SOMETIMES AVAST resident shield DOESN’T check the ole files like docs…
here is the report
*
avast! Report
This file is generated automatically
Task ‘Mantra’ used
Started on Monday, September 15, 2003 10:13:22 AM
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\EXPLORER.EXE [+] is OK
C:\WINDOWS\SYSTEM\ParseDls.exe [+] is OK
C:\WINDOWS\NOTEPAD.EXE [+] is OK
my setting is SCAN OLE DOCUMENTS
I use w98se
and avast resident shield give me this problem often but not every time!!!
so sometime AVAST miss to scan for example doc file
i use only a resident task(i edit only one) and i run only 1
but sometime it missed to scan doc files…!!!
What is your exact setting of the Standard Shield (appart from the fact that the “Scan OLE documents on open” is on - i.e. how about Scanning files on open, Created/modified files, …)?
What version of avast! do you use - build 260?
Can you give us a full path of a missed file (an example)?
OK, thanks.
Can you give me an example of the OLE document (I mean the filename) that was missed?
Btw, why are you mentioning the reboot? Do you mean that sometimes, when you reboot, avast! works OK (no matter how many times you try, no document is missed, everything works OK, as long as Windows are running) and on another reboot, the documents are missed (or even all of them?) - until you reboot again?
Istituzioni di Diritto Privato.doc
DirComun.doc
example
“Btw, why are you mentioning the reboot? Do you mean that sometimes, when you reboot, avast! works OK (no matter how many times you try, no document is missed, everything works OK, as long as Windows are running) and on another reboot, the documents are missed (or even all of them?) - until you reboot again?”
yes right!
for example while i’m typing i try to open a doc file and avast missed it
if now i reboot and try to open a doc file avast will check it!!!
strange i know …
after a reboot i tried to open docs…but avast checked winword but not doc!
avast! Report
This file is generated automatically
Task ‘Mantra’ used
Started on Monday, September 15, 2003 2:06:22 PM
C:\WINDOWS\RUNDLL32.EXE [+] is OK
C:\WINDOWS\SYSTEM\rnaapp.exe [+] is OK
C:\WINDOWS\SYSTEM\tapisrv.exe [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\Istituzioni di Diritto Privato.doc [+] is OK
C:\WINDOWS\SYSTEM\ParseDls.exe [+] is OK
C:\Programmi\Alwil Software\Avast4\ASHAVAST.EXE [+] is OK
C:\Programmi\File comuni\AVP Shared Files\avpupd.exe [+] is OK
C:\Programmi\Opera\Opera.exe [+] is OK
C:\Programmi\File comuni\AVP Shared Files\avpupd.exe [+] is OK
C:\Programmi\miranda\miranda32.exe [+] is OK
C:\Programmi\Alwil Software\Avast4\ENGLISH\ENHANCED.HTM [+] is OK
C:\Programmi\Alwil Software\Avast4\DATA\Skin\blue panel.asws [+] is OK
C:\Programmi\Alwil Software\Avast4\DATA\Skin\low res.asws [+] is OK
C:\Programmi\Alwil Software\Avast4\DATA\Skin\shadow fist.asws [+] is OK
C:\Programmi\Alwil Software\Avast4\DATA\Skin\teak zeppelin.asws [+] is OK
C:\Programmi\Outlook Express\MSIMN.EXE [+] is OK
C:\WINDOWS\SYSTEM\PSTORES.EXE [+] is OK
C:\Programmi\Internet Explorer\IEXPLORE.EXE [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\jus.unitn[1].htm [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\jus.unitn[1].htm [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\25A5KP2F\global_var[1].js [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\25A5KP2F\global_var[1].js [+] is OK
C:\WINDOWS\TEMP\aswB022.TMP [+] is OK
C:\WINDOWS\TEMP\Script_0004f90f.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\216PS50J\function_top[1].js [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\216PS50J\function_top[1].js [+] is OK
C:\WINDOWS\TEMP\aswB033.TMP [+] is OK
C:\WINDOWS\TEMP\Script_0004fd72.html [+] is OK
C:\WINDOWS\TEMP\Script_0004fd82.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\MXULMVA5\header[1].js [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\MXULMVA5\header[1].js [+] is OK
C:\WINDOWS\TEMP\aswB044.TMP [+] is OK
C:\WINDOWS\TEMP\Script_000501a8.html [+] is OK
C:\WINDOWS\TEMP\Script_000501b2.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\25A5KP2F\subheader[1].js [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\25A5KP2F\subheader[1].js [+] is OK
C:\WINDOWS\TEMP\aswB054.TMP [+] is OK
C:\WINDOWS\TEMP\Script_0005055b.html [+] is OK
C:\WINDOWS\TEMP\Script_0005056c.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\216PS50J\supfooter[1].js [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\216PS50J\supfooter[1].js [+] is OK
C:\WINDOWS\TEMP\aswB065.TMP [+] is OK
C:\WINDOWS\TEMP\Script_00050a50.html [+] is OK
C:\WINDOWS\TEMP\Script_00050a5d.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\7PDHZZOD\footer[1].js [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\7PDHZZOD\footer[1].js [+] is OK
C:\WINDOWS\TEMP\aswB072.TMP [+] is OK
C:\WINDOWS\TEMP\Script_00050c15.html [+] is OK
C:\WINDOWS\TEMP\Script_00050c27.html [+] is OK
C:\WINDOWS\TEMP\aswB076.TMP [+] is OK
C:\WINDOWS\TEMP\Script_00050e58.html [+] is OK
C:\WINDOWS\TEMP\Script_00050e64.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\H4UAIM7C\Main[1].html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\4LA7CXQB\Main[1].html [+] is OK
C:\WINDOWS\TEMP\aswB0D0.TMP [+] is OK
C:\WINDOWS\TEMP\Script_00052281.html [+] is OK
C:\WINDOWS\TEMP\aswB103.TMP [+] is OK
C:\WINDOWS\TEMP\Script_00052fe2.html [+] is OK
C:\WINDOWS\TEMP\Script_00052fee.html [+] is OK
