Author Topic: Ransomware Shield only blocking modifications or also access to data?  (Read 3537 times)

0 Members and 1 Guest are viewing this topic.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
I was wondering, is Ransomware Shield only blocking unknown programs from modifying protected files or will it also prevent reading of those files even if they aren't being modified at all? Coz while modification (encryption) is super annoying and unwanted, stealing said data without modification can also be an issue. How is that handled by Ransomware Shield?
Visit my webpage Angry Sheep Blog

Offline Claudiu7

  • Jr. Member
  • **
  • Posts: 64
is that handled by Ransomware Shield?

Also I want to know if Ransomware Shield, beyond doing what its name says, can cook, clean and wash dishes....

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
I'm asking in all seriousness, because if it also prevents reading of files, not just modifications, it can be used to reinforce security on certain things, like browser for example and preventing rogue apps from stealing its data, like password storage file of the browser etc
Visit my webpage Angry Sheep Blog

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
I was wondering, is Ransomware Shield only blocking unknown programs from modifying protected files or will it also prevent reading of those files even if they aren't being modified at all? Coz while modification (encryption) is super annoying and unwanted, stealing said data without modification can also be an issue. How is that handled by Ransomware Shield?

As I have said before I'm not even sure if it is protecting the folders I entered manually and I know no way to test this.

I put on were my downloads, images and data folders (not default locations), have come .pdf, various image formats and .txt file types.

It doesn't stop me opening them, nor does it stop me deleting them.  As far as text and image files go it allows them to be edited with a text or image editor.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
That's how Smart Mode works, it allows whitelisted apps to manipulate protected files, but not unknown ones. Which is why I'm asking, it's almost impossible to test with legit apps. Controlled Folder Access in Windows Defender was suppose to work this way, yet their whitelist is absolute worthless garbage for some reason. And it's Microsoft, they should've had the best whitelist...
Visit my webpage Angry Sheep Blog

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
...will it also prevent reading of those files even if they aren't being modified at all? Coz while modification (encryption) is super annoying and unwanted, stealing said data without modification can also be an issue.
Hi, there's a separate shield for this in Premium.
-> https://support.avast.com/en-ww/article/39/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
...it can be used to reinforce security on certain things, like browser for example and preventing rogue apps from stealing its data, like password storage file of the browser etc
Another function that is available in Premium.
https://support.avast.com/en-ww/article/Use-Antivirus-Password-Protection/
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
As I have said before I'm not even sure if it is protecting the folders I entered manually and I know no way to test this.
Hi Dave, for testing purpose you could blacklist an app, it should get blocked then.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
As I have said before I'm not even sure if it is protecting the folders I entered manually and I know no way to test this.
Hi Dave, for testing purpose you could blacklist an app, it should get blocked then.

Thanks for that.

Though the more I'm seeing of this, I feel with the major differences (which weren't particularly clear), this seems to be a hook to purchase the Premium version.  As the Smart Scan still mentions files at risk even though I have the Ransomware Shield enabled.  In which case i will probably disable/remove it completely and go to my fallback a robust backup and recovery strategy.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
1. Though the more I'm seeing of this, I feel with the major differences (which weren't particularly clear), this seems to be a hook to purchase the Premium version.
2. As the Smart Scan still mentions files at risk even though I have the Ransomware Shield enabled.  In which case i will probably disable/remove it completely and go to my fallback a robust backup and recovery strategy.
1. Tbh, I don't think so. Afaik, there are no differences (Free/Premium) regarding Ransomware Shield.
2. Most probably because the FAQ/Ads haven't been adjusted/updated yet, this usually takes a while.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Ransomware Shield only blocking modifications or also access to data?
« Reply #10 on: July 11, 2020, 02:55:46 PM »
1. Though the more I'm seeing of this, I feel with the major differences (which weren't particularly clear), this seems to be a hook to purchase the Premium version.
2. As the Smart Scan still mentions files at risk even though I have the Ransomware Shield enabled.  In which case i will probably disable/remove it completely and go to my fallback a robust backup and recovery strategy.
1. Tbh, I don't think so. Afaik, there are no differences (Free/Premium) regarding Ransomware Shield.

2. Most probably because the FAQ/Ads haven't been adjusted/updated yet, this usually takes a while.

Unfortunately I don't have the same confidence when details are lacking.  The FAQs and Ads really should have been given an update before release so they too can be updated at the same time.

Perhaps the fact that I really don't need the cover provided (doesn't help), having made my own backup and recovery provision.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5494
  • Whatever will be, will be.
Re: Ransomware Shield only blocking modifications or also access to data?
« Reply #11 on: July 12, 2020, 04:33:28 PM »
With Strict mode enabled, even Windows Explorer got blocked by Ransomware shield.
And as long as I can see Ransom shield only blocks modifications, not access.
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline DougCuk

  • Jr. Member
  • **
  • Posts: 50
Re: Ransomware Shield only blocking modifications or also access to data?
« Reply #12 on: July 18, 2020, 01:17:44 PM »
The Ransomware Shield by design only blocks changes to files (edits, renames, deletion, encryption) but it doesn't block read access.

In Avast Free v20.5 the Ransomware Shield definitely works in "Strict Mode" - but you would have to list all your own Apps as allowed and also things like Windows Explorer and the Command Prompt to avoid being queried every time you tried to alter your own data.

However I have yet to prove that the default "Smart Mode" is actually protecting anything. The oldest and least known editing program I could find was a 20 year old Hex Editor with no digital signature and from a random author (not a named company) and was able to freely change file contents without triggering a response. So I am not sure what criteria Avast is using as to its internal list of Trusted Apps. Has anyone found an program that "Smart Mode" does block?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Ransomware Shield only blocking modifications or also access to data?
« Reply #13 on: July 18, 2020, 01:28:17 PM »
Has anyone found an program that "Smart Mode" does block?
Yes, example in screenshot, I had to whitelist it manually.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DougCuk

  • Jr. Member
  • **
  • Posts: 50
Re: Ransomware Shield only blocking modifications or also access to data?
« Reply #14 on: July 18, 2020, 02:53:07 PM »
Was that a particularly old version of that file?
I have just tested with v15.2 of that file (7zG.exe) dated Nov 2015 and can't get a reaction when adding files to a 7z archive that is supposedly protected by the Ransomware Shield under Smart Mode. I tested both the x86 and x64 versions and both are ignored by the Shield under Smart Mode - that version has no digital signature on the files.

If I activate "Strict Mode" the action is blocked with a red Avast popup warning and if I blacklist 7zG.exe I get a Windows error popup saying Access Denied. So the system is active but doesn't consider my version of 7zG.exe a threat under Smart Mode.

If the Shield doesn't react to a 20 year old Hex Editor from a random author with no digital signature then I am not sure what would qualify as a non-trusted app.