avast!4.x bug ? still can download eicar.com with the browser refresh

i’m using avast home (4.7.892) free edition. After I installed, i tested it with download file “fake virus tester” from eicar.org, eicar.com (http://www.eicar.org/download/eicar.com), and as expected, it worked, avast can detected it (pop up “avast! Warning”) and telling me that eicar.com is virus and given me an option to abort the connection. I clicked “Abort Connection”, i stopped On-Access Protection and tried again… firefox save window appeared, indicated that the On-Access Protection is stopped 100%. Well… I didn’t download file eicar.com yet because i aborted and close that save window.
After that, i started On-Access Protection again, and refresh a link address (http://www.eicar.org/download/eicar.com)… strangely, pop up “avast! Warning” doesn’t pop up and i can still download that file!!!, it means, avast! doesn’t detect eicar.com as a virus anymore.

Is that a bug ? I tested it with IE and still found a same problem.

Thank’s

In my opinion, the browser downloaded the file into its cache at the moment you stopped avast! On-Access Protection (doesn’t matter that you closed the download dialog; most browsers today use some speculative download while the save dialog is still opened). So, the subsequent access to that link doesn’t really go to network (i.e. Web Shield can’t do anything about it), but simply loads the file from browser cache.

Why? ::slight_smile:

i stopped it for testing purpose, after my friends told me that he found this strange problem after (accidently) he turn off On-Access Protection and after turn it on again, he still can open virus file’s he downloaded from internet with refresh firefox browser

so you mean avast cannot detect that file with Standard Shield ? Because after i download it, i can execute that file and i still didn’t received any virus notify from avast that this file is virus.

btw i’m sorry about my posted before, ast posted i told that i found this problem with IE too, actually i found this problem only when i use firefox browser, i’m sorry :frowning:

Which eicar version? I mean, eicar.txt or eicar.com or eicar.zip…
You cannot execute (run) the virus and get infected if the Standard Shield is on.
You can, IF your sensitivity level allows to save files to disk without scanning, download it, but not execute it.
WebShield does exactly this: scans the http traffic before it is saved to disk.

Sure, Standard Shield should detect it, but you didn’t supply much info about the Standard Shield settings in the original post, it was mostly related to the browser part.
So, how exactly are you starting the file? What sensitivity have you set for Standard Shield?

sorry long time to reply…
i looked it again and the setting sensitivity for standard shield is normal (default from avast installer) sir…