App Review F-Secure SAFE vs Ransominator

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

bayasdev

Level 19
Thread author
Verified
Top Poster
Well-known
Sep 10, 2015
901


I've setup protected folders but my sample is not able to trigger it or DeepGuard

This test shows how an antivirus behaves with certain threats, in a specific environment and under certain conditions.
We encourage you to compare these results with others and take informed decisions on what security products to use.
Before buying an antivirus you should consider factors such as price, ease of use, compatibility, and support. Installing a free trial version allows an antivirus to be tested in everyday use before purchase.
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
779
This matches my results with F-Secure. Even the Ransomware Protection designated folders doesn't overpower their whitelisting of the 7zip executable.

This has resulted in successful in the wild exploitation in the past -- except in the real world, the attacker just brought along a Node.js runtime.
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
Yikes, as a home user, and tech savvy myself, probably have a low chance of encounter this. Sounds like a wild pokemon when in this context.

~LDogg
 
  • HaHa
Reactions: bayasdev

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
779
Yikes, as a home user, and tech savvy myself, probably have a low chance of encounter this. Sounds like a wild pokemon when in this context.

~LDogg

I would still feel confident about F-Secure in the real world. Check out @harlan4096's final test report, Malware Hub Report - F-Secure 17.8 Beta - January 2020 Report

Of all of the tested samples, F-Secure only allowed one to encrypt your documents, and that was using the Node.js technique to bypass DeepGuard using a whitelisted binary. F-Secure did fairly well for static scanning. It did as well as I've seen other products do in the Hub for bonus dynamic testing (basically just DeepGuard testing). It has 4 or 5 engines layered together with differing strengths while remaining light.

DeepGuard used to have a reputation for having too many false alarms. These days, I find this new balance to be totally reasonable. Given all this talk about whitelisting individual Steam games to use Protected Folders, etc, I understand why F-Secure might have decided to implement their Protected Folders in this fashion.
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
I would still feel confident about F-Secure in the real world. Check out @harlan4096's final test report, Malware Hub Report - F-Secure 17.8 Beta - January 2020 Report

Of all of the tested samples, F-Secure only allowed one to encrypt your documents, and that was using the Node.js technique to bypass DeepGuard using a whitelisted binary. F-Secure did fairly well for static scanning. It did as well as I've seen other products do in the Hub for bonus dynamic testing (basically just DeepGuard testing). It has 4 or 5 engines layered together with differing strengths while remaining light.

DeepGuard used to have a reputation for having too many false alarms. These days, I find this new balance to be totally reasonable. Given all this talk about whitelisting individual Steam games to use Protected Folders, etc, I understand why F-Secure might have decided to implement their Protected Folders in this fashion.
I feel confident as I know the software is a top notch, just when people do this it can be/seem scary for other(s).

~LDogg
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
779
I feel confident as I know the software is a top notch, just when people do this it can be/seem scary for other(s).

~LDogg

Yep it's a great reminder that no AV software is perfect. You have to pair it at least with good common sense, and never feel so confident in your malware protection that you're willing to handle potentially unsafe files using a valuable computer.
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
Yep it's a great reminder that no AV software is perfect. You have to pair it at least with good common sense, and never feel so confident in your malware protection that you're willing to handle potentially unsafe files using a valuable computer.
Yes, one has to use common sense for daily activities for sure.

~LDogg
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top