Windows_Security
Level 24
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
- Mar 13, 2016
- 1,298
Hi all, I played with some anti-ransomware protection programs from performance and ease of use perspective. Feel Free to add your experience and free anti-ransomware program tips.
For performance I monitored the program launch time of the first and four consecutive starts of Chrome (Woolyss Chromium) on Pentium dual core (G3240@3.2Ghz) and first generation SSD (OCZ-Sata2). All programs did not affect download speed (as expected since their behavioral component will most likely monitor disk and process activity).
1. Kaspersky Anti-Ransomwate Tool for Business
Pro's: Easy to use, set and forget, does well in both formal tests as MalwareTips member tests.
Con: Does not auto update. So behavioral detection rules will age and reduce in effectiveness.
C:\Program Files\Chromium\chrome.exe - 5 executions Kaspersky Free business V1
0.8266
0.2659
0.2495
0.2914
0.2814
C:\Program Files\Chromium\chrome.exe - 5 executions Kaspersky Anti-Ransomware V2
0.6864
0.3538
0.3151
0.3487
0.3439
V2 has both a performance and useability improvement. V2 de-installs without the need to disable auto protection (therefore this setting has disappeared in console).
2. AppCheck by CheckMal
Pro's: Easy to use, set and forget, does well in MalwareTips member tests.
Con: Free version has a predefined set of file extensions it protects, which is missing some formats.
Tweak tip: change something in paid autobackup feature. Disable AppCheck protection. Open Regedit and look for AppCheck in HKLM/Software. Browse through it's registry keys settings and you will see a string with a lot of file extensions. Double click on that key and add the format you need to protect (e.g. AVI). Enable protection again and your are done. A wrongly edited key might lower protection, Therefor I explicitly give only directions, no screen prints, so only people knowing what they are doing are able to do this trick (for as long as CheckMal allows this tweak).
C:\Program Files\Chromium\chrome.exe - 5 executions AppCheck
0.7798
0.2373
0.2401
0.2594
0.2687
3. Secure Folders
Pro's: Easy to use, Has a GUI to define which folders to protect and which programs to allow
Con: Free because it is abondonware. Works on my machines with Windows 7, 8.1 and 10
C:\Program Files\Chromium\chrome.exe - 5 executions SecureFolders
0.6858
0.2654
0.3114
0.2958
0.2334
4. Pumpernickel by Execubits
Pro's: Mini-kernel driver with Secure Folders on steroids granularity.
Con: Free version needs ini-file (only suitable for power users) and is valid for on year (needs manual update om 1-4-2018).
C:\Program Files\Chromium\chrome.exe - 5 executions Pmpernickel
0.6391
0.2490
0.2648
0.2509
0.3215
5. RansomOff by Heilig Defense
Pro's: Offers Folder protection which has PumperNickel granularity with SecureFolders like graphical user interface. It also has some other goodies like MBR protection and Behavioral monitoring (called Policy protection). Experienced members like CruelSister like the concept and developer is open to improvement suggestions.
Con: Is still a Release Candidate. configuration is a breeze for power users, but user interface is not directed to guiding average PC users. The UI-design is from the late 90's so some might find it very ugly.
C:\Program Files\Chromium\chrome.exe - 5 executions RansomOff
0.5922
0.2520
0.2490
0.2176
0.2025
6. RansomFree by Cyberreason
Pro's: Really set and forget easy to use program with minimal performance impact. Protection can be disabled for one hour (e.g. when you want to do an image backup or data recovery). A lot can be said about the communication of Cyberreason (Israelian elite), but the bottom line fact is that this extra line of defense is very suitable for novice users and has minimal system impact.
Con: Canary approach is post-infection protection to minimize the damage.Cyberreason has released udates after new ransomware appears. Some people may dislike damage control security and use of canary files, but in professional world it is just one of the options of contingency management. Benefit of canary files is that it has low false positives and high compatibility with other security apps. Here is a video explaining canary file approach (link).
C:\Program Files\Chromium\chrome.exe - 5 executions RansomFree
0.4833
0.1870
0.1564
0.1575
0.1892
7.Document Protector by 360 Total Security
Pro's: Set and forget, easy to use program with an option to customize file extensions to be protected.
Con: You need another backup solution when you only protect documents changed in last 30 days. When you use eternal mode, it would suite as only protection, but files are backup on date, not on folder structure, so it is not easy to restore all files of a specific folder.
C:\Program Files\Chromium\chrome.exe - 5 executions 360 Document Protector
0.6235
0.2768
0.2500
0.2646
0.3283
8. Easy File Locker
Pro's: Set and forget, has same granularity as PumperNickel and Folder protection of RansomOff (you select which programs to exclude per folder).
