Author Topic: Win32:Sobig-F vs AVAST4  (Read 4850 times)

0 Members and 1 Guest are viewing this topic.

mantra

  • Guest
Win32:Sobig-F vs AVAST4
« on: August 25, 2003, 01:11:12 PM »
today somebody sends to me via email this virus

i use avast4 pro(with a free serial-i was a beta tester)
and outlook 2000(not express)

ok
the resident shield detected it
but the on-demand scan with full setting DOESn't detect!!!

so i re-open outlook 2000 and i used the residend shield to delete it

why the on-demand scanner doens't detect?
is because it was in the outlook database..?

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re:Win32:Sobig-F vs AVAST4
« Reply #1 on: August 25, 2003, 01:15:46 PM »
What were you scanning with the on-demand scanner?

mantra

  • Guest
Re:Win32:Sobig-F vs AVAST4
« Reply #2 on: August 25, 2003, 04:22:47 PM »
scan all file by content
sensibility test whole file & ignore ..
packers all

but i think there is a bug, in a system with a lof of ram, the unpacker engine doesn't work


Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re:Win32:Sobig-F vs AVAST4
« Reply #3 on: August 25, 2003, 04:27:50 PM »
If I remember correctly, Outlook stores its messages in some kind of compressed file; these files are not handled by avast! unpacking engine, so there's no wonder it was not found.

mantra

  • Guest
Re:Win32:Sobig-F vs AVAST4
« Reply #4 on: August 25, 2003, 05:15:03 PM »
thanks igor