App Review Avast Free (Hardened Mode) vs Ransominator

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

SeriousHoax

Level 49
Verified
Top Poster
Well-known
Mar 16, 2019
3,862
There is anyway to create a rule for that or do i need to set unknown applications as 'Untrusted' individually. I couldn't find any way to create a rule that could set all unknow apps as untrusted by default
Open "Protection" components of Kaspersky. Click on Application Control. There in this page this option is available.
 

Islam Gamal

Level 4
Verified
Well-known
Jan 25, 2018
155
i tested this sample with Comodo internet security latest version with two different settings. the first one: i changed the auto containment to block unknown files and with this settings Comodo blocked it immediately. the second one: i kept the default settings (Run virtually Partially limited) and the sample contained in the sandbox and the text file appeared but the files didn`t encrypted and when i closed the text file, it disappeared from the sand box.
 

harlan4096

Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,905
There is anyway to create a rule for that or do i need to set unknown applications as 'Untrusted' individually. I couldn't find any way to create a rule that could set all unknow apps as untrusted by default

1587970810955.png
 

Moonhorse

Level 38
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,728
Avast has security flaws, I don't expect it to stop a ramsonware that even kaspersky couldn't, lol kkk, it's a very weak antivirus.

Its always been decent, they have large userbase, they have the cashflow for everything with all that bloat/ paid services

Its top product, its far from weak,,,,some people just dont like that they datamine so much , but that doesnt mean their antivirus is lacking against others
 

Vitali Ortzi

Level 24
Verified
Top Poster
Well-known
Dec 12, 2016
1,322
Did someone submit it or was this automatic?

Kaspersky was also super aggressive in my testing at the cloud having a reaction. I had to recompile my sample with a bit more obfuscation midway through testing because it started getting blocked statically on other VMs after I clicked the button saying to undo.

No other AV I tested did this -- I suspect they required more than one or two hosts detecting a binary.
Not in the endpoint version you can be patient zero with never seen malware on just one endpoint and get a detection super fast .
The speed of the Russians is incredible!
Good to hear the speed of the non endpoint protection is fast as well !
 

SeriousHoax

Level 49
Verified
Top Poster
Well-known
Mar 16, 2019
3,862
Did someone submit it or was this automatic?

Kaspersky was also super aggressive in my testing at the cloud having a reaction. I had to recompile my sample with a bit more obfuscation midway through testing because it started getting blocked statically on other VMs after I clicked the button saying to undo.

No other AV I tested did this -- I suspect they required more than one or two hosts detecting a binary.
Maybe both automatic and manual submission! I'm not sure because I found it here last night and I didn't submit it: https://opentip.kaspersky.com/C92E226D39B612785F8CE5074DA03DEEC6618E5C9AAEB4046AD153133B027805/
Now you would see in that report that in the extracted files category Kaspersky found one Adware but that wasn't there for some reason when I checked the first time. It appeared there later. You're maybe right about it requiring more than one host to detect a binary. I think most of the initial UDS based detection are hash based. KSN blacklists this suspicious items with hash as a first line of defense to protect other users. The detection here was "UDS:Hoax.Win64.FakeRansom.a" Here "a" surely refers to variants so if the sample is slightly modified then Kaspersky might not detect it at first launch on a new PC but later would create another UDS signature and maybe this time the variants would be different so something like "b" instead of "a". It may continue to be like this till a malware analyst personally analyze and create a proper signature. I've seen similar behavior for Microsoft for some other samples.
Interestingly Bitdefender and ESET has now created signature for this sample: VirusTotal
Even Microsoft but I ran it in sanboxie with Windows Defender installed and WD didn't stop the sample from executing instead waited for me to open Windows Security and then I had to manually chose options but by that time the sample already did its job. This is detected by their cloud as some not so dangerous PUP it seems.
Edit: WD now detects it with a different signature: "Trojan:Win32/Wacatac.C!ml"
 
Last edited:

Fel Grossi

Level 13
Verified
Top Poster
Well-known
Jan 17, 2014
627
i tested this sample with Comodo internet security latest version with two different settings. the first one: i changed the auto containment to block unknown files and with this settings Comodo blocked it immediately. the second one: i kept the default settings (Run virtually Partially limited) and the sample contained in the sandbox and the text file appeared but the files didn`t encrypted and when i closed the text file, it disappeared from the sand box.
Thanks for test Comodo.

So even in the default settings Comodo protected the system. As i suspected
 
Last edited:

DSD27

Level 5
Well-known
Apr 15, 2020
227
Has Avast already created 'don't sell my personal information' mode? LOL
Do you have state secrets? They all get your info/data, don't be naive… The difference is either you're aware or not, if they tell you about it or not and if someone found out or not. Windows does it, Facebook does it, Google... If you start caring for that you won't be able to get online.
 
  • +Reputation
Reactions: stefanos

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
Looks like I maybe using Avast as my next AV after my subscription for F-Secure runs out. Is Avast light on a system at all? Haven't used it in ages. If one could provide an SS regarding the CPU & disk usage that would be great.

~LDogg
 

bayasdev

Level 19
Thread author
Verified
Top Poster
Well-known
Sep 10, 2015
901
Looks like I maybe using Avast as my next AV after my subscription for F-Secure runs out. Is Avast light on a system at all? Haven't used it in ages. If one could provide an SS regarding the CPU & disk usage that would be great.

~LDogg
I remember Avast Free 2019 when installed with minimal components being really light not as ESET but lighter than anything else, what concerns me is their data oriented business model.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top