App Review McAfee: how bad is the worst antivirus?

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
TPSC
I pressed CTRL + F on the bazar page and typed few letters of the hash haha
Yes, so it was more because of SHA256?
1752518387147.png
 
I pressed CTRL + F on the bazar page and typed few letters of the hash haha


This is the VT report.

Seems like Trend Micro has a rule in the pattern.
Yap. Remcos Backdoor is the signature name and it's not generic.
This file is fairly new dated July 14.
Results show some AV are still catching up on heuristics but soon that will change to official names.
 
I believe that if it were executed, they detected it by behavior.
I updated the report and Avast appeared now. Trend Micro detections with names are sometimes hash-based, they recently got patents on better threat correlation through clustering and calculations of N-grams. Only a test can confirm. Their detections have become much better named lately.

Nevertheless, it is detected.
 
I believe that if it were executed, they detected it by behavior.
Probably yes; however, I prefer to rely on pre-execution detection; post-execution detection is more risky, and ultimately need to reinstall Windows as not everytime I can revert changes to registry, scheduled tasks, and others.
 
I updated the report and Avast appeared now. Trend Micro detections with names are sometimes hash-based, they recently got patents on better threat correlation through clustering and calculations of N-grams. Only a test can confirm. Their detections have become much better named lately.

Nevertheless, it is detected.
B is still sleeping 😴
 
Probably yes; however, I prefer to rely on pre-execution detection; post-execution detection is more risky, and ultimately need to reinstall Windows as not everytime I can revert changes to registry, scheduled tasks, and others.
Yes, no problem. Of course, since it's not a VM or a dedicated test machine like @Trident has, it's better not to take any chances. Plus, K would block it because of application control and system inspector. Since it's an unknown file, without a signature, downloaded from the internet, K would probably put it in High Restriction and block its execution. This is a backdoor. If it tried to change something on your system, K would block it, shut down the process, and revert it, causing no damage to your machine. That's in the paid version of K. I don't know if the free version has application control and system inspector. Although no AV is perfect, I've never seen K fail in the paid versions, even with 0-day attacks.