AVG does not detect virus downloaded in sandbox

If it's not about a problem in the program
Post Reply
slbox
Posts: 17
Joined: Thu Dec 27, 2012 2:42 pm

AVG does not detect virus downloaded in sandbox

Post by slbox » Sat Dec 29, 2012 11:43 pm

When I use an unsandboxed Firefox to download the EICAR test file (http://www.eicar.org/85-0-Download.html), my AVG Anti-Virus Free Edition 2013 (running on Windows 7 64-bit) pops up a box saying it has detected a virus.

But then when I use a sandboxed Firefox to download the EICAR test file, I don't get any alert from AVG. I can see the eicar.com file in my C:\Sandbox\username\DefaultBox\user\current\Downloads directory. Then when I right click on the eicar.com file inside that sandbox directory and select "Scan with AVG", AVG detects the virus.

Any idea why the AVG Resident Shield doesn't detect the virus immediately after it is downloaded inside the sandbox?

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Sun Dec 30, 2012 11:15 am

Interesting, and scary, because my Malwarebytes Pro doesn't even detect those files as a possible virus after I move them out of the sandbox.
What the heck?

I updated to the latest Malwarebytes Pro AV engine yesterday, and also the definition files, then rebooted as required.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

Blues
Posts: 214
Joined: Sun May 10, 2009 7:37 pm
Location: Blue Ridge Mtns

Post by Blues » Sun Dec 30, 2012 11:23 am

Paul, this is known behavior by MBAM.

As I recall, they justify the failure to identify the EICAR tests as viruses because they consider their app to be an adjunct to a standard AV and concentrate on the threats that standard AV's either miss or do not provide comprehensive protection against.

As to the issue of AV's detecting within the Sandbox, I have had issues with Hitman Pro not being able to properly run or detect within my downloads folder (which is forced).
If I move the file out of the downloads folder, it works as expected.

I do not have that same issue with either MBAM or EAM.
Blues

Real-Time: Sandboxie (Lifetime), Online Armor Premium, Webroot SecureAnywhere AV

On Demand: Shadow Defender, MBAM Pro, HitmanPro, Drive Snapshot / Macrium Reflect

opera
Posts: 212
Joined: Sat May 26, 2007 11:15 am
Location: uk

Post by opera » Mon Dec 31, 2012 2:13 am


Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Mon Dec 31, 2012 5:26 pm

Thanks for the link, opera.
I think their attitude towards checking the EICAR files is misguided.
Just how hard can it be to add those few files to their virus definitions?
It's not as if the contents of those files ever changes.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

opera
Posts: 212
Joined: Sat May 26, 2007 11:15 am
Location: uk

Post by opera » Tue Jan 01, 2013 12:56 am

Lots of people agree with you Guest10

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest