PDA

View Full Version : Packed / modified trojans


ChrisP
May 23rd, 2007, 08:05 AM
Will AVG 7.5 detect trojans that have been repacked / compressed or modified in some way?

I know my F-Secure wont. I have TojanHunter which I believe does, but have removed it from my system, so rely on AVG.

Cheers,

Chris

TopperID
May 28th, 2007, 06:44 PM
Are you referring to the realtime Guard or the demand scanner? Have a look at this review from a year ago:-

http://scheinsicherheit.pytalhost.de/decompdelay.htm

The following quote refers to the most recent version of ewido at that time:-

-{ Quote: "(e) Ewido 4.0.0.151 beta /w signatures as of 30 April 2006 (emulation & on-access mem scanner)

---------------------------------------------------------------------------
\Ewido40\ (2) 766 464 (Operating system: Windows XP SP2)
---------------------------------------------------------------------------
*** nothing left (the on-access mem scanner got them all ...) ***

Comments: The emulation of Ewido 4 beta failed to detect the same samples that were missed by Ewido 3.5. However, the memory scanner has been significantly improved (i.e., it appears that it has been integrated into the on-access scanner and, moreover, it seems that the mem scanner does not only scan the executed files once but repeatedly) and, therefore, the overall results are much better. The new heuristics (still under development) do not seem to help if the generic unpacking engine gets outfoxed by anti-emulation code." }-
You'll notice that the demand scanner (which has heuristics) missed some samples, but the on-access Guard found the lot! The reason for this is that the Guard will scan executables twice, once when you attempt to run the file and again as the file unloads into memory. The first scan might miss heavily encrypted samples because the sigs are disguised, but it is the scan in memory that snaps these up.

Trojan Hunter did not do as well in these tests. Its demand and on-access scanners both missed samples.