- Apr 13, 2013
- 3,224
After running RAA.js .. there was an .exe appeared on task manager ? Am I wrong?Hardened Mode Aggressive missed too...it allows only Avast whitelisted stuffs?
It missed coz the samples were script & not exe (if I am correct samples are script And guess hardened mode monitors exe only)?
CyberCapture does only exe and when it knows they came from online(downloaded from http/s and you also have to have web shield on and Avast community on. You also have to sacrifice your firstborn and pray to our lord and Savior Gaben daily). If you copy them to a vm from your pc it doesn't do anything. So basically it's kind of a gimmick. Sure Avast people will find a reason it does this but ok for me anything that doesn't react always it's a gimmick.The sample that got by was the typical RAA ransomware- so the only exe that it called up (other than wscript) is Wordpad for the false Document. For this test I purposely didn't use anything either true Zero-day or stuff I code as I wanted the concentration to be on common malware that AVAST should react to but does not. Avast fans are too caught up in impressive sounding terms like "Hardened Mode" and "CyberCapture" (I still LOVE that term!), when in reality sometimes they work and sometimes they don't.
But Avast isn't trash by any stretch. I think next week will be a repeat Avast test, but this time against something that has been showing up with great frequency lately- an executable that will try to turn our system into a malware distributing Zombie.
Avast = Top kek, CyberCapture doesn't work, Hardened Mode still doesn't work well. Having everything set to high doesn't equal with high detection (you will have high FPs instead).
Maybe after Avast will add IDP from AVG will be better (I won't put my hopes in that).
FP positives aren't THAT bad. I'd rather have a lot of those than an infected computer.