Author Topic: Do autosandbox and BB shield really work?  (Read 7594 times)

0 Members and 1 Guest are viewing this topic.

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Do autosandbox and BB shield really work?
« on: June 03, 2011, 05:19:23 PM »
Hi friends, Here is the thing i have never got any pop up from autosandbox other than a single case where it flagged KM player as suspicious ans as i don't use KM player much so i uninstalled it. I generally install lots of software ( mostly from cnet and all free) but never even once get an warning. So today i downloaded a patch from torrent. This patch is flagged as malware by 25 scanner in VT. But not by avast. But what surprised me most is when i tried to install in virual mode of ruternil system safe, still there is no warning from autosandbox stating its suspicious. After installation and use of about 1 hr i did not get any warning from avast BB shield. What went wrong? Can anybody explain something as Avast autosandbox and BB shield is supposed to warn against unknown threat.

http://www.virustotal.com/file-scan/report.html?id=d2e894996c1567e95123a22d76bfcdae94861365b537aa901717732e218b9d0a-1307112917
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

yongsua

  • Guest
Re: Do autosandbox and BB shield really work?
« Reply #1 on: June 03, 2011, 05:25:51 PM »
Was it probably a potentially unwanted program?Correct me if I am wrong.Anyway,please submit the sample with a zip file to virus@avast.com

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Re: Do autosandbox and BB shield really work?
« Reply #2 on: June 03, 2011, 05:29:59 PM »
Its a patch for internet download manager. Ok if you say i can send it to avast lab. I am not complaining avast does not pick it up, its normal. My question is why avast's Autosandbox and BB shield had not pick it up as potential threat.

Edit: well gmail is refusing to send the file. Can i somehow move the file manually to chest so that i can send it to lab.
« Last Edit: June 03, 2011, 05:35:12 PM by gautam7 »
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Do autosandbox and BB shield really work?
« Reply #3 on: June 03, 2011, 05:44:47 PM »
Good to know why it is not picked up by the heuristics and behavior blocker...
If we can't have a more aggressive detection we will be infected by zero-day malware more frequently.
The best things in life are free.

yongsua

  • Guest
Re: Do autosandbox and BB shield really work?
« Reply #4 on: June 03, 2011, 05:53:03 PM »
Good to know why it is not picked up by the heuristics and behavior blocker...
If we can't have a more aggressive detection we will be infected by zero-day malware more frequently.

And that's why Avast! did not participate the recent retrospective test from AV-C?

yongsua

  • Guest
Re: Do autosandbox and BB shield really work?
« Reply #5 on: June 03, 2011, 06:01:10 PM »
Can i somehow move the file manually to chest so that i can send it to lab.

Hi,gautam.It is impossible to manually move the file that is not flag by Avast! as a malware to the chest.Correct me if I am wrong.

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Re: Do autosandbox and BB shield really work?
« Reply #6 on: June 04, 2011, 04:41:12 AM »
Quote
If we can't have a more aggressive detection we will be infected by zero-day malware more frequently.

My point exactly and its even not like zero day malware since half the scanner of VT detects it. Also MBAM and Hitman pro detects it.
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Re: Do autosandbox and BB shield really work?
« Reply #7 on: June 04, 2011, 12:39:26 PM »
Ok here is more these three patch also does not trigger avast Autosandbox and BB shield. Directly scanned with PUP on does not detect. The third one is a bit tough only 2 scanner of VT detect ( MBAM also don't detect it) but still it should trigger Autosandbox or BB IMO. Moreover OA HIPS did warn me by multiple pop up.

http://www.virustotal.com/file-scan/report.html?id=1f8787aa05ceb44d33f93e60cf9a0ac44cee4945f9c837fe7df4c24193ff35f9-1307181478
http://www.virustotal.com/file-scan/report.html?id=7ea538e078f00bed40d8ba689977f6dd2d0395e0ebbf332c85d47fb8f2df3430-1307182615
http://www.virustotal.com/file-scan/report.html?id=f7341796570effc81c125f7cad4269ecb9f34066601d8ce4b58595398ffd2a40-1307182145

This is unbelievable. Can some senior member forward this info to avast team so that they can have a look at what is going wrong.

