- Apr 13, 2013
- 3,224
@Nightwalker I received some feedback from a friend who was testing RansomOFF that he found it very heavy on his machine. Have you had that experience?
@Nightwalker I received some feedback from a friend who was testing RansomOFF that he found it very heavy on his machine. Have you had that experience?
Thank you for the reply.Harbor- For me there is no contest- RansomOff is the winner for the following reasons:
1). Although slight, RansomOff has a better base mechanistic protection routine against ransomware than the others.
2). The Startup Alerts actually work for things other than ransomware. I didn't expand on this in the video, but will in the near future.
3). Although I personally don't like anti-exe functionality, many do. The way Helig has implemented it (on-demand only, and with options for signed and unsigned) is very nice.
4). When fully implemented the Folder exclusion thingy will be of value.
5). And most important- the quality of the Developer. Even though I was a total bitch by putting out this video (and on a weekend!), you may have noticed that Helig not only gave the video a Like, but without any Double-Talk or excuses acknowledged it and I'm sure will fix it very, very shortly. This attitude is very rare and should be very valued. As a sidenote, I actually had a previous video done in which RO passed totally, but when I received the Xdata sample I felt disingenuous by putting it out- so I did this one in its place, What a pain!
Anyway, minus the above LoveFest I prefer RansomOff to the others.
Thank youH- I'm glad you responded as I didn't point out something you mentioned above about the Jaff C variant- Yes, the original pdf was left on the system, but this file wasn't intrinsically bad as it had to bring up Word in order to run a macro which had to download the payload which then had to run. RO totally blocked the payload, so by leaving the original pdf is really trivial.
Now to your question- AppGuard is great (just ask Umbra), and I'm not familiar with reHIPS (also ask Umbra). But with RansomOff there is really nothing left to clean up (look how it dealt with the RAA sample). Anyway I feel that if ANYTHING is leaf over and has has to be cleaned up it is kind of a fail. That's why I love CF as all the crap can be flushed without further user input, and with RansomOff it will do this stuff automatically.
@HeiDef Not really crucial, but I would like the word "recommended" be included beside the word "Deny", or anything that signifies the recommended default action. Allow may also have the "not recommended".
Was Xdata removed/deleted as well?