Author Topic: avast! engine on online scanner (VirusTotal)  (Read 5510 times)

0 Members and 1 Guest are viewing this topic.

TAP

  • Guest
avast! engine on online scanner (VirusTotal)
« on: January 25, 2006, 10:14:58 AM »
I come across a variant of Win32:Sdbot that the latest version of avast! on my machine detects it but when I submit it to an online scanner (VirusTotal) it's so surprised that avast! engine doesn't detect this sample as you see.

Is avast! on VirusTotal not the same engine as avast! for desktop/server? so this may be the proof that the results from an online scanner are not reliable to determine the efficiency of an antivirus software as some people/amateur testers try to do.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re: avast! engine on online scanner (VirusTotal)
« Reply #1 on: January 25, 2006, 10:23:22 AM »
The engine on VirusTotal is basically the same as the Windows desktop/server engine.
The difference may be in the particular version, however. The online scanners are not updated during the ordinary program updates, but rather receive a special version of the program from time to time (I am talking about avast! right now, don't know how other products work). So, sometimes the engine might be slightly older than the one publically available, sometimes also slightly newer. While the same virus database is used everywhere, newer versions of the scanning engine may have improved unpacking capabilities, which may affect the detection as well.

In this particular care, you can see that the virus was detected inside of an Upack-compressed executable. The engine on VirusTotal is probably slightly older than your desktop one - and it's probably not able to unpack this particular version of Upack (and the virus database currently doesn't contain the signature for the compressed file itself).

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: avast! engine on online scanner (VirusTotal)
« Reply #2 on: January 25, 2006, 10:36:30 AM »
Ok, this is excellent example for my question.
Could generic unpacker help in this very case (if the older version would have one) or it would fail to detect it anyway (since there were some hints about avast! 5.x having gen unpacking)? I'm still learning about this generic unpacking so this question might sound dumb hehe
Visit my webpage Angry Sheep Blog

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: avast! engine on online scanner (VirusTotal)
« Reply #3 on: January 25, 2006, 11:03:44 AM »
In theory yes, but even a generic unpacker is definitely not a panacea.

Some packers cannot be unpacked generically (are way too complex and the emulation would take too long) and some may give strange (unusable) results...

But yes, it's a useful tool (although our internal stats show that right now, we're able to unpack the vast majority of all packed files (up to 90%)).

If at first you don't succeed, then skydiving's not for you.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: avast! engine on online scanner (VirusTotal)
« Reply #4 on: January 25, 2006, 11:42:41 AM »
Hi Vlk,

How do you declare the differences between Jotti and Virus Total,
they are there.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re: avast! engine on online scanner (VirusTotal)
« Reply #5 on: January 25, 2006, 11:53:31 AM »
I'm not sure what exactly are you asking about...
Jotti, just as Virus Total, may have a different version of the engine that the public one (and different version than Virus Total at that). Besides, Jotti is running on Linux, so there may be fewer packers supported in the avast! engine.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: avast! engine on online scanner (VirusTotal)
« Reply #6 on: January 25, 2006, 01:28:15 PM »
Thanks Vlk! ;D
Visit my webpage Angry Sheep Blog