About: Avira Antivir PersonalEdition Classic to use with Download Statusbar (a Firefox 3.0 add-on)
The problem is about scanning one file downloaded, and what to use as ARGUMENT-line in Firefox Download Statusbar add-on.
It is obvious that Firefox does something with the command line passed, so that AVP cannot see the correct syntax. The problem seems to be around a double qoute ( " ) that becomes an "escaped quote" ( \" ), but I do not have more than that info...
First I notice that AVCMD.EXE is not supported anymore, so another AVP scanner needs to be used.
I tried to find a working configuration for AVSCAN.EXE (already in the AVP map), and have here the result that does the job on my Windows XP Prof SP3 wit Firefox 3.0.
Although, HTM files (with it's map) is not scanned when saved in Firefox, but i don't know how necessary that is.
I have included all players, the AVP configuration file, the argument used, the command used, the command line passed by Firefox (as seen by Sysinternals Process Explorer) and also the scan result by AVP.
Configuration file used: C:\Program Files\AntiVir PersonalEdition Classic\AVP_DSB.CFG
(change ExitMode=1 into ExitMode=2 to make the window close after a scan with no positive results)
(Parameter=0x00300432 turns the process scan and scan registry off)
! ! Set this file READ ONLY after placing it, or it will be gone after the first scan ! (Right-click the file, choose "Properties", an tick "Read only")
### C:\Program Files\AntiVir PersonalEdition Classic\AVP_DSB.CFG
[CFG]
GuiMode=1
ExitMode=1
[SEARCH]
Parameter=0x00300432
[SCANNER]
ScanRootkits=0
[CONTROLCENTER]
ProfileType=4
ProfileName=Download Statusbar in Firefox
ProfileDescription=This profile is used for scanning files downloaded trough Download Statusbar in Firefox (FF3.0 has been the test).
### End of C:\Program Files\AntiVir PersonalEdition Classic\AVP_DSB.CFG
Download Statusbar virus-scanner command line:
C:\Program Files\AntiVir PersonalEdition Classic\avscan.exe
Download Statusbar argument line (note the spaces and double quotes ! ):
/CFG="C:\Program Files\AntiVir PersonalEdition Classic\AVP_DSB.CFG /PATH="%1
----------
Just for info, this is what, according to Process Explorer, is used as command line by Firefox / Download Statusbar:
"C:\Program Files\AntiVir PersonalEdition Classic\avscan.exe" /CFG=\"C:\Program Files\AntiVir PersonalEdition Classic\AVP_DSB.CFG
"/PATH=\"C:\Documents and Settings\Username\Mijn documenten\test\TEST_EICAR\eicar_com.zip"
----------
Avira report on detecting the TEST-VIRUS eicar_com.zip downloaded from
www.eicar.org/anti_virus_test_file.htm(A fake test virus in a .COM-file within an archive)
Avira AntiVir Personal
Report file date: zondag 22 juni 2008 12:27
Scanning for 1350570 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: Username
Computer name: ERIK-XP
Version information:
BUILD.DAT : 8.1.0.308 16478 Bytes 28-5-2008 17:03:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 17-4-2008 09:26:31
AVSCAN.DLL : 8.1.1.0 53505 Bytes 17-4-2008 09:26:31
LUKE.DLL : 8.1.2.9 151809 Bytes 17-4-2008 09:26:32
LUKERES.DLL : 8.1.2.1 12033 Bytes 17-4-2008 09:26:32
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18-7-2007 18:58:07
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 7-3-2008 19:24:40
ANTIVIR2.VDF : 7.0.4.195 2546176 Bytes 14-6-2008 19:26:43
ANTIVIR3.VDF : 7.0.4.233 260608 Bytes 21-6-2008 19:20:22
Engineversion : 8.1.0.59
AEVDF.DLL : 8.1.0.5 102772 Bytes 17-4-2008 09:26:32
AESCRIPT.DLL : 8.1.0.44 278907 Bytes 20-6-2008 19:22:36
AESCN.DLL : 8.1.0.22 119157 Bytes 20-6-2008 19:22:36
AERDL.DLL : 8.1.0.20 418165 Bytes 25-4-2008 20:24:01
AEPACK.DLL : 8.1.1.6 364918 Bytes 20-6-2008 19:22:35
AEOFFICE.DLL : 8.1.0.20 192891 Bytes 20-6-2008 19:22:34
AEHEUR.DLL : 8.1.0.32 1274231 Bytes 20-6-2008 19:22:34
AEHELP.DLL : 8.1.0.15 115063 Bytes 30-5-2008 09:39:10
AEGEN.DLL : 8.1.0.29 307573 Bytes 20-6-2008 19:22:32
AEEMU.DLL : 8.1.0.6 430451 Bytes 8-5-2008 13:01:55
AECORE.DLL : 8.1.0.31 168310 Bytes 7-6-2008 10:16:50
AVWINLL.DLL : 1.0.0.7 14593 Bytes 17-4-2008 09:26:31
AVPREF.DLL : 8.0.0.1 25857 Bytes 17-4-2008 09:26:31
AVREP.DLL : 7.0.0.1 155688 Bytes 16-4-2007 12:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 17-4-2008 09:26:31
AVARKT.DLL : 1.0.0.23 307457 Bytes 17-4-2008 09:26:31
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 17-4-2008 09:26:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 17-4-2008 09:26:32
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 17-4-2008 09:26:32
NETNT.DLL : 8.0.0.1 7937 Bytes 17-4-2008 09:26:32
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 17-4-2008 09:26:29
RCTEXT.DLL : 8.0.32.0 86273 Bytes 17-4-2008 09:26:29
Configuration settings for the scan:
Jobname..........................: Download Statusbar in Firefox
Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\AVP_DSB.CFG
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: off
Scan memory......................: on
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: off
Scan all files...................: Use file extension list
File extensions..................: -HT*,
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: zondag 22 juni 2008 12:27
Starting the file scan:
Begin scan in 'C:\Documents and Settings\Username\Mijn documenten\test\TEST_EICAR\eicar_com.zip'
C:\Documents and Settings\Username\Mijn documenten\test\TEST_EICAR\eicar_com.zip
[0] Archive type: ZIP
--> eicar.com
[DETECTION] Contains code of the Eicar-Test-Signature virus
[WARNING] The file was ignored!
End of the scan: zondag 22 juni 2008 12:27
Used time: 00:05 min
The scan has been done completely.
0 Scanning directories
2 Files were scanned
1 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
1 Files not concerned
1 Archives were scanned
1 Warnings
0 Notes