Sample Testing with 360 Total Security Essentials 07.07.2015

Status
Not open for further replies.

LahiruRajinda

Level 4
Thread author
Verified
Well-known
Forum Veteran
Jul 6, 2015
158
562
269
35
Silicon Valley
First of all, I'm not affiliated with Qihoo or any other AV developer.
This test was done on my personal computer without using a VM.

Test Info:
AV Version: TSE v6.6.1.1013
fE4VeYm.png

Protection Mode: Performance
ONDemand Scan from Right-Click Context Menu
Virus Samples: hxxp://mega.co.nz/#!M1g1jJIR!6FYbSSFUFF99Qythxq7V3U-dqTaO-g0GA_WzfmTwD6w
Thanks to Member SkyboundSteven

Test Results:

Without Internet Connection

  • Both ON: 60/76 Phase2: 1/17
  • BD: 51/76 Phase2: 0/26
  • AVIRA: 56/76 Phase2: 1/21
  • Both OFF: 1/76 Phase2: 0/76

With Internet Connection

  • Both ON: 70/76 Phase2: 1/7
  • BD: 70/76 Phase2: 1/7
  • AVIRA: 70/76 Phase2: 1/7
  • Both OFF: 70/76 Phase2: 1/7

Logs: http://www22.zippyshare.com/v/Egg1BILv/file.html

Conclusion:
It appears that 360 TSE is using Cloud Scan Engine by default over both BD & Avira engines when it's connected to the cloud. Results have also suggested that QVMII engine is able to detect 1/76 files and it's causing disturbance while removing the threats, which explains the Phase2 result.
 
No testing by running the malware sample with 360 off, then trying to remove it with different engines on?
 
No testing by running the malware sample with 360 off, then trying to remove it with different engines on?
I've tried disabling 360TSE instead of putting it on Performance mode, but that didn't change anything. It would appear that, currently, there is no way to disable the QVMII engine for an ON Demand scan.
 
Status
Not open for further replies.