App Review Total Security 360 vs Wanna Cry Ransomware

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,711
Thanks for the video.

I believe you were running on only the Qihoo engines without Bitdefender and Avira enabled. Don't know what the result would be with them on, but here is how to turn them on:

Go to Virus Scan on the Main GUI dialog on the left side (pics are of 360 Total Security Essentials but 360 Total Security should be almost exactly the same procedure):

1 Qihoo.png

Click on the badge top left:

2 Qihoo.png


Open Settings top right, just right of the blue shirt in this picture. Click on Virus Scan:

3 Qihoo.png


A little bit disappointing that the active system protection and that the Qihoo engines didn't get block the ransomware. I would have hoped those engines would be better by now than they appear to be, especially the AI engine. With Bitdefender and Avira on maybe it's a different story.

BTW, yes it's disappointing that the BD and Avira engines are off by default in 360 TS. It's not nearly as good without them. Last I saw Qihoo claimed that this is done to reduce system resource usage, but I'd be kind of surprised if it didn't save them money too...
 

stefanos

Level 28
Verified
Top Poster
Well-known
Oct 31, 2014
1,712
Thanks for the video.

I believe you were running on only the Qihoo engines without Bitdefender and Avira enabled. Don't know what the result would be with them on, but here is how to turn them on:

Go to Virus Scan on the Main GUI dialog on the left side (pics are of 360 Total Security Essentials but 360 Total Security should be almost exactly the same procedure):

View attachment 196406
Click on the badge top left:

View attachment 196407

Open Settings top right, just right of the blue shirt in this picture. Click on Virus Scan:

View attachment 196408

A little bit disappointing that the active system protection and that the Qihoo engines didn't get block the ransomware. I would have hoped those engines would be better by now than they appear to be, especially the AI engine. With Bitdefender and Avira on maybe it's a different story.

BTW, yes it's disappointing that the BD and Avira engines are off by default in 360 TS. It's not nearly as good without them. Last I saw Qihoo claimed that this is done to reduce system resource usage, but I'd be kind of surprised if it didn't save them money too...
360TS have many options for protection my friend. And this is the best option. The sandbox ;) And if you click fast block at hips you lost maby some files but not all
 
Last edited:

Atlas147

Level 30
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 28, 2014
1,990
see the video at 7:42 is the answer why 360 lost many files. black007 don t click block for 25 seconts


I don't think that should affect anything at all, when the prompt is up for the user to block or allow the detection the detection should be suspended and shouldn't be able to damage the computer.
 
  • Like
Reactions: black007 and AtlBo

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,711
360TS have many options for protection my friend. And this is the best option. The sandbox ;) And if you click fast block at hips you lost maby some files but not all

Thanks. Yes I have noticed this about 360. However, I tend to go with this view:

I don't think that should affect anything at all, when the prompt is up for the user to block or allow the detection the detection should be suspended and shouldn't be able to damage the computer.

Due to the damaging nature of ransomware, I also feel that Qihoo should block the activity itself immediately. This dilemma was faced by many of the a-v companies, who seem to have addressed it in some cases or for most ransomware samples. Qihoo for their part does have the file restoration application. Not sophisticated, but it works. Also, there is the decryption application for some ransomwares. In the case of WannaCry, I think that even if Qihoo had itself stopped the file at first detection (first alert), some files may have been damaged. That's the same issue I mentioned noticing with products of other vendors early on with WannaCry and some others I recall, like perhaps Petya and maybe Satana.

This said, Qihoo also does have the sandbox for running files as mentioned by @stefanos. Sandbox is a big bonus for MS Office. I haven't ever been able to get it to work from the context menu to run files in a standard user account, though. It's hard to work with otherwise for running single new files.

Anyway, my solution for the computer that is running Qihoo 360 is Comodo Firewall + Qihoo 360 Essentials (very light) + AppCheck A/RW + NVT OSArmor. It's overkill, except that I use the computer quite oftenly, and none of the apps are resource greedy in any way. I can still see why someone could say it's way too much, but it works very well for me , and I am confident with the setup. It's maximum possible peace of mind for free, unless maybe I ran Kaspersky Security Cloud in place of 360. Just wanted the Bitdefender and Avira signatures from a-v anyway.
 

black007

Level 1
Thread author
Verified
Jul 14, 2014
30
first of all Thank for this reply

Thanks for the video.

I believe you were running on only the Qihoo engines without Bitdefender and Avira enabled. Don't know what the result would be with them on, but here is how to turn them on:

Go to Virus Scan on the Main GUI dialog on the left side (pics are of 360 Total Security Essentials but 360 Total Security should be almost exactly the same procedure):

View attachment 196406
Click on the badge top left:

View attachment 196407

Open Settings top right, just right of the blue shirt in this picture. Click on Virus Scan:

View attachment 196408

A little bit disappointing that the active system protection and that the Qihoo engines didn't get block the ransomware. I would have hoped those engines would be better by now than they appear to be, especially the AI engine. With Bitdefender and Avira on maybe it's a different story.

BTW, yes it's disappointing that the BD and Avira engines are off by default in 360 TS. It's not nearly as good without them. Last I saw Qihoo claimed that this is done to reduce system resource usage, but I'd be kind of surprised if it didn't save them money too...

i Think the engines isnot Problem couse i can crypt file of the two outher engines

and do not forget this Settings are It is assumed to be from the company it self and some user do not know about that and Do not change the settings

this is real test in real world :oops::oops::oops:

360TS have many options for protection my friend. And this is the best option. The sandbox ;) And if you click fast block at hips you lost maby some files but not all


see the video at 7:42 is the answer why 360 lost many files. black007 don t click block for 25 seconts


in the real world most of People donot run any file in sandbox Only if it is for testing

It is assumed that the company is activating the sandbox automatically and not by the user like avast

and even i pressure blcok faster The result will be the same

I don't think that should affect anything at all, when the prompt is up for the user to block or allow the detection the detection should be suspended and shouldn't be able to damage the computer.

