Archive file - Decompression bomb

Hi

I have just removed an infection off my computer with the help of people in this forum. However, I just started scanning my external hard drives to make sure the infection has not spread to my drives. The first scan I ran with Avast Free edition flagged a file, could someone have a look and give me their opinion on whether this is some kind of threat?

G:\software\Nero 7.8.5.0 setup file.exe|>Cab\E4060BF5.cab|>rootFEAA0A71.img|>root.img

Error: The file is a decompression bomb. (42110)

I have looked through some of the associated topics and I understand what a decompression bomb is but if someone else uses Nero I thought they might know if this genuine or something else.

Hope someone can help me :-[

Rish

The file in itself is the installation file for Nero 7.8.5.0 setup file.exe (try a google search for it) and is highly compressed, to reduce download size. When you install it it is unpacked into a much larger size, the same has to happen when you want to scan the file.

Not only is the installation file compressed, in the path given you will see that there are other files that are also compressed within that, the .cab file and some of its contents also. So this is as indicated a highly compressed file.

The name really is the most dangerous thing about this and I wish they would change it or simply not report it, a real PITA.

These highly compressed files are generally ‘archive’ files which are inert, don’t present an immediate risk until they are unpacked.

Hi David,

If I want to install this software what would you suggest, how do I determine if it is just an installation file for Nero or something else that is hiding inside, before unpacking it??

Thanks :slight_smile:

Rish

Don’t you already have Nero installed, it is a CD/DVD burning software ?

If not - There is nothing to stop you installing as and when it starts its install avast would be scanning the contents as they are unpacked and run.

The only thing you might need to do is exclude the G:\software\Nero 7.8.5.0 setup file.exe file as the file system shield would scan this file and may come up with the same alert. Just copy and paste the full path into the file system shield > expert settings > exclusions. That should allow you to start the install and avast would then scan the other files that it unpacks and installs.

Nero is installed but If I wipe my computer in the future I will have to install it again, but I wanted to make sure that I would not be installing something malicious. Thanks for your help, appreciate it. :smiley:

Rish