C:\WINDOWS\TEMP\aswB105.TMP [+] is OK
C:\WINDOWS\TEMP\Script_000530e5.html [+] is OK
C:\WINDOWS\TEMP\Script_000530f0.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\Picturep[1].html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\Picturep[1].html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\index9[36].html [+] is OK
C:\WINDOWS\TEMP\aswB304.TMP [+] is OK
C:\WINDOWS\TEMP\Script_0005adab.html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\Picturep[1].html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\index9[37].html [+] is OK
C:\WINDOWS\TEMP\aswC0B3.TMP [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\Picturep[1].html [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\UK0UOTD2\index9[28].html [+] is OK
C:\WINDOWS\TEMP\aswD063.TMP [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\CLQZO56N\Picturep[1].html [+] is OK
C:\Programmi\Opera\Cache4\opr007IY.htm [+] is OK
C:\WINDOWS\Local Settings\File temporanei Internet\Content.IE5\4LA7CXQB\index9[26].html [+] is OK
C:\WINDOWS\TEMP\aswE2D2.TMP [+] is OK
C:\Programmi\Babylon\babylon.exe [+] is OK
C:\PROGRAMMI\BABYLON\utils\shlhook.exe [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\Istituzioni di Diritto Privato.doc [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\Istituzioni di Diritto Privato.doc [+] is OK
C:\WINDOWS\EXPLORER.EXE [+] is OK
C:\WINDOWS\NOTEPAD.EXE [+] is OK
Task stopped: Monday, September 15, 2003 2:18:46 PM
Run-time was 12 minute(s), 24 second(s)
avast! Report
This file is generated automatically
Task ‘Mantra’ used
Started on Monday, September 15, 2003 7:39:59 PM
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\dirtto pub.doc [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\dirtto pub.doc [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\dirtto pub.doc [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\dirtto pub.doc [+] is OK
Task stopped: Monday, September 15, 2003 7:40:44 PM
Run-time was 45 second(s)
avast! Report
This file is generated automatically
Task ‘Mantra’ used
Started on Monday, September 15, 2003 7:40:45 PM
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\dirtto pub.doc [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\Application Data\Microsoft\Modelli\Normal.dot [+] is OK
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\STARTUP\dgnwnlc.dot [+] is OK
C:\WINDOWS\Desktop\Istituzioni di Diritto Privato.doc [+] is OK
C:\WINDOWS\rundll32.exe [+] is OK
*
avast! Report
This file is generated automatically
Task ‘Mantra’ used
Started on Monday, September 15, 2003 7:42:43 PM
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\SYSTEM\ParseDls.exe [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\WINDOWS\EXPLORER.EXE [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
C:\Programmi\Microsoft Office\Office\WINWORD.EXE [+] is OK
OK, I can see you tried to open a number of DOC files in the last part of the report.
Do I understand it correctly that there was a reboot between 7:40:45 PM (where all the .DOC files were tested) and 7:42:43 PM (where no files were tested)?
To narrow down the problem, I’d like to know 2 things (if you can reproduce the problem and boot the Windows such that the .DOC files are not scanned, again).
When the .DOC files are not scanned - at the same moment:
Does the “Scan files on open” works? You have the HT* mask enabled, so - what happens when you open a HTML file? Does it appear in the log? Or only the browser (opera, IE, …)?
If you check the resident protection settings, is the “Scan OLE documents on open” really checked? (I mean, maybe the task configuration was not read correctly…)
But as I said… it must be in the situation when the .DOC files are not scanned - if possible.
Thanks.
" OK, I can see you tried to open a number of DOC files in the last part of the report.
Do I understand it correctly that there was a reboot between 7:40:45 PM (where all the .DOC files were tested) and 7:42:43 PM (where no files were tested)?"
YES right!
“1. Does the “Scan files on open” works? You have the HT* mask enabled, so - what happens when you open a HTML file? Does it appear in the log? Or only the browser (opera, IE, …)?”
when avast miss doc , miss html files too!!!
i tried some minutes ago and it missed doc and html!!
(if u want i can send the log)
resident shield checked only explorer.exe many times but not htlm pages
“2. If you check the resident protection settings, is the “Scan OLE documents on open” really checked? (I mean, maybe the task configuration was not read correctly…)”
i made one new with the right setting the problem persist!
have u same behave to your pc?igor
i have a clean install on w98se (new install)
i installed some time ago!
so my w98se has not problems
Well, the problem is that I don’t have the same behavior… if I had, it would be (probably) rather easy to fix.
So, it looks like the Scanning files on open isn’t working correctly sometimes…
Could you please download StartupList, run it as StartupList.exe /complete /full /forceall and send me the resulting log (maybe not to the forum, but better by a private message)?
Well, there isn’t much knowledge to share…
It seems to be a problem with the Standard Shield initialization; we have already incorporated changes that could help… and we’ll see more after the following update (that should be out really soon).