Some people read messages that appear to them

This is given from to 4 sec or More to file to work freely

Which during that period the file has been completed
 
  • Like
Reactions: AtlBo and upnorth

stefanos

Level 28
Verified
Top Poster
Well-known
Oct 31, 2014
1,712
Thanks. Yes I have noticed this about 360. However, I tend to go with this view:



Due to the damaging nature of ransomware, I also feel that Qihoo should block the activity itself immediately. This dilemma was faced by many of the a-v companies, who seem to have addressed it in some cases or for most ransomware samples. Qihoo for their part does have the file restoration application. Not sophisticated, but it works. Also, there is the decryption application for some ransomwares. In the case of WannaCry, I think that even if Qihoo had itself stopped the file at first detection (first alert), some files may have been damaged. That's the same issue I mentioned noticing with products of other vendors early on with WannaCry and some others I recall, like perhaps Petya and maybe Satana.

This said, Qihoo also does have the sandbox for running files as mentioned by @stefanos. Sandbox is a big bonus for MS Office. I haven't ever been able to get it to work from the context menu to run files in a standard user account, though. It's hard to work with otherwise for running single new files.

Anyway, my solution for the computer that is running Qihoo 360 is Comodo Firewall + Qihoo 360 Essentials (very light) + AppCheck A/RW + NVT OSArmor. It's overkill, except that I use the computer quite oftenly, and none of the apps are resource greedy in any way. I can still see why someone could say it's way too much, but it works very well for me , and I am confident with the setup. It's maximum possible peace of mind for free, unless maybe I ran Kaspersky Security Cloud in place of 360. Just wanted the Bitdefender and Avira signatures from a-v anyway.
The HIPS of 360TS is every time with question. You must click fast for block if you want to not see big troubles .I used it many years and i know this. Agree with you for combo. Works very good and secure with woodooshield and is very light with osarmor. For now i use it with osarmor. But this test for me is not good because the tester not click the block and want to show us 360TS is trush. The problem is not Avira and Bitdefender on this test because the cloud signature found the ransomware.
 

stefanos

Level 28
Verified
Top Poster
Well-known
Oct 31, 2014
1,712
first of all Thank for this reply



i Think the engines isnot Problem couse i can crypt file of the two outher engines

and do not forget this Settings are It is assumed to be from the company it self and some user do not know about that and Do not change the settings

this is real test in real world :oops::oops::oops:





in the real world most of People donot run any file in sandbox Only if it is for testing

It is assumed that the company is activating the sandbox automatically and not by the user like avast

and even i pressure blcok faster The result will be the same



Some people read messages that appear to them

This is given from to 4 sec or More to file to work freely

Which during that period the file has been completed
The only automatically sandbox in COMODO sandbox. And i think everybody if download one unknown file or one crack sure first time run it in sandbox. And try it again the ransomware with fast block. I am sure the result is not the same.
 
  • Like
Reactions: AtlBo

stefanos

Level 28
Verified
Top Poster
Well-known
Oct 31, 2014
1,712
Agree with you. But in this test would not change the result and with all the engines open. Only the fast block
I would like a comment from Evjls Rain because he knows this product very well and has done a lot of tests on the protection mechanism of 360TS
 
  • Like
Reactions: AtlBo

black007

Level 1
Thread author
Verified
Jul 14, 2014
30
The only automatically sandbox in COMODO sandbox. And i think everybody if download one unknown file or one crack sure first time run it in sandbox. And try it again the ransomware with fast block. I am sure the result is not the same.

If your words are true why you did not company put sandbox in automatic mode and run any file suspicious in sandbox

Do not Depends on the user couse some of them dont now what is malware

and most of them Leaves settings by default

I still say that the program is not good because I tried to hack the device with the a payload and Activate all engines

and hack is done without any Notifications

If you ask me to do a video to prove that I'm ready
 
  • Like
Reactions: AtlBo and stefanos

Libera Milanesi

Level 2
Verified
Aug 19, 2018
52
a lot of tests on the protection mechanism of 360TS
They have good technology, there's absolutely no way you can ignore this. I haven't done thorough tests with their sandbox but the real-time protection works properly and they have other nice behavioral features. The option for using the Avira and Bitdefender engine is always a huge bonus because both Avira and Bitdefender are great with signatures.

I wonder to what extent Qihoo use the Avira and Bitdefender SDK's though in terms of whether they only use signatures or other content like Machine Learning from them as well. Does anyone here know who could tell me, or should I contact Qihoo instead and ask?

On the whole, I recon Qihoo performs quite well for protecting a customer from malware.
 

stefanos

Level 28
Verified
Top Poster
Well-known
Oct 31, 2014
1,712
If your words are true why you did not company put sandbox in automatic mode and run any file suspicious in sandbox

Do not Depends on the user couse some of them dont now what is malware

and most of them Leaves settings by default

I still say that the program is not good because I tried to hack the device with the a payload and Activate all engines

and hack is done without any Notifications

If you ask me to do a video to prove that I'm ready
Do same video but with fast block
 
  • Like
Reactions: AtlBo and black007

stefanos

Level 28
Verified
Top Poster
Well-known
Oct 31, 2014
1,712
yes only fast block but the program still not good

i will test other ransomware and recrypt them without any Notifications and see with he did
Believe me, I have been testing this program for many years. It is very good for free antivirus if you take advantage of all the protections it gives you. I can not post my tests because I do not speak good English and I can not explain what i do. And with Comodo firewall combo you have maby the best protection
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top