Author Topic: Error Avast 4.5.505 and Winrar  (Read 5902 times)

0 Members and 1 Guest are viewing this topic.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Error Avast 4.5.505 and Winrar
« on: November 05, 2004, 02:30:36 AM »
I just discovered a "bug" with Avast 4.5.505 and Winrar (3.40 beta 4 registered)

- I created a plain rar file with 10 files in it. 9 are things that are detected by Avast as malware. 1 is a legitimate file and is not detected by Avast as being infected.
- I right click the rar file and choose scan.
- The first infection is detected.
- I tick "do not show this window again"
- I select delete
- On the next screen I again choose delete

Doing this everything goes well and at the end of the scan the rar only contains the 1 legitimate file.

Now I do exactly the same, except this time I use a rar file with 588 files in it from which one is not infected. When the scan is finished, they entire rarfile is gone. Even the legitimate one.

I did some more testing with different amounts of files in it. It turns out that 80 files in the archive is the turning point.

I hope this will be solved.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Error Avast 4.5.505 and Winrar
« Reply #1 on: November 05, 2004, 02:33:52 AM »
Did some more testing. The same happens when I start Avast and do a manual scan of the folder I placed that rar file in. Settings thorough and archive scan enabled.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:Error Avast 4.5.505 and Winrar
« Reply #2 on: November 05, 2004, 08:57:16 AM »
WinRAR 3.40 beta is outdated. Final release of 3.40 was already released long ago.
Visit my webpage Angry Sheep Blog

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re:Error Avast 4.5.505 and Winrar
« Reply #3 on: November 05, 2004, 09:45:41 AM »
Well, I think the problem doesn't have anything to do with the number of files. My guess is that one of the files is "stored" (i.e. archived without any compression) in the .RAR archive. This way, avast! scanner finds it both during the decompression of the archive, and also during the scanning of the "outer" file (because the stored file is clearly visible there - it would be detected even with archives turned off).
When found inside of the archive, only the corresponding file is deleted; when detected in the "envelope", however, the whole archive is deleted.

I'm just trying to improve the behavior somehow... but I'm afraid the problem is not 100% solvable. Changing the behavior one way will make another problem appear elsewhere. Regarding the actions on archives, there always will be situations when it doesn't work right, I'm afraid.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:Error Avast 4.5.505 and Winrar
« Reply #4 on: November 05, 2004, 01:12:58 PM »
WinRAR 3.40 beta is outdated. Final release of 3.40 was already released long ago.
Actually 3.41 is out now too!
"People who are really serious about software should make their own hardware." - Alan Kay

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Error Avast 4.5.505 and Winrar
« Reply #5 on: November 05, 2004, 01:49:11 PM »
Igor, I got about 700 malware samples here and tried it with different files. It was always that "magic" 80 files where it goes wrong.

I know there are newer version and I just tested them. The same thing happens.

I just can't found out if this is caused by Avast or Winrar. (or perhaps even the combination of the two of them.)

I don't think that it is likely someone would get into troubles because of this. Who will scan/have a archive with 80 or more malwares in it :D

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re:Error Avast 4.5.505 and Winrar
« Reply #6 on: November 05, 2004, 01:54:39 PM »
What happens when you scan the file with the archive scanning turned off? (scanning the whole file, though - e.g. using a thorough scan).

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Error Avast 4.5.505 and Winrar
« Reply #7 on: November 05, 2004, 03:35:16 PM »
Test conditions:
- Plain rar archive.
- 587 malwares (individually detected by Avast and other av's)
- 1 non infected file.
- Scanning the folder the archive is in. (it's the only file there)

Archive scanning off, thorough on:
First infected file in the rar is detected, entire archive is removed without scanning the rest.

Archive scanning off, standard scan on:
Nothing detected.

Archive scanning on, standard scan on:
First infected file in the rar is detected, scan resumes. 534 malwares are detected and correctly removed from the rar. Failed to detect 52 malwares which are detected with a thorough scan and archive scanning on.
« Last Edit: November 05, 2004, 03:44:50 PM by Eddy »

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re:Error Avast 4.5.505 and Winrar
« Reply #8 on: November 05, 2004, 03:39:54 PM »
That confirms my theory. I'll did some improvement to the behavior (it will be included in the next update), but don't expect miracles from it.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Error Avast 4.5.505 and Winrar
« Reply #9 on: November 13, 2004, 04:23:33 PM »
Well a miracle did happen ;D

It is working perfectly with 4.5.518