App Review Qihoo 360 and Malwarebytes 3.1.2 vs. NonPetya

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
Hey thanks @Evjl's Rain!
I suspect that Qihoo used offline definitions (or cached signatures in its case) while detecting the file on execution... it displays the same name it had for the static detection, with no more info.
If it was HIPS/BB intercepting the attack, there could have been a different alert informing about the action performed by the malware, though I may be wrong here.
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Hey thanks @Evjl's Rain!
I suspect that Qihoo used offline definitions (or cached signatures in its case) while detecting the file on execution... it displays the same name it had for the static detection, with no more info.
If it was HIPS/BB intercepting the attack, there could have been a different alert informing about the action performed by the malware, though I may be wrong here.
something I forgot to tell, after I disabled the internet connection, I scanned the file again, it was not detected. Then I made the video

I also suspect some kind of caching
 

Andytay70

Level 15
Verified
Top Poster
Well-known
Jul 6, 2015
737
Not surprised here either not been a fan of MB since version 3.0 was released. Very mediocre to say the least. :eek:
I have to agree there froggy, Malwarebytes team must be holding their heads in their hands at how dreadful their product has become.
Finding another on demand scanner thats good now a days is getting harder!
 

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
I have to agree there froggy, Malwarebytes team must be holding their heads in their hands at how dreadful their product has become.
Finding another on demand scanner thats good now a days is getting harder!
Hitman Pro, Zemana, Norton Power Eraser(free), Herdprotect(beta)
all of these are miles better in detecting anything than Malwarebytes
 

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,716
I suspect that Qihoo used offline definitions (or cached signatures in its case) while detecting the file on execution... it displays the same name it had for the static detection, with no more info.

Maybe so. This one uses EB/DP to move. Maybe Qihoo found some reason to think someone might be working off line after leanning of the rpresence of NP so added sig.
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
Maybe so. This one uses EB/DP to move. Maybe Qihoo found some reason to think someone might be working off line after leanning of the rpresence of NP so added sig.
Though we cannot attribute a specific behavior with the detection, that attempt to exploit SMB via EB may be a possibility here.
There can be the enumeration of connected hosts - lookup and SMB copying, attempt of remote execution and what not among the possible interception(s) at different stages...the next and main trashing functionality aside.
 

codswollip

Level 23
Content Creator
Well-known
Jan 29, 2017
1,201
Malwarebytes team must be holding their heads in their hands at how dreadful their product has become.
Actually not. They insist that these videos are not real world tests and that in the "real world" MBAM would protect the system. Of course MB never offers proof of any protection apart from just words.
 
Last edited:

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684

Windows Defender Shill

Level 7
Verified
Well-known
Apr 28, 2017
326
Qihoo is very impressive

But I don't agree with the MB bashing, they're still probably the best at PUP detection. And they certainly detect most common ransom ware.
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Qihoo is very impressive

But I don't agree with the MB bashing, they're still probably the best at PUP detection. And they certainly detect most common ransom ware.
detect by signatures, yes, but if the ransomwares are zero-day, MB won't be able to protect
there are much better free options out there, such as appcheck and ransomoff

signatures and heuristics are covered by AVs
Also I read the official statement from MB that its anti-exploit module CAN'T block eternalblue/doublepulsar exploit

for me, zemana has a slightly better PUP protection and everyone can get it for free
 
Last edited:

Transhumana

Level 6
Verified
Well-known
Jul 6, 2017
271
It saddens me to see Malwarebytes performing that badly in latest tests; I've been a loyal customer for almost a decade, ever since it helped me to get rid of the only nasty infection I've ever had and every other thing i tried failed (and even though that happened a long long time ago, I still vividly remember the fear and panic I felt when that rogue crap popped up on my desktop :p). It has been my favorite piece of security software for a long time.
To be honest, I don't know much about AV software testing methodology so I don't know what to make of their claims that even though they don't score high on tests, they perform well in real world situations.
 
  • Like
Reactions: Sunshine-boy

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
It saddens me to see Malwarebytes performing that badly in latest tests; I've been a loyal customer for almost a decade, ever since it helped me to get rid of the only nasty infection I've ever had and every other thing i tried failed (and even though that happened a long long time ago, I still vividly remember the fear and panic I felt when that rogue crap popped up on my desktop :p). It has been my favorite piece of security software for a long time.
To be honest, I don't know much about AV software testing methodology so I don't know what to make of their claims that even though they don't score high on tests, they perform well in real world situations.
it's because we, as home users, rarely get true zero-day malwares. We usually get a week or a few months old malwares so we are usually protected by AVs

somebody told me that his company were protected by symantec endpoint protection but nonpetya infected many of the machines, although symantec/norton products have scored really well in MT hub tests + symantec can protect against eternalblue/doublepulsar exploit. not sure what happened
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top