Author Topic: HUGE bug (file system shield settings)  (Read 3681 times)

0 Members and 1 Guest are viewing this topic.

Theblob

  • Guest
HUGE bug (file system shield settings)
« on: April 10, 2013, 07:14:16 PM »
ok this one's so big I can't belive no one brought this up before:

basically its IMPOSSIBLE to get the real-time file scanner to test files on execution only (the only time when a virus/trojan gets dangerous)
btw scan on run-only are option that Eset & Kaspersky also have (but they work on these products)

I have several trojan exes (not mere leaktests) which I use to test the AVs. but I also edit some of them to change signatures to test the proactive aspects (heuristic & behavior blocking). problem is with Avast I can't to that unless I disable File Shield, else I throws up an alarm every time I access the infected files even if I dont double-click

this is very important since I've a slow drive (not them fancy SSDs) so if a file gets tested everytime it's written or even viewed then the whole system slows down
this a pity considering that the AV itself is low on resources (I chose to test this one when Avira went over to the Dark Side)



so this what I did:

ticked all 3 boxes in "scan when executing"
unticked everything in "scan when opening"
unticked everything in "scan when writing"

and IT DONT WORK. alarm goes off whenever I even right-click on an infected file (alert says something about explorer.exe)

AND if I also untick "scan programs when executing" (first box in  "scan when executing" settings) I can at least right-click on a trojan file & open it with a hexeditor. but if I try to copy the file or any sort of writing, again an alert (again with explorer.exe)

in other words Avast confuses "executing" with "reading"    ???


I even tried a workaround by adding a test folder to the file shield's exclusion list (ticked R & W, left X unticked) but again same error, even a right-click on a bad file triggers the alert
which means the RWX settings are also buggy

worse, I can get Avast to scan files when accessing (read/write) but NOT execute (in other words useless, and also the complete opposite of what I want)


so, question for the developers here: do you even test your products thorougly? I mean if you let such obvious bugs like that spoil a potentially good program then its a recipe for disaster. security progs like AVs & FWs are supposed to be released in working form, not pre-alpha or beta (unless specifically mentioned otherwise, but here v8.0.1483 is -supposed- to be final version)




but hey if you dont belive me you can test it yourself:

theres a reputable site called matousec where they test the outbound (leak) protection of firewalls, there's a leaktest called jumper.exe
there's several versions of the file, command line & GUI version which work in different ways, I'm talking about the GUI version (which is blacklisted by Avast, go figure why)
it's a leaktest that creates a dll and also tries to terminate explorer.exe. or something

http://www.matousec.com/downloads/windows-personal-firewall-analysis/leaktests/Jumper.zip

so there we go, try to do the following:

put that exe in a custom folder (you gonna need to disable avast file shield first because of the bug) then see if you can tick the right options so that avast reacts ONLY when you double-click on the file (ie. try to run it)
you must be able to open the file's folder, left-click on the file, right-click, open with notepad, with a hexedit...and make copy of it (to same folder or elsewhere) without Avast reacting (no alerting no scanning no nothing)
see for yourself if it works :|
« Last Edit: April 10, 2013, 07:45:33 PM by Theblob »

Offline zenzor

  • Jr. Member
  • **
  • Posts: 80
Re: HUGE bug (file system shield settings)
« Reply #1 on: April 10, 2013, 07:36:27 PM »
I too hope that this gets fixed soon.  Just upgraded to v8 and I don't want it to scan whenever I copy or move files, it slows down everything way too much-

Theblob

  • Guest
Re: HUGE bug (file system shield settings)
« Reply #2 on: April 10, 2013, 07:39:38 PM »
EXACTLY

but I cant believe they even let a big bug like that get through. 8.0.1483 is still obviously beta version :/

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: HUGE bug (file system shield settings)
« Reply #3 on: April 10, 2013, 08:24:14 PM »
If you feel it "is" a bug start a topic here https://feedback.avast.com/
Click "login">click "single sign-in"

Please be a lot more concise on the feedback board as they don't need essays.
Get to the point and do it quickly...please.  :)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Theblob

  • Guest
Re: HUGE bug (file system shield settings)
« Reply #4 on: April 10, 2013, 08:50:34 PM »
ok I just did that,
I just wrote a line - but considering the layout of the feedback page I doubt the developers will even read it (no more than they read the forum)

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: HUGE bug (file system shield settings)
« Reply #5 on: April 10, 2013, 09:18:27 PM »
ok I just did that,
I just wrote a line - but considering the layout of the feedback page I doubt the developers will even read it (no more than they read the forum)
Trust me the devs keep a very close eye on the feedback board.  8)
And they keep a close eye on the forums as well.  8)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Theblob

  • Guest
Re: HUGE bug (file system shield settings)
« Reply #6 on: April 10, 2013, 09:26:14 PM »
Trust me the devs keep a very close eye on the feedback board.  8)
And they keep a close eye on the forums as well.  8)
the feedback has a voting system which obviously means visibility is proportionate to voting count (heck I can't even see my own msg) so simple logic says that chances of feedback being of any use in short term is very low. by the time they notice the bug (let alone fix it) the company might be outa business ^^
(it only took me about 10s but that's still 10s time waste. ho well)


as for the forum I dunno if they bother either, there aint no "bug report" subsection in this section of the forum else I would've posted there

Offline zenzor

  • Jr. Member
  • **
  • Posts: 80
Re: HUGE bug (file system shield settings)
« Reply #7 on: April 12, 2013, 02:10:19 PM »
And they keep a close eye on the forums as well.  8)

A close or a closed eye? :P