- Apr 17, 2021
- 454
Do you see Avira's certificate in the browser? Are they MITMing HTTPS connection or not?
Do you see Avira's certificate in the browser? Are they MITMing HTTPS connection or not?
There is a workaround: Create a folder, Drag and drop the files you want to scan (upload to APC for analysis) into the folder and Create a new custom scan in Avira to scan that folder.Yes, its light only takes around 40mb of memory. But no idea what i expected with the web protection and https scanning on free version , it still requires browser extension
About luke filewalker its gone, but i cant scan folders or items , cant even drag them to avira to scan
View attachment 267146
How's the browsing speed and CPU usage while browsing with HTTPS scanning? Is it heavy in this regard like Kasper or on the light side like ESET?
The performance impact is acceptable.How's the browsing speed and CPU usage while browsing with HTTPS scanning? Is it heavy in this regard like Kasper or on the light side like ESET?
Can it block malicious connections made outside of the browser?The performance impact is acceptable.
No + https scanning is greyed outDo you see Avira's certificate in the browser? Are they MITMing HTTPS connection or not?
Yes. I tested some scripts (trojan downloader) and it blocked malicious connections.Can it block malicious connections made outside of the browser?
If possible for you and your free time allows... Please can you sharing a few screenshots of protection settings?No + https scanning is greyed out
Based on my test so far, Sentry is good at blocking and rolling back changes made by Trojan dropper.Still remains weak against malicious scripts, resulting in an locked VM, saw no activity from Sentry aswell.
View attachment 267148
Problem was that Avira missed too much, there were 5 different startup items added, mostly JS and Windows Script Host items, and probably a lot more as it was only what Task Manager was showing, not to mention these were nasty pieces of malware, it may have detected some of these startup items if it werent for the new user, but it should have blocked them before they had the chance to add startup items, as if they had the chance to add startup items they probably already did their malicious actions, I manually ran these startup items, Avira didnt even react.Based on my test so far, Sentry is good at blocking and rolling back changes made by Trojan dropper.
This "add users" script is hard for BB to block, to be honest.
Maybe Sentry is still not good at script malware?Problem was that Avira missed too much, there were 5 different startup items added, mostly JS and Windows Script Host items, and probably a lot more as it was only what Task Manager was showing, not to mention these were nasty pieces of malware, it may have detected some of these startup items if it werent for the new user, but it should have blocked them before they had the chance to add startup items, as if they had the chance to add startup items they probably already did their malicious actions, I manually ran these startup items, Avira didnt even react.
Possibly, but as Avira (supposedly) have AMSI intergration I would have expected it too catch almost all malware samples, but it missed 5 out of 10 scripts, what was more concerning was the fact all of these samples were already detected by most major AV companies, almost all of which included Defender.Maybe Sentry is still not good at script malware?
Sorry i reverted backup already. @Anthony Qian already posted those settings that are changeable, only the https scanning enabled/disabled + some archive scan settings, there is nothing to see reallyIf possible for you and your free time allows... Please can you sharing a few screenshots of protection settings?
Maybe the free version doesn't have HTTPS scanning?No + https scanning is greyed out
I am using Antivirus Pro.Maybe the free version doesn't have HTTPS scanning?
@Anthony Qian Did you test free or paid version?
Doubt it. The signature engine seems to be the same as before.Hmm interesting, will it afect F-secure which use Avira engine?