Start a Conversation

Unsolved

This post is more than 5 years old

2 Intern

 • 

5.8K Posts

1056

January 3rd, 2017 12:00

AVLab: Protection against Ransomware Test

AVLab is a Polish-based independent tester of security products. In October 2016 they tested 40 security solutions in their ability to block 28 malicious crypto-ransomeware threats, using Windows 10 Professional x64 systems. You can read an English translation of their results in pdf format here:
avlab.pl/.../ENG_2016_ransomware.pdf

Comment:
I don't speak Polish, and can't vouch for the "independence" or bonafides of AVLab. They seem legit. My security didn't object to their website, and the pdf file was clean. Interesting results. I'm not aware of any other comparative tests that look at ransomware.

3 Apprentice

 • 

15.3K Posts

January 3rd, 2017 14:00

Taking the liberty to summarize the "popular" free a-v products:

Only avast & avg earned a "good" rating... while avira, panda & windows defender all fell BELOW "average".  

If I'm reading the chart correctly, the combination of avast, when supplemented by MBAM PRO, would have an optimal impact.

2 Intern

 • 

5.8K Posts

January 5th, 2017 08:00

On this particular test, the combination of MBAM Premium and Avast Free would indeed have provided good protection.

However MBAM (and Malwarebytes Anti-Ransomware Beta) didn't perform that well in general, which is disappointing. It's too bad that CryptoPrevent was not included in this test. I see that currently it has over 40,000 definitions loaded. I use the free version 7.04.0021, which requires manual checks for updates. Which means I'm probably not current with protection most of the time, as I don't check for updates that often.

I note that Windows 10 was used as a test platform. The methodology and discussion don't address whether Win 10 or the Edge browser provides any protection against ransomware, but for the 28 samples used they obviously did not.

As I understand it, ransomware is usually contracted by a "drive-by" download, by just visiting a malicious website. It looks like a nightmare. I'm counting on my regular image (and data) backups to an external hard drive to save my bacon if I ever face this problem. I've no idea if this is sufficient.

No Events found!

Top