Author Topic: avast! doesn't recognize Eicar Virus in an archiv and later  (Read 4322 times)

0 Members and 1 Guest are viewing this topic.

DonMatze

  • Guest
Hello,
first I'll describe the scenario:
I'm using Windows 7 with SP1 and avast! Free 6.0.1091. The virus database is 110526-0.
All protection modules are activated exept the mail modul. I use "scan whole file" (don't know how you call this in engish. I've got the german version).
The file is a self-extracting rar file (.exe) and contains an other rar archive. The second one is password crypted and contains a (VisualBasic written) "Hello World",
with the Eicar Test Virus in the ADS. If I download the VB file directly, avast! will detect it.
The first archive contains also a .bat file, which encrypts the second one. At this point my avast! fails.
The datasystem monitoring module doesn't detect the written Eicar virus. I can execute the "Hello World" programme and nothing happens.
First if I do a manual scan, using avast!, I'll get the virus message.
You can take a look at the archive (they share this archive for tests)
https://www.evil-shit.de/rar/
Username: Selbsttester
Password: 123456

And now my question: Why does avast! find this test virus just with a manual scan?


Greetings
Matthias

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #1 on: May 27, 2011, 05:08:47 PM »
Well, if I understand it correctly, you are executing the innocent VB file... and not its ADS.

DonMatze

  • Guest
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #2 on: May 27, 2011, 05:11:22 PM »
Jep.

But avast! should scan the whole file. Thats for me the ADS either.
And avast! doens't give me a message at the unpacking. At this time the self-extracting archive writes the Eicar virus.


Greetings
Matthias

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #3 on: May 27, 2011, 05:19:40 PM »
For the first one, I would disagree. From the filesystem's point of view, the streams are rather separated. You execute the file - and it has nothing to do with the ADS. You execute the ADS - and it has nothing to do with the file (or more precisely, with the main stream of the file).

As for the second one... sounds you are right, I'll ask someone to check it.

DonMatze

  • Guest
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #4 on: May 27, 2011, 05:23:11 PM »
Thank you very much.

The link is in my first post, but you can read =).


Greetings
Matthias

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #5 on: May 27, 2011, 05:33:52 PM »
OK, correction - in your case, it doesn't get detected because of the extension (eicar.txt). If you enable scanning of all files "when writing", and remove the default *.txt exclusion from the File System Shield, it gets detected on extraction.

However, I tried with my own file which has an EXE in ADS... and there seems to be a problem on XP.

Nesivos

  • Guest
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #6 on: May 27, 2011, 06:11:12 PM »
OK, correction - in your case, it doesn't get detected because of the extension (eicar.txt). If you enable scanning of all files "when writing", and remove the default *.txt exclusion from the File System Shield, it gets detected on extraction.

However, I tried with my own file which has an EXE in ADS... and there seems to be a problem on XP.

Do you actually have to remove the *.txt extension from scan exclusions or can you just uncheck the scan on "Execute" box for *.txt files?  It seems to me that what you will then have is a universal scan on "Execution" with a list of exclusions.   So by unchecking the "Execute" box for *.txt files the execution of a *.txt file would longer be considered an "Exclusion" and would therefore be scanned by Avast.
« Last Edit: May 27, 2011, 06:12:50 PM by Nesivos »

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #7 on: May 27, 2011, 06:18:21 PM »
You don't have to remove the line, you can just uncheck the "Write" mark (we're talking about extraction here) - but it won't do alone. There's an internal list of extensions that are scanned (if not excluded) - and .txt is certainly not amongst them. So you'd have to add a custom extension on the second or third page of the settings).

DonMatze

  • Guest
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #8 on: May 27, 2011, 06:33:13 PM »
Hello,

the function wasn't enabled, you were right.
But my avast! doesn't react, even if I use the funktion "check all files at writing".
Do you mean, there is a problem at your XP machine?



Greetings
Matthias

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #9 on: May 27, 2011, 06:38:42 PM »
Yes, I don't get any detection on an XP machine - but I do on Win 7 (which uses different drivers than XP).
Did you uncheck the *.txt exclusion from File System Shield settings as well?

Nesivos

  • Guest
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #10 on: May 27, 2011, 06:43:14 PM »
You don't have to remove the line, you can just uncheck the "Write" mark (we're talking about extraction here) - but it won't do alone. There's an internal list of extensions that are scanned (if not excluded) - and .txt is certainly not amongst them. So you'd have to add a custom extension on the second or third page of the settings).


Thanks :) I added *.txt under the custom extensions

DonMatze

  • Guest
Re: avast! doesn't recognize Eicar Virus in an archiv and later
« Reply #11 on: May 28, 2011, 01:44:17 PM »
Ah okay.
Now it works!
Searched on the wrong place.
Good luck with the XP problem!


Greetings
Matthias