App Review More Fun with Ransomware Part 4

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Clearly Avast rely on the signatures which why the Hardened Mode nor the DeepScreen help a lot, considering that its still a lack of analysis how to prevent the possible buffer overflow attack.

Unfortunately the HIPS concept didn't help either which better to rely on the traditional ones.

Meanwhile for BDAR like other products, it should be up to date for latest ransomware variants.
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
Tornado- I already had a video finished about CryptoPrevent and similar Group policy modifiers that was to be published instead of this one, but just as I was going to upload it I discovered that CP will have a major new build coming out soon. Therefore I felt a video on the current version would be neither fair nor especially relevant.

But as soon as CP version 8 finishes beta I'll be all over it (for fair or foul).
 

Der.Reisende

Level 45
Honorary Member
Top Poster
Content Creator
Malware Hunter
Dec 27, 2014
3,423
Bit late to the party, but great vid as always :) Nice to see Avast! work well :) Had it in the past, quite good software, but the time I used it, agressive settings made the system quite slow. However I love their UI and the tons of stuff it has - and can be configured to the users wishes :)
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
minegroasprilla- as Circe (nice name, btw) stated I don't use an AV as I really don't see much point in them as they are fairly easy to bypass with any serious zero-day coding. For an example, if you have seen any of the Boot time videos you would have noticed that none of the AVs tested detected my timing Trojan, and only a minority detected the ransomware that was dropped (I made sure all of them would have stopped it if run normally).

The real issue would be if instead of an old ransomware sample I coded in a zero-day version...

Also, this may be of interest:

Google Online Security Blog: New research: Comparing how security experts and non-experts stay safe online
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top