App Review Avast's Behavior Blocker (Tested IDP Only) against ransomware

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
IDP/behavior shield has no protection against petya.
You tested petya too soon :D so avast failed quite early

I perfomed a similar test and left petya at the end of the video and obviously it couldn't protect

someone posted my avast IDP video on avast forum and they smashed me because I disabled the other modules, the test was invalid, not a bypassed, those 3 modules had a link to each other and should not be disabled... bla bla bla
 
Last edited:

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Avast components are likely connected to each other and if you disable one of them, hence will turn into soft protection only.

e.g Hardening Mode must be enable as it can determine quickly if the file is unrecognized regardless if no internet connection to retrieve immediate information.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Avast components are likely connected to each other and if you disable one of them, hence will turn into soft protection only.

e.g Hardening Mode must be enable as it can determine quickly if the file is unrecognized regardless if no internet connection to retrieve immediate information.
even though they are connected to each other, which is not verified, the avast dev. didn't say it clearly, avast IDP in malware hub test perform similarly to itself testing alone.

I dont really see any connection here
 
Last edited:

RejZoR

Level 15
Verified
Top Poster
Well-known
Nov 26, 2016
699
IDP/behavior shield has no protection against petya.
You tested petya too soon :D so avast failed quite early

I perfomed a similar test and left petya at the end of the video and obviously it couldn't protect

someone posted my avast IDP video on avast forum and they smashed me because I disabled the other modules, the test was invalid, not a bypassed, those 3 modules had a link to each other and should not be disabled... bla bla bla

This is not true. It protects against Petya (seen it myself, IDP only). I'm just not sure what was the case here.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
This is not true. It protects against Petya (seen it myself, IDP only). I'm just not sure what was the case here.
not for me. I have tested it several times but it always failed
perhaps you tested with a different sample/variant which could be blocked

by the way I have seen the same samples blocked by AVG's IDP but missed by avast's IDP and opposite in malware hub. It was inconsistent
 

RejZoR

Level 15
Verified
Top Poster
Well-known
Nov 26, 2016
699
You should contact avast! team. Or, if you can pack the Petya sample and drop a link to my PM (or at least the hash so I have a reference point). I'll talk to the guy in charge for IDP now that we have direct contact with the avast! guys I can poke them why this is happening.
 

erreale

Level 9
Thread author
Verified
Content Creator
Malware Hunter
Well-known
Oct 22, 2016
409
You should contact avast! team. Or, if you can pack the Petya sample and drop a link to my PM (or at least the hash so I have a reference point). I'll talk to the guy in charge for IDP now that we have direct contact with the avast! guys I can poke them why this is happening.

I could send you via PM the link to download the sample Petya I used.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top