Author Topic: Evo-Gen, FileMetaGen, FileRep, FileString.  (Read 9986 times)

0 Members and 1 Guest are viewing this topic.

naren17

  • Guest
Evo-Gen, FileMetaGen, FileRep, FileString.
« on: February 27, 2014, 09:08:26 PM »

Currently I am testing Avast Free latest very often. And I test on real system i.e no VM, XP SP3 32 Eng.

Can anyone explain what these detections are or how these scans work?

Today I tested Avast 2 times.
Both the times, after rightclick scan (PUP enabled) & execution of the malware (PUP enabled), some malware were not detected. After 5 mins I executed the malware that were not detected & now few were detected as FileMetaGen. After 5 mins again I executed the remaining few malware & all were detected as FileString, only one was not detected.

Now I dont know if these detections were due to streaming updates
OR
Evo-Gen, FileMetaGen, FileRep, FileString detections are like live scans i.e suspicious/unknown samples are uploaded & scanned by autoscan/autoanalyzers & found malicious detections are sent to the users so these detections were there.

Can anyone explain/give info?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #1 on: February 27, 2014, 09:12:46 PM »
do you have virustotal scan of the samples?......if so, post link to scan results


Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #2 on: February 27, 2014, 09:19:13 PM »
These detections are not possible in Virustotal.

FileRep means that the file has a bad reputation.

Evo-Gen is a technique to detect unknown samples with one big signature for millions of files, cloud based.

FileString and Metagen are variations of FileRep.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #3 on: February 27, 2014, 09:20:51 PM »
It's dangerous to do testing on your productive system... what would you do it it got infected with a sample a cryptolocker and it wasn't detected by the anti-virus?
Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #4 on: February 27, 2014, 09:22:59 PM »
Quote
These detections are not possible in Virustotal.
others may detect and VT will give lots of file info detected or not     ;)




naren17

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #5 on: February 27, 2014, 09:48:26 PM »
It's dangerous to do testing on your productive system... what would you do it it got infected with a sample a cryptolocker and it wasn't detected by the anti-virus?

Its my test system so no worry.

naren17

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #6 on: February 27, 2014, 10:06:24 PM »
do you have virustotal scan of the samples?......if so, post link to scan results
Sorry dont have the samples now as after test I reverted to clean state of the system with Comodo Time Machine & deleted the snapshot of the test.
But I will do a test soon & if the same scenario happens, will post the VT links here.

By the way, dont know how the samples were detected after 5 mins as asked in my first post, but one thing I forgot to mention that when I first ran the samples those undetected were running in the memory. After 5 mins when I ran the undetected samples again as I have mentioned in my first post few were detected, & those few detected the second time 2 were already running in the memory from the first run but they were not detected & they should be detected, right?

Dont know if you will understand what I mean so let me explain with example.

First run - Undetected samples - A & B active in the memory.

Second run - After 5 mins I ran A & B from the folder again & they were detected. But A & B already active in the memory from the first run were not detected/terminated/quarantined, etc... Whereas they should also be quarantined/blocked, etc... by Avast, right?

true indian

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #7 on: March 01, 2014, 04:42:21 AM »
Do you restart and wait for a while after installing avast,maybe cloud servers take time to stabalize connection to the protection backend?

naren17

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #8 on: March 01, 2014, 12:08:15 PM »
Do you restart and wait for a while after installing avast,maybe cloud servers take time to stabalize connection to the protection backend?
I always check connection is established

true indian

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #9 on: March 02, 2014, 04:31:16 AM »
I always check connection is established

Could test avast again and keep me posted with the results on deepscreen and others here.Really interested on how it does.This time before you go out executing the files wait for a while to see if the connection goes off in between.  :)

I know what you mean.These backend detectors are getting tough to understand now.  :o
« Last Edit: March 02, 2014, 04:41:15 AM by True Indian »

naren17

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #10 on: March 02, 2014, 11:42:08 AM »
I always check connection is established

Could test avast again and keep me posted with the results on deepscreen and others here.Really interested on how it does.This time before you go out executing the files wait for a while to see if the connection goes off in between.  :)

I know what you mean.These backend detectors are getting tough to understand now.  :o

OK, when I will do a test, will keep the connection GUI interface open.

naren17

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #11 on: March 02, 2014, 01:37:22 PM »
Tested 120 latest malware pack on malwaretips.
Avast latest, PUP enabled
XP SP3 32 Real System i.e no VM

Todays test was shocking. I dont if Avast new technology is stable?

Scan detected 96/120
24 executed, few detected, couple didn't run, few missed. I didn't got a single Deepscreen scan popup, strange? Finally a ransomware 21.exe infected & restarted the system & blocked system boot.

I tested 21.exe with both Hardened mode, Moderate & Aggressive & no alert, strange? & same as above, ransomware infected the system.

For all test I had kept update GUI interface opened & connection was established.
For every test I reverted the system to clean state & did the test.

I dont understand, why no Deepscreen & Hardened alert was there?

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #12 on: March 02, 2014, 01:54:45 PM »
Take a look at this: http://forum.avast.com/index.php?topic=147058.0

Tested in a VM with Win 8.1 and no updates.

No Deepscreen alerts, few Evo-Gen detections and one heuristic detection.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

true indian

  • Guest
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #13 on: March 02, 2014, 04:04:39 PM »
Now this is getting wierd really...sometimes backend detects sometimes missed.

Naren,could you re-test the samples again to see if any changes are there now?

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: Evo-Gen, FileMetaGen, FileRep, FileString.
« Reply #14 on: March 02, 2014, 08:57:37 PM »
If possible could you upload the files and test them at virustotal.com?
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.