PS: after that i downloaded the autosandbox tool and when i run i, i did get auutosandbox warning from avast and it had the red border. 
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Re: Do autosandbox and BB shield really work?
« Reply #8 on: June 05, 2011, 06:02:14 PM »
Hi everyone can i post the link to this thread in the thread started by pk " Sandbox/ safezone- feature requests" so that the avast team look to the problem (or issues) of autosandbox or would that be considered as violation of some forum rule?

Thanks
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

oldduke

  • Guest
Re: Do autosandbox and BB shield really work?
« Reply #10 on: June 06, 2011, 07:29:03 PM »
Mine certainly seems to.  I get this screen about every 30 seconds or so with the message, "C:\Program Files\Google\Google Desktop Search\pdftotext.exe".  It is always the same and I do not know why.  But it's driving me crazy with it's constant repetition.

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Re: Do autosandbox and BB shield really work?
« Reply #11 on: June 06, 2011, 07:43:09 PM »
Mine certainly seems to.  I get this screen about every 30 seconds or so with the message, "C:\Program Files\Google\Google Desktop Search\pdftotext.exe".  It is always the same and I do not know why.  But it's driving me crazy with it's constant repetition.

Hi oldduke welcome to the forum you can add the process as trusted in the expert seting under file system scan.

Click real time shield> file system shield > expert setting> autosandbox > add > then add the process.

Or when next time you got the pop up try run normally and click remember my dissision
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).

Offline Ashish Singh

  • Poster
  • *
  • Posts: 437
  • Proud to be an Indian
    • Quick Heal
Re: Do autosandbox and BB shield really work?
« Reply #12 on: June 07, 2011, 04:53:15 AM »
Can i somehow move the file manually to chest so that i can send it to lab.

Hi,gautam.It is impossible to manually move the file that is not flag by Avast! as a malware to the chest.Correct me if I am wrong.

No dear, its possible to manually add a genuine file to chest if you think its suspicious.
Go to chest-->Right click on the right hand side area of GUI select add--> Browse for the file you want to add in the chest click ok and its done.
Now right click on that file in the chest and select submit for analysis/virus lab(not sure)

Regards
Ashish Singh
Windows 7 Ultimate(32 bit), avast! free (always latest released or beta), Intel Core2Duo, 2GB RAM, Outpost Firewall Pro 7.5,IE 9,TuneUp Utilities 2011,Diskeeper 2011

http://www.incredibleindia.org 

Caution! Online world is full of man made Aliens

yongsua

  • Guest
Re: Do autosandbox and BB shield really work?
« Reply #13 on: June 07, 2011, 05:07:33 AM »
Can i somehow move the file manually to chest so that i can send it to lab.

Hi,gautam.It is impossible to manually move the file that is not flag by Avast! as a malware to the chest.Correct me if I am wrong.

No dear, its possible to manually add a genuine file to chest if you think its suspicious.
Go to chest-->Right click on the right hand side area of GUI select add--> Browse for the file you want to add in the chest click ok and its done.
Now right click on that file in the chest and select submit for analysis/virus lab(not sure)

Regards
Ashish Singh


How idio am I. :-[

Offline gautam7

  • Full Member
  • ***
  • Posts: 193
Re: Do autosandbox and BB shield really work?
« Reply #14 on: June 07, 2011, 06:20:22 PM »
Thanks Ashish and don't feel bad yongsua after all we learn every day.  :) I am interested if avast team respond to this topic.
Lenovo B40 laptop/ core i3 4010U CPU (1.7 GHz)/ 4.0 GB RAM/500 GB HDD,OS: windows 10 64 bit, Browser: Google Crome/ FF (adblock plus, lastpass,) Security: Avast pro 10, MBAM (free).