Author Topic: av-comparatives.org late start of Avast at boot-time  (Read 5584 times)

0 Members and 1 Guest are viewing this topic.

hatsandcats

  • Guest
av-comparatives.org late start of Avast at boot-time
« on: December 16, 2010, 02:44:05 PM »
Hi,
I very much favor Avast and recommend it readily.

However, in the new av-comparatives.org performance report (see http://av-comparatives.org/images/stories/test/performance/performance_dec_2010.pdf), only AVG and Sophos started their protection before malware, at boot time.  Here's a quote:

"To support our concerns, we tested on an older system if the products are loading all their protection modules before e.g. malware in the start-up folder is executed. All products failed this test, except AVG and Sophos. AVG and Sophos were the only two products which detected and blocked the mal- ware before its execution after system start-up (by loading itself at an early stage), in all others cases first the malware was successfully executed and only later detected by the AV products, when it was already too late."


Is there a response from the Avast team to this comment? I'm hoping that an update will correct this weakness.

Thanks!
Bob Stromberg, Salem, NY


Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: av-comparatives.org late start of Avast at boot-time
« Reply #1 on: December 16, 2010, 02:47:38 PM »
Good question...
The best things in life are free.

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: av-comparatives.org late start of Avast at boot-time
« Reply #2 on: December 16, 2010, 02:55:04 PM »
Wow interesting question need to be answers and thanks for the update av-comparatives.org Dec. 2010 report.
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline Maxx_original

  • Avast team
  • Super Poster
  • *
  • Posts: 1479
Re: av-comparatives.org late start of Avast at boot-time
« Reply #3 on: December 16, 2010, 03:06:24 PM »
in fact, there's nothing to worry about.. first of all, the malware must get to the PC somehow and that's not done between PC power up and a logon screen... so the initial detection of such sample is a job for real-time shields, which are all already running when a user-mode subsystem is on (and a penetration of new malware is possible).. if we come accross a scenario where an older malware binary becomes detected later, then you always can schedule a boot-time scan (and as you probably know, it is started very early).. testing with AV solution turned off and restarting the machine and similar laboratory approaches don't reflect reality...

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: av-comparatives.org late start of Avast at boot-time
« Reply #4 on: December 16, 2010, 03:25:13 PM »
It is an interesting comment, but seeing a statement like this, without further explanation / description of the test procedure makes me a bit suspicious...

I mean, he's talking about the "start-up folder". What exactly is that? If it's really the Startup folder in the Start menu, then it doesn't make much sense to me at all. I mean, the contents of the Startup folder is executed on LOGON, not on BOOT. That is, the user first has to log on and only then, after the Explorer loads, will the programs in that folder get executed. Now avast (and any other AV) runs as a system service, meaning that its start is independent of users logging in and out... so, in this particular case, one would have to question whether the speed at which the user was logged on was same for each tested product, for example.

Now, I have to say that the avast protection services actually start very early in the boot process. Typically much earlier than the user actually sees the logon screen, actually. So the results from this "test" are a bit disappointing / strange, indeed.... I'll try to talk to Andreas and find out more details.


Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: av-comparatives.org late start of Avast at boot-time
« Reply #5 on: December 16, 2010, 03:28:05 PM »
But... why do AVG and Sophos start earlier in the boot process? Why do they do before avast does?

Edited: Thanks Vlk. Please, post after you got more info.
The best things in life are free.

Offline Chris Thomas

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1936
  • Christian Geek - aka 'born again' Geek
Re: av-comparatives.org late start of Avast at boot-time
« Reply #6 on: December 16, 2010, 03:28:52 PM »
I thought there was something called rootkit scan on system start up and load avast service before other system services

Is this related to the first post?

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: av-comparatives.org late start of Avast at boot-time
« Reply #7 on: December 16, 2010, 05:23:22 PM »
It is an interesting comment, but seeing a statement like this, without further explanation / description of the test procedure makes me a bit suspicious...

Now, I have to say that the avast protection services actually start very early in the boot process. Typically much earlier than the user actually sees the logon screen, actually. So the results from this "test" are a bit disappointing / strange, indeed.... I'll try to talk to Andreas and find out more details.
Thanks
Vlk
Yes Please do...I've read something about AV's protection not starting early enough in the boot up process a while back on the web ...but can't remember now which AV research service did it ???

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89067
  • No support PMs thanks
Re: av-comparatives.org late start of Avast at boot-time
« Reply #8 on: December 16, 2010, 05:48:14 PM »
I thought there was something called rootkit scan on system start up and load avast service before other system services
<snip>

The anti-rootkit scan doesn't happen until 8 minutes after boot. There is little point in doing a rootkit scan that early as it may not be established and generally the functions to run a comparison against whatever the appropriate Windows API says is running against what is actually running may not be available.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

IBK

  • Guest
Re: av-comparatives.org late start of Avast at boot-time
« Reply #9 on: December 16, 2010, 10:51:47 PM »
@Vlk: in the mail with the preview about the performance test we pointed out the issue and offered remote access to a TestPC to see what is meant in case that you can not replicate it by yourself in your lab. Other vendors already confirmed this issue and said that they are going to fix it asap, as the AV should detect/block the malware before it can load and do anything.
P.S.: e.g. on Windows XP, most home users run as Admin / no pwd = no logon screen.
« Last Edit: December 16, 2010, 10:54:52 PM by IBK »

MAG

  • Guest
Re: av-comparatives.org late start of Avast at boot-time
« Reply #10 on: December 16, 2010, 11:21:17 PM »
The default file shield setting seems to be "scan when executing", so couldn't malware stay dormant until boot, then execute early in boot and so remain undetected?

Hexo

  • Guest
Re: av-comparatives.org late start of Avast at boot-time
« Reply #11 on: December 17, 2010, 06:24:53 AM »
Is this on every OS or only on XP?