App Review An Interlude with WinAntiRansom

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,151
The curious thing is that to stop ransomware there really isn't any setting other than default. Install WAR, plop in the reg code and it will work with or without a reboot. As I'm very, very familiar with Tesla and have a fairly good idea of WAR's mechanism of action I engaged in a bit more research. Try as I might I couldn't reproduce what B found in his video without initially manipulating C++ runtime (things only seem to be running).
 

1qay1qay

Level 1
Verified
Apr 17, 2016
36
Anyone have any insights on WAR protection ? Is this another HIPS ? I purchase WAR but i am not sure if it will work with Comodo FW, since i dont know how WAR is supposed to work.
 

Tempnexus

Level 3
Verified
Nov 25, 2015
136
Anyone have any insights on WAR protection ? Is this another HIPS ? I purchase WAR but i am not sure if it will work with Comodo FW, since i dont know how WAR is supposed to work.
Well it's not as chatty as HIPS, but it is a tad chatty in my opinion. I was hoping (when I bought it) that it would be a clear cut YES or NO for ransmware...basically if it goes off I was hoping it was because it honesty thinks it's ransomware. But I found it going off for many other reasons that were nowhere near ransomware.
Hence my original question above regarding the number in the parenthesis. Since so far I might as well just run HIPS or MAMUTU.
-----------------------------------------------------
Reason for saying HIPS or MAMUTU is because if WAR is going to be as chatty as those two then there is no point in actual protection value. Eventually I will slip up and allow ransomware.
 
Last edited by a moderator:

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
@1qay1qay: Its more as Behavior based where it will determine immediately the possible malicious/ransomware attacks.

-----------------

Seems weird and mysterious about Britec's video unless possible misaligned on the configuration? We don't know.
 
R

Ray Redbad

Britec09's test of the Bitdefender product showed it failed miserably also. The results of that and the WAR testing should be disqualified.

Anyone have any insights on WAR protection ? Is this another HIPS ? I purchase WAR but i am not sure if it will work with Comodo FW, since i dont know how WAR is supposed to work.
AI engine. WinPatrol recently adopted the oh-so-pretty-pretty page design so popular these days. Here's a better one...
WinAntiRansom

Note: VirusTotal's policy has changed so the feature is no longer available as of the next release scheduled for Monday, June 13. See the latest postings in the WAR thread at Wilders Security for more detail.

Cheers.
 
Last edited by a moderator:
R

Ray Redbad

WinAntiRansom 2016.8.533 August 19th, 2016 - Stable Release

downloads

Added over 30 new behaviors to AI Engine, including improved detection of Trojans and Rats.
Improved program discovery. (Will run post-update)
Yellow tray icon denotes program discovery in progress.
Fixed bug where program discovery dialog would not always open.
Improved service start-up on Windows XP
“Daily” files no longer necessary
Fixed bug that could result in false positives that refuse to be “allowed”
Enhance Program Discovery to find additional programs.
Reduced CPU usage when updates are being applied.
Enhanced engine to detect/block additional attack vectors.
 

Tempnexus

Level 3
Verified
Nov 25, 2015
136
WinAntiRansom 2016.8.533 August 19th, 2016 - Stable Release

downloads

Added over 30 new behaviors to AI Engine, including improved detection of Trojans and Rats.
Improved program discovery. (Will run post-update)
Yellow tray icon denotes program discovery in progress.
Fixed bug where program discovery dialog would not always open.
Improved service start-up on Windows XP
“Daily” files no longer necessary
Fixed bug that could result in false positives that refuse to be “allowed”
Enhance Program Discovery to find additional programs.
Reduced CPU usage when updates are being applied.
Enhanced engine to detect/block additional attack vectors.
I am finding that the latest WInAntiRansom is acting way too chatty even in a regular game install, it popped up twice during STEAM Deus EX Humanity Divided install. That is bad since I am beginning to just disregard the warnings and allow them all...and that is not how it should work.
 
  • Like
Reactions: Der.Reisende

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top