Advice Request Do you use AppCheck Anti-Ransom?

Please provide comments and solutions that are helpful to the author of this topic.

Do you use AppCheck?

  • I use AppCheck free version

    Votes: 12 18.2%
  • I use AppCheck pro version

    Votes: 4 6.1%
  • I use a different anti-ransomware

    Votes: 12 18.2%
  • I don't need a standalone antiransomware solution

    Votes: 34 51.5%
  • What's Appcheck?

    Votes: 4 6.1%
  • What's ransomware?

    Votes: 0 0.0%

  • Total voters
    66
Status
Not open for further replies.

Handsome Recluse

Level 23
Verified
Top Poster
Well-known
Nov 17, 2016
1,242
It's data damage control. You're system might be infected but at least your data is intact. Might save people from the holes in the downtime of backups. This could be really important for some. Notably people who basically inputs data everytime. Especially because antivirus is the most likely main protection and this is just an easy install.
 
  • Like
Reactions: AtlBo and shmu26

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,141
Nope, just tested today Petya on GPT. Ended up without any partitions and a big red skull on my display :)
You mean there's a ransomware that attacks GPT? Or are you referring to the MBR part (for backware compatibility) of the GPT?

If you also have MBRFilter installed maybe this will save you.

Thanks
 
  • Like
Reactions: AtlBo

Quassar

Level 12
Verified
Well-known
Feb 10, 2012
585
I dont use any standalone apps kind of anti ransome etc.
I stay with solid SRP/HIPS regroup with facing aplications in Virtual and Sandbox database/systems

SpyShelter + AppGuard
Vmware / Sandbox and SadowDefender on main system
 
  • Like
Reactions: AtlBo and shmu26

Peter2150

Level 7
Verified
Oct 24, 2015
280
It's data damage control. You're system might be infected but at least your data is intact. Might save people from the holes in the downtime of backups. This could be really important for some. Notably people who basically inputs data everytime. Especially because antivirus is the most likely main protection and this is just an easy install.

My downtime from backups is nil. My hourly incrementals take on average 45 seconds. I just did a restore from the most recent incremental. The restore took a whopping 45 seconds.
 
D

Deleted member 178

@Peter2150 seems macrium really boosted their solution since last time i used it (long long time ago) ; btw , welcome to to MT, didn't remembered you registered ;)
 
  • Like
Reactions: AtlBo and shmu26

Amelith Nargothrond

Level 12
Verified
Top Poster
Well-known
Mar 22, 2017
587
You mean there's a ransomware that attacks GPT? Or are you referring to the MBR part (for backware compatibility) of the GPT?

If you also have MBRFilter installed maybe this will save you.

Thanks

I mean that Petya (two options):
  • overwrote part of (if not the entire) Partition Entry Array, which is in the primary GPT header (LBA2), adding its own entries in the GPT structure or
  • overwrote the first sectors of the hdd, adding its own classic MBR at the beginning of the HDD, creating the EFI partition and encrypting the rest of the content in bulk
, otherwise the pc would not boot, the HDD would still have all the partitions, not just one big and valid one (like after the attack).

But if it doesn't overwrite what it overwrites in a controlled manner, might be difficult to recover the HDD if you pay the ransom.

To conclude,
Before the attack: i had UEFI/GPT and 4 partitions
After the attack: i had UEFI and one partition (didn't analyze the structure unfortunately). UEFI can cope with MBR as long as it has the EFI partition table, but i don't think i saw that. So my personal opinion is that Petya created it's own GPT structure entirely. But this needs to be verified, they are just assumptions based on what i saw for a few seconds at the Macrium recovery step in the UI of Reflect.
 
Last edited:

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
any chance that we can attach 2 cruelsister's video about appcheck free and pro in the first post in the spoiler so everyone can have a look what appcheck is and how effective it is?
@shmu26 what do you think? I know you cannot edit your post but maybe a mod/admin can help

Links to the 2 videos:

 
Last edited:

jerzy601

Level 21
Verified
Top Poster
Well-known
Jun 20, 2011
1,005
Not on my laptop I do not use this soft because it does not need it because I use other anti-ransomware programs.
 
  • Like
Reactions: AtlBo and shmu26

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
any chance that we can attach 2 cruelsister's video about appcheck free and pro in the first post in ther spoiler so everyone can have a look what appcheck is and how effective it is?
@shmu26 what do you think? I know you cannot edit your post but maybe a mod/admin can help
Great idea. Mods?
 

cruelsister

Level 43
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
Evjl and Shmu- There will also soon be a third one. Starting this weekend will be published a the first of a weekly 4 part ransomware series:

1). RanStop
2). AppCheck
3). HMPA
4). CF10

The same malware will be used for all.
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
I don't need to. A good AV, tweaked browser, max UAC and common sense are enough to avoid ransomware without the need of all these anti-exe programs slowing the everyday usage.
If I was the only one using my PC, this would be a correct assessment for me as well, Buuuttt
I have 3 daughters and a click happy wife, AppCheck fits right in there
I run Voodoo, W.A.R & HMPA, they could not dream of slowing down this beast ;)
 

brod56

Level 15
Verified
Top Poster
Well-known
Feb 13, 2017
737
If I was the only one using my PC, this would be a correct assessment for me as well, Buuuttt
I have 3 daughters and a click happy wife, AppCheck fits right in there
I run Voodoo, W.A.R & HMPA, they could not dream of slowing down this beast ;)

Yeah sure. I have my parents computer tweaked too with Kaspersky in TAM. If we are experienced, then we don't need any type of anti-exe. But in case on novice users, I always recommend to them one of the three: Kaspersky (TAM), Voodoshield or Comodo Firewall (Proactive).
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top