Hi friends, Here is the thing i have never got any pop up from autosandbox other than a single case where it flagged KM player as suspicious ans as i don’t use KM player much so i uninstalled it. I generally install lots of software ( mostly from cnet and all free) but never even once get an warning. So today i downloaded a patch from torrent. This patch is flagged as malware by 25 scanner in VT. But not by avast. But what surprised me most is when i tried to install in virual mode of ruternil system safe, still there is no warning from autosandbox stating its suspicious. After installation and use of about 1 hr i did not get any warning from avast BB shield. What went wrong? Can anybody explain something as Avast autosandbox and BB shield is supposed to warn against unknown threat.
Its a patch for internet download manager. Ok if you say i can send it to avast lab. I am not complaining avast does not pick it up, its normal. My question is why avast’s Autosandbox and BB shield had not pick it up as potential threat.
Edit: well gmail is refusing to send the file. Can i somehow move the file manually to chest so that i can send it to lab.
Good to know why it is not picked up by the heuristics and behavior blocker…
If we can’t have a more aggressive detection we will be infected by zero-day malware more frequently.
Ok here is more these three patch also does not trigger avast Autosandbox and BB shield. Directly scanned with PUP on does not detect. The third one is a bit tough only 2 scanner of VT detect ( MBAM also don’t detect it) but still it should trigger Autosandbox or BB IMO. Moreover OA HIPS did warn me by multiple pop up.
Hi everyone can i post the link to this thread in the thread started by pk " Sandbox/ safezone- feature requests" so that the avast team look to the problem (or issues) of autosandbox or would that be considered as violation of some forum rule?
Mine certainly seems to. I get this screen about every 30 seconds or so with the message, “C:\Program Files\Google\Google Desktop Search\pdftotext.exe”. It is always the same and I do not know why. But it’s driving me crazy with it’s constant repetition.
No dear, its possible to manually add a genuine file to chest if you think its suspicious.
Go to chest–>Right click on the right hand side area of GUI select add–> Browse for the file you want to add in the chest click ok and its done.
Now right click on that file in the chest and select submit for analysis/virus lab(not sure)