Avast 4.2 - Error in detection in .VHD file

jimbo45

New member
Guru
Gold Member
VIP
Local time
4:18 AM
Messages
5,941
Location
Hafnarfjörður IS
Hi all

I've been testing AVAST 4.2 fairly rigorously on both VISTA X-64 and W7 7100 X-64.

Straight from the MS site I downloaded the .VHD Virtual disks (XP compatability mode)

AVAST reports that the .VHD file contains a "COMPRESSION BOMB". Now this doesn't actually tell me what this is -- but the fact that it reports something with the word BOMB in it means it can't be good. :mad:

Now as this VHD file was downloaded from the official Microsoft site I assume it HAS to be OK (or does it - I would imagine MS regularly checks its own websites - there's plenty of people out there who'd jump at a chance of attacking a MS site if they could).

I'm going to download the XP compatability mode again and have another scan.

VISTA again reports the file as CLEAN) so I think there still might be a couple of things AVAST need to fix in W7 when reading compressed or "archive" type files.

I can't post the screenshot -- once I see something with the word "BOMB" in it I immediately WIPE the entire machine. Schnell Fast, Pronto.

Cheers
jimbo
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
The Avast forum reports this: A decompression bomb is a file that unpacks to an enormous amount of data - thus "flooding" the unpacking engine. It's quite hard to detect such files reliably, so it's possible that it gives some false alarms ocassionally.

The entire forum is here,
Hope this helps..
 

My Computer My Computer

OS
windows 7
Hi there
Thanks
It's a pity they have to use the word "Bomb" in this -- they should perhaps just say "unable to scan" or whatever. By using the word BOMB I'm sure most people would assume the file is NOT good.

Cheers
jimbo.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
No problem, glad to help. And I agree about the word 'bomb', but it sure catches your attention.
 

My Computer My Computer

OS
windows 7
Hi all

I've been testing AVAST 4.2 fairly rigorously on both VISTA X-64 and W7 7100 X-64.

Straight from the MS site I downloaded the .VHD Virtual disks (XP compatability mode)

AVAST reports that the .VHD file contains a "COMPRESSION BOMB". Now this doesn't actually tell me what this is -- but the fact that it reports something with the word BOMB in it means it can't be good. :mad:

Now as this VHD file was downloaded from the official Microsoft site I assume it HAS to be OK (or does it - I would imagine MS regularly checks its own websites - there's plenty of people out there who'd jump at a chance of attacking a MS site if they could).

I'm going to download the XP compatability mode again and have another scan.

VISTA again reports the file as CLEAN) so I think there still might be a couple of things AVAST need to fix in W7 when reading compressed or "archive" type files.

I can't post the screenshot -- once I see something with the word "BOMB" in it I immediately WIPE the entire machine. Schnell Fast, Pronto.

Cheers
jimbo

When I first saw that term I was pretty freakin' scared too. But then I learned it just means a compressed file that if it were to be uncompressed to be scanned would take up all the memory in the machine. So, unless you were to suspect that file was particularly vulnerable to being infected, then you don't have to worry about it.
 

My Computer My Computer

Computer Manufacturer/Model Number
Dell Inspiron 1520 (Laptop)/ Home (Desktop)
OS
Windows 7 x64 / Same
CPU
Intel Core 2 Duo T7250 / Intel Core i7 930
Motherboard
Intel 945 / Asus P6X58D-E
Memory
4GB / 6GB
Graphics Card(s)
NVIDIA GeForce 8400M GS / ASUS 1GB
Sound Card
Whatever Dell gave me :-( / Onboard
Monitor(s) Displays
15.4" LCD / Crappy CRT
Hard Drives
Seagate 500GB SATA; 7200 RPM / Seagate 1TB SATA; 7200 RPM
PSU
N/A / OCZ Fatal1ty 550W Modular
Case
N/A / Antec 900
Cooling
Air
Mouse
Microsoft Presenter (Bluetooth)
Back
Top