App Review Emsisoft vs. Ransomware - Double Feature (Juan Diaz)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Wraith

Level 13
Verified
Top Poster
Well-known
Aug 15, 2018
634
It seems that Emsisoft doesn't monitor the child processes if it's a trusted process. Fcrypt used cmd to encrypt the files and since cmd is a trusted windows component, the BB ignored it's actions. I wonder how OSArmor would fare in such a situation.
 

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,821
Big Emsisoft flaw. You must correct that.:p
It's being worked on:
We are currently reworking the way trust works in EAM, so it assigns trust based on a trust-chain. That means, GPG may be trusted when it is started by a trusted process, but not if it is started by an unknown or untrusted process.

There is no ETA yet for when this change will roll out ...
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top