Kaspersky Anti-ransomware Tool auto updating?

Status
Not open for further replies.

RejZoR

Level 15
Thread author
Verified
Top Poster
Well-known
Nov 26, 2016
699
Just wondering, is Kaspersky Anti-Ransomware Tool able to auto update itself? Has anyone seen it do that live? Asking because I can't see any "Check for updates" button. I know that most of the capability comes from System Watcher component and KSN cloud, but surely, at one point the program will have to get updated. Right?
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,683
For now We only have that beta build... and it seems has no auto-update feature, so if KL releases a new beta I guess We''ll have to uninstall and install the new one...
 

RejZoR

Level 15
Thread author
Verified
Top Poster
Well-known
Nov 26, 2016
699
Beta? The tool seems very much a final version... I mean, why would Kaspersky offer beta software to businesses which are the most critical about productivity and can't afford to use "beta" software...
 

RejZoR

Level 15
Thread author
Verified
Top Poster
Well-known
Nov 26, 2016
699
Well, I would and I have :D I've tried it before and it's as effective as System Watcher in Kaspersky AV. And you can see my test how effective it is there all by itself. Though, this one doesn't remove files, it only blocks access. Still, it protects the same and that's what's important.
 
K

KGBagent47

Well, I would and I have :D I've tried it before and it's as effective as System Watcher in Kaspersky AV. And you can see my test how effective it is there all by itself. Though, this one doesn't remove files, it only blocks access. Still, it protects the same and that's what's important.
Watching reviews of KAR was the tipping point that made me go ahead and purchase a KAV license. And your KAV videos made me very happy I did.
 

RejZoR

Level 15
Thread author
Verified
Top Poster
Well-known
Nov 26, 2016
699
It's just funny that KAR detects EVERYTHING under same detection name. It doens't matter if they are trojans, viruses or ransomware, they are all detected with same name. Anyone else noticed that?
 

N31R

Level 1
Verified
Jul 25, 2016
30
If you mean "Bazon.a" then that's the most prevalent name for cloud detection. There are a couple of others, but that's the most common one.
If you disconnect from the internet you'll only get the "offline" behavioral detection names like Trojan.Win32.Generic etc.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
It's just funny that KAR detects EVERYTHING under same detection name. It doens't matter if they are trojans, viruses or ransomware, they are all detected with same name. Anyone else noticed that?

Yup, well majority of detection came from cloud, heuristics and generic detection. Likely Kaspersky wants to reduce the redundancy load where signatures is obsolete in specific strain of infection.
 
  • Like
Reactions: harlan4096

Windows_Security

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 13, 2016
1,298
@RejZoR

My guess is that the way KapLar-AR is build it does not need a lot of updates. Reading the scarce documentation the cloud AV uses the Kapersky Security Network and the behavioral blocker receives heuristic pattern updates. The heuristics patterns contain the behavioral rules to block a program, so in theory this could be a near zero update program.
 
  • Like
Reactions: harlan4096

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
@RejZoR

My guess is that the way KapLar-AR is build it does not need a lot of updates. Reading the scarce documentation the cloud AV uses the Kapersky Security Network and the behavioral blocker receives heuristic pattern updates. The heuristics patterns contain the behavioral rules to block a program, so in theory this could be a near zero update program.
I think this product is over because the beta testing period is over (31/12/2016)
I tested it with KIS's system watcher only. KIS only missed 1 ransomware while this KARW missed a lot
 
W

Wave

I think this product is over because the beta testing period is over (31/12/2016)
I tested it with KIS's system watcher only. KIS only missed 1 ransomware while this KARW missed a lot
My guess is that it's either surrounded by static analysis methods (e.g. generic detection's) than behavioral aspects, or it has no real behavioral aspects. Since the System Watcher will be monitoring the program's execution flow (e.g. behavior based on what it does), whereas this might not intercept program's at all.

I might have a look and do some checking.
 

Windows_Security

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 13, 2016
1,298
@Wave

Use process explorer or process hacker to look at the two executables and simply list the DLL's in each product.

upload_2017-1-19_21-43-56.png


@Evjl's Rain
Were the results with cloud the same or close call?
 
Last edited:
  • Like
Reactions: harlan4096
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top