AV-Comparatives Blog - Proactive Protection for WannaCry

Discussion in 'other anti-virus software' started by hamlet, May 17, 2017.

  1. hamlet

    hamlet Registered Member

    Joined:
    May 10, 2005
    Posts:
    229
    Here is a link to an interesting post on the AV-Comparatives blog. The post shows the results of a test to determine which av products would have detected WannaCry pre-May 12 on unpatched systems. One thing that jumps out is that they say that ESET Internet Security would not have detected WannaCry. That seems to be directly counter to ESET's statements on their forums.

    http://weblog.av-comparatives.org/proactive-protection-wannacry-ransomware/
     
  2. Spartan

    Spartan Registered Member

    Joined:
    Jun 21, 2016
    Posts:
    1,424
    Location:
    Dubai
    This is the email I got from ESET:

     
  3. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    From what I understand, ESET IS would have prevented the vulnerability that helped the malware spread not the malware itself.
    An update was needed to detect it on memory.

    Here's the post: https://forum.eset.com/topic/11948-massive-ransomware-attack/?do=findComment&comment=60078
     
  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    I have received emails from multiple vendors all claiming that they prevent it, while some seem to imply they are they only ones that do.
     
  5. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
    Was going to say, that does not seem correct about ESET.
     
  6. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
    Ditto got emails from multiple av companies with the same verbiage.
     
  7. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    In my experience (nothing scientific) just Kaspersky, Emsisoft and Bitdefender offers adequate protection against zero-day ransomwares.

    Ps: Yes I am biased :argh:
     
  8. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    Ehmmmm, ever heard about Comodoo_O :geek:
     
  9. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    Comodo isnt a traditional antivirus (it isnt even on Av Comparatives tests anymore), it has a solid focus on HIPS and Sandbox, a well configured Comodo will block almost all threats.

    Unlike those solutions that I cited, Comodo demands much more from the user, but this isnt bad per se.
     
  10. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    It depends on how you set it.
    For example, Comodo Firewall at Cruelsister's settings won't need almost any user interaction. The same is true for CCAV at default settings.
    Of course, the user should be aware of what the green border means (sandboxed app) and how to whitelist it (if the app is good) :)
     
  11. guest

    guest Guest

    tssssss, those vendors are weaklings compared to Appguard, BRN doesn't need such trivial and puny mail campaign , because ransomware just can't past it in the first place !

    Ps: I'm biased too :argh:
     
  12. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Me too am biased!

    Yesterday I run WannaCry in a shadowed session (Shadow Defender). Devilish nasty program encrypted tons of files in C and D drive, one for system the other for documents (4GB). Really quick this encryptor indeed. :'(

    Clicked restart... Suddenly all back to normal :geek: :-*
     
  13. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Hi Mister X,
    I also have Shadow Defender and I feel quite safe for now. But a question comes to my mind, is there any possibilities that one day ransomware will
    be able to block a restart?:(
     
  14. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Anything's possible with computers. If such comes to happen just push reset button or power button and you'll be just fine.
     
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I don't get it, why would ESET have failed to protect? It couldn't recognize it by signature or behavior blocker?
     
  16. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    @hamlet
    Thanks for sharing link to this interesting test.
     
  17. JRCATES

    JRCATES Registered Member

    Joined:
    Apr 7, 2005
    Posts:
    1,205
    Location:
    USA
    Interesting. Thanks for sharing, hamlet.

    17 of the 21 tested would have prevented it beforehand......not sure whether to feel good about that, or be concerned that all 21 didn't catch and stop it. On the surface, though, at least that does seems to speak well for those antivirus programs and solutions that DID successfully thwart and prevent it.

    Either way you look at it, it is interesting to see....and I'm glad that someone took the time to test these products in a prior state to see what "would have" happened.
     
  18. JerryM

    JerryM Registered Member

    Joined:
    Aug 31, 2003
    Posts:
    4,306
    I was surprised to see that Eset IS did not protect since it was one of two that MRG Effitas had a 100% detection.
    Jerry
     
  19. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    Panda did well, considering that it's a cloud av and they tested an offline system
     
  20. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I'm borderline shocked that Eset did not pass this test. They usually perform so well detecting, and blocking Ransomware.
     
  21. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,752
    Location:
    Toronto Canada
    Avira came through, so I have to be happy about that.
     
  22. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    When asked whether ESET had a sort of behavior blocker, they mentioned the Advanced Memory Scanner.
    https://forum.eset.com/topic/5283-behavior-blocker/#comment-29725

    However if you click the link I posted above. Marcos states "I would also add that a WannaCrypt memory detection was added in update 15403"
    So, it appears to required signatures and probably shouldn't be considered a behavior blocker.

    And since this was done with definitions prior to May 12, ESET couldn't detect it by any signature.
     
  23. Macstorm

    Macstorm Registered Member

    Joined:
    Mar 7, 2005
    Posts:
    2,642
    Location:
    Sneffels volcano
    That's why I never trusted Eset software...
     
  24. IBK

    IBK AV Expert

    Joined:
    Dec 22, 2003
    Posts:
    1,886
    Location:
    Innsbruck (Austria)
    There seems to be some misunderstanding - I will add a note to clarify (the test looked at the ransomware part only; ESET would have detected the spreading part though).
     
  25. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.