Advice Request Avast Heuristics Detection

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.
N

NullByte

Thread author
Hello,

I've seen in Avast and in most guides that people change the heuristics sensitivity from Low to Normal or even High. My question is: did anyone see a heuristic detection ? I've tested Avast so many times but I never seen a "Heur" detection. Does changing the heuristics sensitivity improve detection ?

I did a test a few days ago (184 GB samples) and most files where detected by "EVO-Gen, DRep and Malware-Gen" and I've set heuristics sensitivity to High (even with Normal I didn't see any improvements) and I didn't see any "Heur" detection.
 

Logethica

Level 13
Verified
Top Poster
Well-known
Jun 24, 2016
636
My Heuristic sensitivity in Avast is set to high...
I have yet to see a heuristic detection either.
What type of samples are you testing with?....I think that a "heuristic detection" would be a slim possibility anyway because (correct me if i am wrong)...the heuristics would be a weighted evaluation system that would best detect a zero day modification of a pre-recognised malware..
If the malware samples that you were testing were more than a day old then they would maybe be detected by their signatures before the heuristics had a chance to scan it.
maybe either find some samples that are very fresh,or perhaps "modify" an existing one.
 

Atlas147

Level 30
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 28, 2014
1,990
This is what Heuristics looks like on Avast, they call it EvoGen
upload_2016-7-25_23-23-16.png
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
I have heuristics enabled and its always a good thing to see what kind of tweaks you can do to a security software to get even more protection. I use Avast as my AV and Anti-EXE
 
  • Like
Reactions: Logethica
O

Omnipotent

Thread author
Win32:Malware-gen is the generic description from Avira, Microsoft, Avast and ESET of unknown Trojans which are detected by its antivirus heuristic engine.

Win32:Evo-gen [Susp] is a broad classification used by the Avast Behavior Monitor feature for software that exhibits suspicious behavior categorized as potentially malicious. The Behavior Monitoring feature observes the behavior of processes as they run programs.
 
  • Like
Reactions: Logethica

Atlas147

Level 30
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 28, 2014
1,990
Win32:Malware-gen is the generic description from Avira, Microsoft, Avast and ESET of unknown Trojans which are detected by its antivirus heuristic engine.

Win32:Evo-gen [Susp] is a broad classification used by the Avast Behavior Monitor feature for software that exhibits suspicious behavior categorized as potentially malicious. The Behavior Monitoring feature observes the behavior of processes as they run programs.

I think malware-gen might be just a generic term but it's still in the signatures, because in virustotal there are a ton of samples called malware-gen for avast and I don't think there are heuristics in virustotal scanners
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top