Scanner Clean-Up Does Not Function Properly [M1498]

Scanner Clean-Up Does Not Function Properly

  1. Scanner does not clean all objects on first clean-up pass; multiple clean-up passes required to remove all objects.
  2. Object removal takes an excessive amount of time (in the case of 342 files a total of 9 minutes).
  3. Threats detected counter in the Scanner does not match Task item log “Items scan” number.

Equivalent samples can be downloaded from Virussign.com: Free Malware Feeds - VirusSign

NOTE: Attached video is in AVI format using Microsoft Video 1 codec. It should be viewable using Windows Media Player, VLC Player or Class Media Player.

The video is 15 minutes long. From 3 to 12 minutes (9 minutes) the scanner is removing the objects.

Can you reproduce the problem & if so how reliably?:

Yes. Reproducible every time - at will.

If you can, exact steps to reproduce. If not, exactly what you did & what happened:

1: Scan large malware pack from Virussign.com.
2: Scan detects malicious items.
3: Apply “Clean-up” action.
4: Re-scan remaining items; items not removed during initial clean-up in Step 3 are re-detected
5: Apply “Clean-up” action.
6: Re-scan remaining items; items not removed during 2nd clean-up in Step 5 are re-detected
7: Apply “Clean-up” action.
8: Re-scan remaining items; all items detected by original scan Step 1 are now removed.
9: Check “Tasks” log; “Items scanned” numbers do not match the actual number of items scanned.

One or two sentences explaining what actually happened:

I scanned large malware pack (355 files) from Virussign.com. The scanner detected 342 items. Upon clean-up, only 303 files were removed. Re-scanned malware pack (52 remaining files). Scanner detected 16 items. Upon clean-up, 37 items remained. Re-scanned malware pack (37 remaining files). Scanner detected 1 item. Upon clean-up, 36 items remained.

Only 13 files should remain (355 files in malware pack - 342 files detected by scanner = 13 files).

Scan clean-up took 9 minutes.

One or two sentences explaining what you expected to happen:

I expected scanner to remove all detected items, the scan time to take perhaps only 1 minute, and for the Task logs to match the actual number of files scanned.

If a software compatibility problem have you tried the advice to make programs work with CIS?:

Not Applicable.

Any software except CIS/OS involved? If so - name, & exact version:

No.

Any other information, eg your guess at the cause, how you tried to fix it etc:
OneDrive download links to the exact malware packs used in the video:
04\10 Virussign - https://onedrive.live.com/redir?resid=2C645D108A1E40C7!4867&authkey=!AFlFTRDY_cFp1ds&ithint=file%2Czip
04\11 VIrussin - https://onedrive.live.com/redir?resid=2C645D108A1E40C7!4868&authkey=!AAf6jrVti09-QsY&ithint=folder%2C
04\12 Virussign - https://onedrive.live.com/redir?resid=2C645D108A1E40C7!4869&authkey=!ALaK_qJUmLrQDuI&ithint=file%2Czip
ARCHIVE PASSWORD: virussign

B. YOUR SETUP
Exact CIS version & configuration:

8.2.0.4591 - Proactive Security

Modules enabled & level. D+/HIPS, Autosandbox/BBlocker, Firewall, & AV:

All.

Have you made any other changes to the default config? (egs here.):

Yes. Configuration file attached.

Have you updated (without uninstall) from CIS 5, 6 or 7?:

No.

 [b]if so, have you tried a clean reinstall - if not please do?[/b]:
 
 Not necessary.

 Clean install Windows OS < 1 week, no "bloat\crapware"; clean install CIS.

Have you imported a config from a previous version of CIS:

No.

 [b]if so, have you tried a standard config - if not please do[/b]:
 
 Issue is independent of configuration; I have tried different configuration\settings - does not correct issue.

 THE ISSUE IS NOT SYSTEM DEPENDENT; I have tried on different machines - Intel, AMD, i3, i5, A8, A10, desktop, laptop.

OS version, SP, 32/64 bit, UAC setting, account type, V.Machine used:

Windows 8.1 x86-64 OEM (Toshiba\AMD), “Always Notify,” Administrator, No VM used.

Other security/s’box software a) currently installed b) installed since OS, including initial trial security software included with system:

a=None b=None

C. ATTACH REQUIRED FILES

  1. Video (zipped, AVI format playable using Windows Media Player, VLC Player or Classic Media Player).

OneDrive download link:

https://skydrive.live.com/redir?resid=2C645D108A1E40C7!4693

  1. Configuration file.
  2. Antivirus Log.
  3. Task Log.

[attachment deleted by admin]

That’s interesting. I’ve observed this behavior with similar security related applications, actually.
[at]hjlbx, if possible, please attach a link which is unlikely to change (regarding archive content; one that you’ve used in your test).

Thanks.

Hello qmarius,

The Virussign link is located at the top of the Bug Report.

In any case, here it is again: Free Downloads - VirusSign | Threat Intelligence & Anti-Malware Database

The samples below were utilized in preparing this bug report…

Samples from 04\08: http://freelist.virussign.com/freelist/VirusSignList_Free_150409.zip

Samples from 04\09: http://freelist.virussign.com/freelist/VirusSignList_Free_150410.zip

Samples from 04\10: http://freelist.virussign.com/freelist/VirusSignList_Free_150411.zip

NOTE:

Virussign samples are of extension type: *.vir - renaming them to *.exe or other file extension does not fix issue; issue is independent of sample group’s file extension types.

Best Regards,

HJLBX

Hello,

Please note that Virussign has discontinued open access to its “free” malware sample packs; an account is now required for access. Consequently, the links supplied in the bug report will not direct the user to a download page, but instead open a Virussign login prompt.

In any case, I do not think the AV scan engine clean-up is Virussign-sample dependent. The overall size of the malware pack seemed to be the defining factor in inducing malfunction. In other words, I think any large malware pack will do in replicating the issue shown in the video and documented in the bug report.

Best Regards,

HJLBX

Hi hjlbx,

Please provide a mirror. In general, QA prefer direct links.

Thanks.

Hello qmarius,

Obtaining password\mirror access as requested. Reply from source may take a week or so.

Best Regards,

HJLBX

Hello qmarius,

Will have direct download links for multiple malware packs within the next few days.

Best Regards,

HJLBX

Hello,

I have verified that this issue has not been fixed in v. 4591.

OneDrive download links to the exact malware packs used in the video:

04\10 Virussign - Microsoft OneDrive - Access files anywhere. Create docs with free Office Online.

04\11 VIrussin - Microsoft OneDrive - Access files anywhere. Create docs with free Office Online.

04\12 Virussign - Microsoft OneDrive - Access files anywhere. Create docs with free Office Online.

Best Regards,

HJLBX

ARCHIVE PASSWORD: virussign

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Please check with Comodo Internet Security V10.0.0.6071 Beta thanks.