New antiransomware product: RansomFree

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Is this product better than Malwarebytes 3.0 Anti Ransomware?

If the behavior analysis of RansomFree remains stagnant thus MBAR has an edge for this.

However once the scenario change, for sure RansomFree is a good alternative due to Behavior Analysis.

Relying on Behavior Analysis will take a lot of time for perfection cause everything may based from scratch production.
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
How about using Ransomfree + MBRFilter :cool:
If anyone can perform a review for this combo, I will be highly appreciated
MBRFilter, if it works, should solve the issue of petya protection.
But there are still 2 other major holes in ransomfree protection:
1 while it is protecting the C drive, other drives can get encrypted
2 it will only protect against malware that searches out and encrypts files in logical order. But if the malware is smart, and it can identify high-value data in order to target it first, then your data is toast.
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
W

Wave

It installs a driver, but doesn't give you control over it.
If you try to perform any operation that affects MBR, it will probably get blocked, and if you are lucky enough to remember that you have this driver, you will have to go and uninstall it.
It probably registers a callback to restrict write access to the MBR via FltRegisterFilter - maybe I will analyse and check next week.
 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
Just tested with Cerber.
Created 2nd partition and add same folder and files inside like the one on the desktop.
Files are:
  • jpg
  • png
  • excel
  • pdf
  • word
  • txt
Files on Z: drive are encrypted :mad:

Clipboard01.jpg

UPDATE:

CTB-Locker same results:
Clipboard01.jpg
 
Last edited:

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,141
Just tested with Cerber.
Created 2nd partition and add same folder and files inside like the one on the desktop.
Files are:
  • jpg
  • png
  • excel
  • pdf
  • word
  • txt
Files on Z: drive are encrypted :mad:

View attachment 127767

UPDATE:

CTB-Locker same results:
View attachment 127801
So other drives not protected. This software is good for me since I have only one C: in my MS SP4 and, best of all, it works on behavioral and proprietary techniques without malware signatures! Another tool for my sig-less arsenal.

Thanks
 
Last edited:

SKG2016

Level 1
Verified
Dec 19, 2016
42
I am not too mean here, but, any security software without matured proactive defense feature risks being breached by zero-day or even recent threats, I will watch the development of it for a year and see how it goes.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top