how to test if anti-ransomware is working?

Status
Not open for further replies.

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I am presently running MBAR + bitdefender 2016 total security with the anti-ransomware module enabled.
I want to know whether this is conflicting and causing a downgrade in protection.
How can I test this?
Anybody know if I can safely run both at the same time?
 

Soulbound

Moderator
Verified
Staff Member
Well-known
Jan 14, 2015
1,761
I am presently running MBAR + bitdefender 2016 total security with the anti-ransomware module enabled.
I want to know whether this is conflicting and causing a downgrade in protection.
How can I test this?
Anybody know if I can safely run both at the same time?
Get yourself some samples and load it up in a Virtual Machine with your current setup.

Will not at all recommend you to test it on Host.

MT HUB Pack from 19 has a encryption sample (85)
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
in your opinion, am I right to be worried about the two softwares conflicting?
At first glance, they don't work the same way. BD requires that you define the folders to be protected, and it won't protect a folder that has system files in it.
MBAR seems to give global protection.
So that makes me think they would not conflict.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Since MBAR uses detection related to ransomeware, then you can find samples as mentioned. But regarding on its conflict then likely depends on behavior if a related detection occurred.
 
  • Like
Reactions: _CyberGhosT_

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
maybe I should just turn off that module in BD. I would think that MBAR, which is a dedicated software, should provide stronger anti-ransom protection than the module in BD.
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
MBAR is not currently reccomended for use on production systems as it is in beta, if they start and run on the same system meaning BD module & MBAR "do nothing" till MBAR is at a more stable build or commercial release. That's my honest advise, but your decision to make as it is your system. PeAcE
 

Soulbound

Moderator
Verified
Staff Member
Well-known
Jan 14, 2015
1,761
the sample from 19 is bound to be recognized by BD since @illumination confirmed it was detected by VIPRE and VIPRE uses BD signatures.

MBAR is in beta, but still stable enough to use in production machine so to speak.

Since BD has builtin AR protection, I do not see the need to over complicate things and certainly would not turn that feature off in BD.

unless you are visiting all sites possible, downloading everything under the sun, opening every single attachment you get on an email, chances of you getting infected by ransomware are low.

No protection is perfect when your browsing habits are wrong. Keep that in mind.
 
H

hjlbx

Bitdefender is just protection of defined folders from rapid modification. I am not sure about MBAR as I have never used it.

Of course, there is always potential for conflict between two security softs that do the same thing.

You can safely test using Shadow Defender or Virtual Machine.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top