Con's: Non really
C:\Program Files\Chromium\chrome.exe - 5 executions Easy FileLocker
0.5454
0.1713
0.1869
0.1712
0.1554
For performance I monitored the program launch time of the first and four consecutive starts of Chrome (Woolyss Chromium) on Pentium dual core (G3240@3.2Ghz) and first generation SSD (OCZ-Sata2). All programs did not affect download speed (as expected since their behavioral component will most likely monitor disk and process activity).
1. Kaspersky Anti-Ransomwate Tool for Business
Pro's: Easy to use, set and forget, does well in both formal tests as MalwareTips member tests.
Con: Does not auto update. So behavioral detection rules will age and reduce in effectiveness.
C:\Program Files\Chromium\chrome.exe - 5 executions Kaspersky Free business V1
0.8266
0.2659
0.2495
0.2914
0.2814
C:\Program Files\Chromium\chrome.exe - 5 executions Kaspersky Anti-Ransomware V2
0.6864
0.3538
0.3151
0.3487
0.3439
V2 has both a performance and useability improvement. V2 de-installs without the need to disable auto protection (therefore this setting has disappeared in console).
2. AppCheck by CheckMal
Pro's: Easy to use, set and forget, does well in MalwareTips member tests.
Con: Free version has a predefined set of file extensions it protects, which is missing some formats.
Tweak tip: change something in paid autobackup feature. Disable AppCheck protection. Open Regedit and look for AppCheck in HKLM/Software. Browse through it's registry keys settings and you will see a string with a lot of file extensions. Double click on that key and add the format you need to protect (e.g. AVI). Enable protection again and your are done. A wrongly edited key might lower protection, Therefor I explicitly give only directions, no screen prints, so only people knowing what they are doing are able to do this trick (for as long as CheckMal allows this tweak).
C:\Program Files\Chromium\chrome.exe - 5 executions AppCheck
0.7798
0.2373
0.2401
0.2594
0.2687
3. Secure Folders
Pro's: Easy to use, Has a GUI to define which folders to protect and which programs to allow
Con: Free because it is abondonware. Works on my machines with Windows 7, 8.1 and 10
C:\Program Files\Chromium\chrome.exe - 5 executions SecureFolders
0.6858
0.2654
0.3114
0.2958
0.2334
4. Pumpernickel by Execubits
Pro's: Mini-kernel driver with Secure Folders on steroids granularity.
Con: Free version needs ini-file (only suitable for power users) and is valid for on year (needs manual update om 1-4-2018).
C:\Program Files\Chromium\chrome.exe - 5 executions Pmpernickel
0.6391
0.2490
0.2648
0.2509
0.3215
5. RansomOff by Heilig Defense
Pro's: Offers Folder protection which has PumperNickel granularity with SecureFolders like graphical user interface. It also has some other goodies like MBR protection and Behavioral monitoring (called Policy protection). Experienced members like CruelSister like the concept and developer is open to improvement suggestions.
Con: Is still a Release Candidate. configuration is a breeze for power users, but user interface is not directed to guiding average PC users. The UI-design is from the late 90's so some might find it very ugly.
C:\Program Files\Chromium\chrome.exe - 5 executions RansomOff
0.5922
0.2520
0.2490
0.2176
0.2025
6. RansomFree by Cyberreason
Pro's: Really set and forget easy to use program with minimal performance impact. Protection can be disabled for one hour (e.g. when you want to do an image backup or data recovery). A lot can be said about the communication of Cyberreason (Israelian elite), but the bottom line fact is that this extra line of defense is very suitable for novice users and has minimal system impact.
Con: Canary approach is post-infection protection to minimize the damage.Cyberreason has released udates after new ransomware appears. Some people may dislike damage control security and use of canary files, but in professional world it is just one of the options of contingency management. Benefit of canary files is that it has low false positives and high compatibility with other security apps. Here is a video explaining canary file approach (link).
C:\Program Files\Chromium\chrome.exe - 5 executions RansomFree
0.4833
0.1870
0.1564
0.1575
0.1892
7.Document Protector by 360 Total Security
Pro's: Set and forget, easy to use program with an option to customize file extensions to be protected.
Con: You need another backup solution when you only protect documents changed in last 30 days. When you use eternal mode, it would suite as only protection, but files are backup on date, not on folder structure, so it is not easy to restore all files of a specific folder.
C:\Program Files\Chromium\chrome.exe - 5 executions 360 Document Protector
0.6235
0.2768
0.2500
0.2646
0.3283
8. Easy File Locker
Pro's: Set and forget, has same granularity as PumperNickel and Folder protection of RansomOff (you select which programs to exclude per folder).
Con's: Non really
C:\Program Files\Chromium\chrome.exe - 5 executions Easy FileLocker
0.5454
0.1713
0.1869
0.1712
0.1554
Last edited: