.