Advice Request What antivirus is best for offline scanning?

Please provide comments and solutions that are helpful to the author of this topic.

gery79

Level 12
Thread author
Verified
Top Poster
Well-known
Jun 21, 2011
589
just wondering about this as I ran into some malware and a few trojans in a usb. neither gdata nor norton could disinfect it without internet connections . It troubled me somehow.
Do you think there would be a good paid antivirus which is capable of somehow trying to disinfect viruses or other malware?
 

sepik

Level 11
Verified
Well-known
Aug 21, 2018
505
Hello,
Actually i just tested Dr.Web CureIt! I does not need an internet connection to work. Free version collects some telemetry data, but you can block it with a firewall.
On my system, It found some IOBit and Auslogics .exe/.dll file remnants inside \windows\system32 directory. Give it a go. :)

It is portable version, so you can run it straight outta USB stick, for example. Before scanning, remember to click "select objects for scanning" and checkmark everything there.

Kind regards,
-sepik
 
Last edited:

sepik

Level 11
Verified
Well-known
Aug 21, 2018
505
I thought, original poster means that an av that does need an internet connection...to download sigs.
GData BEAST needs an internet connection. Actually couple of days ago, when was bored...tested fresh bazaar samples against Malwarebytes. It Blocked all of them.
However, it epic failed miserably against notorious Netwalker .ps1. OK, next test was notorious Netwalker agains G-Data, now without G-Data realtime protection OFF...so it was a battle between GData BEAST/DeepRay. Netwalker failed miserably. BEAST nailed it in a hard way. No harm done to the system. GData BEAST is sadly cloud based...probaly GData will epic fail if an internet connection is not available.
Damn G-Data is fast, just make it to run on on-access and let BEAST/DeepRay do the rest...
 

sepik

Level 11
Verified
Well-known
Aug 21, 2018
505
GData is memory hunrgy, its really faster than it was before year ago. It does have an unique ability to include Drives or folder to check when writing/reading...so when im downloadin something which goes to my D:\ data drive, it check when writing/reading....however on my C: drive it check when run...makes the system really fast.
 

SeriousHoax

Level 49
Verified
Top Poster
Well-known
Mar 16, 2019
3,862
Bitdefender, ESET, Emsisoft for sure, not Kaspersky.
Now let me explain why Kaspersky should not be on this list.
What I have seen, Kaspersky often doesn't push all types of signatures via updates to the device. They keep a lot of it in the cloud only. They also constantly cleanup local signatures in favor of cloud-based detection to save disk space and improve performance I assume. I'm talking about Kaspersky AV, not their removal tools.
A few days ago I sent a sample to Kaspersky through @harlan4096 because malware analysts always reply back to him. It was a malware that was in a Firefox cache file which contained an HTML page and that page contained a Hoax/Scam script. Kaspersky wasn't detecting it while I did a right-click scan but Virustotal shows detection and if I try to upload the file in a browser then Kaspersky was detecting it. Harlan told me that some files get detected by WebAV components instead of FileAV and that's why it wasn't getting detected probably. He still submitted to Kaspersky and got a similar reply. Later after knowing from Harlan that Kaspersky now replies to everyone if you're logged into their opentip submission portal, I submitted the file again to get even a more detailed answer and this is the reply I got.
1.PNG
So anything that Kaspersky thinks is not necessary to be detected by FileAV will be detected by WebAV only and static scans don't use WebAV components. It is fair and the reasoning is understandable from Kaspersky's point of view.
But since we're talking about offline detection through the static scan, Kaspersky's high reliance on the cloud and the separation from FileAV to WebAV makes it not the best one for this category. Bitdefender and ESET rarely rely on cloud for signature based detection, and don't have such FileAV vs WebAV separation for signatures.
BTW, Emsisoft has their Emsisoft Emergency Kit by which you can get the benefit of full Bitdefender's local signature + Emisoft's.
 

sepik

Level 11
Verified
Well-known
Aug 21, 2018
505
EEK needs an internet connection to download sigs. Dr.Web CureIt does not, latest sigs is included in the software. If somehow the system gets fkd up, which means malware does some nasty modifications to your internet settings (no internet available) then you can go to local nerd and download Dr.Web CureIt to USB stick. Btw, does anyone knows other portable AV that include sigs?
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,141
EEK needs an internet connection to download sigs. Dr.Web CureIt does not, latest sigs is included in the software. If somehow the system gets fkd up, which means malware does some nasty modifications to your internet settings (no internet available) then you can go to local nerd and download Dr.Web CureIt to USB stick. Btw, does anyone knows other portable AV that include sigs?
One list here

 

silversurfer

Super Moderator
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,112
EEK needs an internet connection to download sigs. Dr.Web CureIt does not, latest sigs is included in the software. If somehow the system gets fkd up, which means malware does some nasty modifications to your internet settings (no internet available) then you can go to local nerd and download Dr.Web CureIt to USB stick.
Well, of course, that's true for all scanners even for Dr.Web CureIt, everyone have to download scanners of choice, so doesn't matter which scanners to choose
as all scannners can be downloaded only in this case via internet connection from workable different network...
 

sepik

Level 11
Verified
Well-known
Aug 21, 2018
505
When you download Dr Web CureIt portable, you dont need to install it, the package does have latest Dr Web sig inside. Downside is that you need to download it everyday to get new sigs. Its portable, runs without any internet connection needed and it detection and especially malware removal capability is good.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
@Freud2004
Yep, but Dr Web works straight outta usb stick. EEK needs an internet connection. Dr Web CureIt you can save on the usb stick, load it there. No need to install or download sigs.
but we also have to download it from another PC
with EEK, we download it -> update -> copy the whole folder to the USB -> latest signatures, completely portable
basically, EEK requires an extra step to update compare to CureIt but in reward, the scanning speed of EEK is much faster than Dr.Web
That's a big plus, IMO
DrWeb, Kaspersky, ESET, BD take forever to scan, especially on very low-end laptops

The downside is EEK may not disinfect a file. It deletes/quarantines
 

silversurfer

Super Moderator
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,112
When you download Dr Web CureIt portable, you dont need to install it, the package does have latest Dr Web sig inside. Downside is that you need to download it everyday to get new sigs. Its portable, runs without any internet connection needed and it detection and especially malware removal capability is good.
You still misunderstood my point: everyone needs to download first even your portable Dr Web CureIt, that means it's necessary to have a workable internet connection, so it doesn't matter what scanner anyone prefers to download as first all scanners must be downloaded or even must be updated like EEK...
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top