Author Topic: Why AvAST think Shareaza Sends mails? Is It the P2P Shield?  (Read 4759 times)

0 Members and 1 Guest are viewing this topic.

Drazick

  • Guest
Why AvAST think Shareaza Sends mails? Is It the P2P Shield?
« on: November 18, 2004, 04:32:21 PM »
Since I upgraded to the latest version (4.5.523) AVAST keeps showing the scaning (as if it scans for mail) every 5 min.
The icon won't response to a rightqleft click.
The yellow tip baloon shows IP addresses.
I guess it connects to the net for something... Update maybe?
What is it?
How can I stop it?

Pic attached. Look at the red circle.
« Last Edit: November 18, 2004, 10:32:56 PM by Drazick »

Drazick

  • Guest
Re:Doing something over and over
« Reply #1 on: November 18, 2004, 06:59:04 PM »
Here's the file...
No mail client, messeging nothing...
Only IE.
« Last Edit: November 18, 2004, 07:00:13 PM by Drazick »

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Doing something over and over
« Reply #2 on: November 18, 2004, 07:07:06 PM »
It must be a local process sending or receiving email, really. Let's see which one it is, maybe it will be an interesting discovery.

First, turn on verbose logging for the Mail Scanner. To do this, add the following line to the [MailScanner] section of <avast>\data\avast4.ini file:

Log=20


Then restart the Internet Mail provider.

Next, wait for the icon to reappear (i.e. wait for the connection to be made). Finally, go to <avast>\data\log, open the file aswMaiSv.log, and find a line with something like

--POP command REDIRECT

followed by some numbers. The last number on the line is the PID (Process ID) of the process that's making the connection. Use the Processes tab of the Task Manager to find out which process corresponds to this PID (enable the PID column first by using the View -> Select Columns command).


Hope this helps,
Vlk
If at first you don't succeed, then skydiving's not for you.

Drazick

  • Guest
Re:Doing something over and over
« Reply #3 on: November 18, 2004, 08:07:49 PM »
Done it.
Found out it's mt P2P software - Shareaza.
How come? Shareaza doesn't use pop/smtp service in order to work...
« Last Edit: November 18, 2004, 10:32:07 PM by Drazick »

RJARRRPCGP

  • Guest
Re:Why AvAST think Shareaza Sends mails? Is It the P2P Shield?
« Reply #4 on: November 19, 2004, 01:45:18 AM »
Looks like Avast has a bug that when programs are using port 25, it  thinks that it's sending E-mails, even when it's not sending E-mails. That's the same type of problem ZoneAlarm has.
« Last Edit: November 19, 2004, 01:46:15 AM by RJARRRPCGP »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Why AvAST think Shareaza Sends mails? Is It the P2P Shield?
« Reply #5 on: November 19, 2004, 01:52:05 AM »
port 25 is assigned for use with SMTP.

I would say applications that are trying to use this port for other things are the "bugged" ones since they do not comply to international standards.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Why AvAST think Shareaza Sends mails? Is It the P2P Shield?
« Reply #6 on: November 19, 2004, 09:14:13 AM »
Well... I've read the FAQ and I must really say I'm surprised. Random port numbers, why not, but haven't these guys ever heard about system (<1024) versus regular ports?

In linux, and most other Unix'es as far as I know, only root can listen to ports < 1024.

Allowing ShareaZa to listen on those ports is IMO a very bad design... :(


Anyway, let's see what we can do.

Cheers
Vlk
If at first you don't succeed, then skydiving's not for you.

peterfu

  • Guest
Re:Why AvAST think Shareaza Sends mails? Is It the P2P Shield?
« Reply #7 on: November 19, 2004, 02:51:37 PM »
Allowing ShareaZa to listen on those ports is IMO a very bad design.

an in my opinion a very clear RFC violation  >:(

hmm, as many ISP's block port 25 for their users (except to access ISP mail server) ot might not be a good idea to use it

br
Peter