App Review An Avast Free AV Ransomware Test

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

FrFc1908

Level 20
Verified
Top Poster
Well-known
Jul 28, 2016
950
I think it would be interesting to see how AVG Free does, considering the buy out. I'm thinking AVG would do better, which will make the buy out even more interesting for both products down the road.

I would not bother buying one of these two , the only thing you will get extra when buying avg is an outbound firewall! avast free is also enough. ad comodo firewall into the mix and you are good to go :D
 
Y

yigido

Avast = Top kek, CyberCapture doesn't work, Hardened Mode still doesn't work well. Having everything set to high doesn't equal with high detection (you will have high FPs instead).

Maybe after Avast will add IDP from AVG will be better (I won't put my hopes in that).
image.jpg
:D Don't say that lol
 

ExoGen CyberSecurity

Level 3
Verified
Well-known
Sep 17, 2016
113
image.jpg

:D Don't say that lol

The word 'kek', which comes from World of Warcraft or Korean. It means the same as 'rofl', or 'lmfao' Used primarily on the internet.

In other works topkek = top rolf / lmfao.

In my post I was talking about Avast and how some components don't work that well (I'm not saying avast is bad, it's ok).
 

Alikhan

Level 2
Verified
Oct 14, 2015
66
I also posted this comment on Youtube and just wanted to see some opinions.

Just a quick question:

CyberCapture is currently only triggered if the file is downloaded via the browser with the Web Shield component being active as well as participating in the Avast community setting enabled (enabled by default).

If you moved the file via USB to the VM or any other way, CyberCapture wouldn't trigger it. Did you download the sample directly through the web?

CyberCapture is currently limited to HTTP/HTTPs and it only targets exe files at this moment of time.

Thanks for the test.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I also posted this comment on Youtube and just wanted to see some opinions.

Just a quick question:

CyberCapture is currently only triggered if the file is downloaded via the browser with the Web Shield component being active as well as participating in the Avast community setting enabled (enabled by default).

If you moved the file via USB to the VM or any other way, CyberCapture wouldn't trigger it. Did you download the sample directly through the web?

CyberCapture is currently limited to HTTP/HTTPs and it only targets exe files at this moment of time.

Thanks for the test.
so we must have "Participate in avast community" enabled to make cybercapture work? I thought they were not connected.
could you show me the link we they say it must be enabled? I tried but couldn't find it
 
  • Like
Reactions: Deleted member 2913

Alikhan

Level 2
Verified
Oct 14, 2015
66
In order for CyberCapture to work, these 4 criteria must be met.

- CyberCapture needs to be enabled
- The file needs to be downloaded via HTTP(s) - At this moment of time no others methods trigger it.
- You have to have the Web Shield component installed "webshield to spot the download and mark it as being downloaded from a specific url"
- Participating in the Avast Community

It's fair to say that not everyone knows that by not having the Web Shield and/or not participating in the community renders CyberCapture useless so people should be sure before changing default settings and their implications.

You do NOT need to participate in Data Sharing.

Link to post from Avast Staff.
https://forum.avast.com/index.php?topic=187679.msg1323389#msg1323389
 
Last edited:

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,712
FP positives aren't THAT bad. I'd rather have a lot of those than an infected computer. ;)
I can see your point. However, there are some circumstances in which a false positive can be unacceptable.

1. Your antivirus falsely detects your documents and other school/work related things as malware and quarantined it.
It's annoying. But you can at least you can restore your files manually. This is the less troublesome one.

2. Same as 1. But the antivirus doesn't have a quarantine feature(or it isn't the default setting). In this case, the file is deleted.

3. Your antivirus detects system files as malicious. This is probably the worst one.
http://www.scmagazineuk.com/mcafee-...s-in-false-positive-nightmare/article/168521/
http://www.pcworld.idg.com.au/artic...e-detection-ruins-weekend-some-windows-users/

It's understandable for users that experience 2 or 3 to find it unacceptable.
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
I can see your point. However, there are some circumstances in which a false positive can be unacceptable.

1. Your antivirus falsely detects your documents and other school/work related things as malware and quarantined it.
It's annoying. But you can at least you can restore your files manually. This is the less troublesome one.

2. Same as 1. But the antivirus doesn't have a quarantine feature(or it isn't the default setting). In this case, the file is deleted.

3. Your antivirus detects system files as malicious. This is probably the worst one.
http://www.scmagazineuk.com/mcafee-...s-in-false-positive-nightmare/article/168521/
http://www.pcworld.idg.com.au/artic...e-detection-ruins-weekend-some-windows-users/

It's understandable for users that experience 2 or 3 to find it unacceptable.

A good quality AV wouldn't do 3 of the circumstances. I have been using Avast and I haven't hit mud yet. :)
 

XhenEd

Level 28
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 1, 2014
1,708
A good quality AV wouldn't do 3 of the circumstances. I have been using Avast and I haven't hit mud yet. :)
That's why FP detections generally are that bad. :D

As for Avast, I still think they're still developing (much more like Alpha or Beta) the CyberCapture tech even though it's now released, just like what they did to their celebrated "released" technologies (e.g. Evo-gen, NG, etc.).
 

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
I can see your point. However, there are some circumstances in which a false positive can be unacceptable.

1. Your antivirus falsely detects your documents and other school/work related things as malware and quarantined it.
It's annoying. But you can at least you can restore your files manually. This is the less troublesome one.

2. Same as 1. But the antivirus doesn't have a quarantine feature(or it isn't the default setting). In this case, the file is deleted.

3. Your antivirus detects system files as malicious. This is probably the worst one.
http://www.scmagazineuk.com/mcafee-...s-in-false-positive-nightmare/article/168521/
http://www.pcworld.idg.com.au/artic...e-detection-ruins-weekend-some-windows-users/

It's understandable for users that experience 2 or 3 to find it unacceptable.

Same reason why some people hate HIPS, like SpS Firewall on maximum setting. You are not just getting 2-3 calls per program opened.:D
 

woodrowbone

Level 10
Verified
Dec 24, 2011
480
Interesting news regarding CyberCapture, Avast crew must take this into consideration, that malware can enter from more points than http(s)?
There are still plenty of users using usb storage, Avast right now seems like half a antivirus???
CyberCapture should be triggered by execution, not web download.

/W
 

Alikhan

Level 2
Verified
Oct 14, 2015
66
Interesting news regarding CyberCapture, Avast crew must take this into consideration, that malware can enter from more points than http(s)?
There are still plenty of users using usb storage, Avast right now seems like half a antivirus???
CyberCapture should be triggered by execution, not web download.

/W

Yes that is correct.

I know that Avast are working to make CyberCapture work from more points than HTTP(s) such as via email, USB and other various mediums. I would also assume that they will make CyberCapture trigger against more file types since it is currently limited to exe.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top