Перейти к содержимому


Фото
- - - - -

Dr.Web CureIt uses different engine?


  • Please log in to reply
8 ответов в этой теме

#1 malware1

malware1

    Member

  • Members
  • 208 Сообщений:

Отправлено 02 Март 2014 - 17:04

Hi,

 

When I have a big amount of files to be submitted, then I usually download latest version of Dr.Web CureIt and scan samples using it. I noticed that many samples undetected by CureIt are detected by Dr.Web engine at VirusTotal. Why does that happen? I receive many information about processed tickets, they sometimes said that the files are already detected and a record exists in the database. No, I don't mean tickets processed after few days (then that's normal that some file are possibly detected, the researchers could already get them from another source, not from my submission, so it was added), I mean the tickets that are processed by ticket auto resolver almost instantly, usually after few minutes. I check the suspicious files using VirusTotal, and yes, they're detected. But why CureIt doesn't detect them? Does it use another version of the engine?


Сообщение было изменено malware1: 02 Март 2014 - 17:11


#2 Dmitry_rus

Dmitry_rus

    Guru

  • Helpers
  • 3 640 Сообщений:

Отправлено 02 Март 2014 - 17:26

Does it use another version of the engine?

No, it doesn't. Try to scan again with new updated bases - CureIt updates regularly, several times a day.



#3 malware1

malware1

    Member

  • Members
  • 208 Сообщений:

Отправлено 02 Март 2014 - 17:52

I tried, the files still aren't detected.



#4 SergM

SergM

    Guru

  • Moderators
  • 9 387 Сообщений:

Отправлено 02 Март 2014 - 17:57

CureIt is not updated as often as the main antivirus



#5 IlyaS

IlyaS

    Massive Poster

  • Posters
  • 2 911 Сообщений:

Отправлено 02 Март 2014 - 18:38

Btw, malware1 do you use sigcheck to test samples on virustotal?
Spoiler


#6 pig

pig

    Бредогенератор

  • Helpers
  • 10 855 Сообщений:

Отправлено 02 Март 2014 - 18:41

I check the suspicious files using VirusTotal, and yes, they're detected.

Can you report a link to VirusTotal scan result?
Also, please check suspicious files here: http://vms.drweb.com/online/?lng=en
and report link to scan result.
Почтовый сервер Eserv тоже работает с Dr.Web

#7 malware1

malware1

    Member

  • Members
  • 208 Сообщений:

Отправлено 02 Март 2014 - 20:19

Btw, malware1 do you use sigcheck to test samples on virustotal?

Spoiler

 

No, I don't.

 

 

 

I check the suspicious files using VirusTotal, and yes, they're detected.

Can you report a link to VirusTotal scan result?
Also, please check suspicious files here: http://vms.drweb.com/online/?lng=en
and report link to scan result.

 

Sorry, I didn't keep the VT links. But here's another file, undetected by CureIt, but detected according to VT: https://www.virustotal.com/en/file/66a5fe9c82ea872a555927f0f1c7d6fa2469311bab84d9f4aa5442c31f552508/analysis/ I sent it using FTP, the ticket wasn't processed yet, but probably will be checked soon.

It's detected by http://vms.drweb.com/online/?lng=en



#8 pig

pig

    Бредогенератор

  • Helpers
  • 10 855 Сообщений:

Отправлено 02 Март 2014 - 21:10

Please show CureIt scan log for this file. Delete existing log file before.
Почтовый сервер Eserv тоже работает с Dr.Web

#9 malware1

malware1

    Member

  • Members
  • 208 Сообщений:

Отправлено 02 Март 2014 - 21:38

Here you go: http://wklej.to/yfnCk/text




Читают тему: 0

0 пользователей, 0 гостей, 0 скрытых