Jump to content

aranud87

ESET Insiders
  • Posts

    25
  • Joined

  • Last visited

  • Days Won

    2

Posts posted by aranud87

  1. 15 hours ago, wraith said:

    I have been using ESET since version 2.5(NOD32). You have an amazing team of analysts and researchers. I don't think it would be that much hard for your team to design an efficient anti-ransomware module that can block any unsigned process trying to encrypt files. That way the probability of false positives will be greatly reduced. You can argue that signed malware and malware those exploit lolbins could still encrypt the files, but then I can argue that no antivirus can catch 100% threats, so why use ESET or any other AV? If you implement this one simple rule, ESET will be able to stop more than 50% ransomwares for which it does not have a signature for. But then again, I somehow feel that the ESET team is not open to suggestions or positive/constructive criticism.

     

    As i say many time, it would be nice to have rules based on the livegrid if user want.

    Full Green Know/safe : allow
    Yellow : ask for launch / ask with high HIPS rules / ask for firewall
    Red : block 

     

  2. 23 minutes ago, novice said:

    OK , clever, but how come it was detected by Microsoft , which is being considered a below basic antivirus  and not detected by ESET with its HIPS, behavior blocker built in HIPS, anti-ransomware shield, "DNA signatures",  Live Grid  ....

     

    Now, somebody is going to provide a sophisticated "explanation" about why this happened, (always is not ESETs fault, there is an explanation for that) and the thread is going to be closed for further comments.

    And tomorrow is another day , like nothing happened!

     

    Hi,

    Sorry for bad english !

    On VT  https://www.virustotal.com/faq/#antivirus-file-scans:

    A given antivirus in VirusTotal detects a file and its equivalent commercial version does not

    VirusTotal antivirus solutions sometimes are not exactly the same as the public commercial versions. Very often, antivirus companies parametrize their engines specifically for VirusTotal (stronger heuristics, cloud interaction, inclusion of beta signatures, etc.). Therefore, sometimes the antivirus solution in VirusTotal will not behave exactly the same as the equivalent public commercial version of the given product.

     

    We can imagine, Eset VT havent Livegrid or PUA or not HIPS...just basic basic signature detection ? i don't know...

     

  3. Hi,

     

    You can search on VT
    https://www.virustotal.com/fr/#search

     

    For example the first :
    e669392b950af703197afaac68c6b7d928298ab9
    https://www.virustotal.com/fr/file/f1da8cc51bdb1e9193daaf267ee0464d4cd0cfaa43d168db4c32d7d4ce9fb93b/analysis/

    ESET-NOD32 - Win32/Floxif.H  - 20181201

     

  4. I know and i send regularly.

    But when i am not on my computer (family, friend), it would be easier to evaluate the reputation of an scanner online file.
    Because :

    VT : just say if it is detected (but don't submit directly and not say livegrid reputation)
    Eset Online Scanner : must be install / not live grid reputation and submission

     

    https://virusdesk.kaspersky.com/ or hxxp://whitelist.kaspersky.com/advisor are perfect for check suspicious and send file

×
×
  • Create New...