Author Topic: Avast! 7 strikes av-comparatives again  (Read 13204 times)

0 Members and 1 Guest are viewing this topic.

true indian

  • Guest
Re: Avast! 7 strikes av-comparatives again
« Reply #15 on: May 20, 2012, 09:44:09 AM »
This is going to much off topic... ::) But anyway.. ;D

here are certain things i recognized in avast autosandbox that makes it show the file is malware warning:

-The malware should drop malicious files that get picked up by file shield

-the malware should try connecting to maicious URL's that network shield can pick up

-And of course it should be running in avast sandbox while doing all that  ;)
« Last Edit: May 20, 2012, 09:48:52 AM by true indian »

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! 7 strikes av-comparatives again
« Reply #16 on: May 20, 2012, 09:50:31 AM »
That's all in theory but in real world i've maybe seen it do that like twice, maybe... Other gazillion times, nothing. Got sandboxed and no additional warnings or verdics were given.
Visit my webpage Angry Sheep Blog

true indian

  • Guest
Re: Avast! 7 strikes av-comparatives again
« Reply #17 on: May 20, 2012, 09:52:52 AM »
That's all in theory but in real world i've maybe seen it do that like twice, maybe... Other gazillion times, nothing. Got sandboxed and no additional warnings or verdics were given.

Well...the thing i mentioned is what is supposed to be actually called malware behaviour by autosandbox...and this what a regular user will come across  ::)

Again this topic is for avast 7 av-comp results...isnt all this stuff supposed to be in an another thread hmmm.... ???

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! 7 strikes av-comparatives again
« Reply #18 on: May 20, 2012, 10:14:52 AM »
And what you said pretty much never happens. And yes, it has to do with AV-Comparatives. It's the real world test where things get executed and if they'd actually make things right, we wouldn't be 5th best but first or second best.  Because being 5th is nothing to be cheerful about, even with free version. Because as far as protection modules go, paid version isn't any different, making paid version look bad as well.
Visit my webpage Angry Sheep Blog

true indian

  • Guest
Re: Avast! 7 strikes av-comparatives again
« Reply #19 on: May 20, 2012, 10:26:31 AM »
And what you said pretty much never happens. And yes, it has to do with AV-Comparatives. It's the real world test where things get executed and if they'd actually make things right, we wouldn't be 5th best but first or second best.  Because being 5th is nothing to be cheerful about, even with free version. Because as far as protection modules go, paid version isn't any different, making paid version look bad as well.

and how that makes sense...when it is sandboxed it should be counted as a block isnt it ???

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! 7 strikes av-comparatives again
« Reply #20 on: May 20, 2012, 10:32:22 AM »
When an expert is sitting in front of a computer, yes. But when it gets sandboxed in front of a casual user, he sees that as an annoyance. How do you know they won't just exclude it or disabled Auto Sandbox if it doesn't give any clear indication what the thing that got sandboxed really is? If it says "Sandboxed because it is trying to modify many system files", most will get scared and leave at it. But if it says there wasn't enough data to make a conclusion, 99% of users will consider it safe and run it outside the sandbox. And then all the crap will spawn...
As much as they've thought things to take clueless users into account they haven't thought about this at all. And what AV-C says as a real-world score doesn't really reflect it in actual real world. And that's what i'm concerned about. Being 5th with such way of doing things makes it even worse than it scored...
Visit my webpage Angry Sheep Blog

true indian

  • Guest
Re: Avast! 7 strikes av-comparatives again
« Reply #21 on: May 20, 2012, 10:38:58 AM »
isnt the static analysis finds file suspicious reason enough for a average user??

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Avast! 7 strikes av-comparatives again
« Reply #22 on: May 20, 2012, 10:43:44 AM »
good work avast team keep it up i must say.
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! 7 strikes av-comparatives again
« Reply #23 on: May 20, 2012, 10:46:34 AM »
isnt the static analysis finds file suspicious reason enough for a average user??

When it says that on pretty much anything even mildly suspicious it kind of loses its purpose. Even for me as an advanced user, seing it trigger bunch of times on clean files it even almost made me disable this darn thing altogether and just keep file reputation feature on...
Visit my webpage Angry Sheep Blog

true indian

  • Guest
Re: Avast! 7 strikes av-comparatives again
« Reply #24 on: May 20, 2012, 10:47:40 AM »
isnt the static analysis finds file suspicious reason enough for a average user??

When it says that on pretty much anything even mildly suspicious it kind of loses its purpose. Even for me as an advanced user, seing it trigger bunch of times on clean files it even almost made me disable this darn thing altogether and just keep file reputation feature on...

I guess a normal user...wouldnt touch it even if it comes up with the same reason or will he/she??

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! 7 strikes av-comparatives again
« Reply #25 on: May 20, 2012, 11:33:45 AM »
It's a far lower chance of them running it anyway...
Visit my webpage Angry Sheep Blog

true indian

  • Guest
Re: Avast! 7 strikes av-comparatives again
« Reply #26 on: May 20, 2012, 11:47:25 AM »
Well i have also seen some alerts with reason: filerep is low/heuristic context

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast! 7 strikes av-comparatives again
« Reply #27 on: May 20, 2012, 02:05:55 PM »
Low reputation spawns a window of it's own with "Abort connection" being default. Plus there is a good description in the window that appears for it.
Visit my webpage Angry Sheep Blog

Offline AntiVirusASeT

  • Poster
  • *
  • Posts: 462
Re: Avast! 7 strikes av-comparatives again
« Reply #28 on: May 20, 2012, 03:44:39 PM »
hmm for me i do not find the static analysis triggered often though. i have more incidents of low reputation triggers. thus i trust static analysis quite highly.

though i do wonder why steam games do trigger static analysis. it would be good if an expert from avast shed some light on it  :)

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast! 7 strikes av-comparatives again
« Reply #29 on: May 20, 2012, 04:51:11 PM »
I haven't seen a trigger of the sandbox in many month.  :o
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet