The Best Ransomware Protection of 2017

Discussion in 'other software & services' started by Rasheed187, May 6, 2017.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Let me present challenge in this way and I though of this after seeing HeiDef's comment about doing their testing in a VM. Is there a Ransomware application that you would trust on your real system and testing real malware on the same?
     
  2. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I don't test and never did test in a VM.

    For my purposes that's too easy and although a safer way out it's because I like a real system to actually take/feel the punches if there's going to be a fight.

    Of course that also takes into account a ready-image when things go south, and they often do with any malware on a RAW system.

    To answer the last question I WILL and DO trust certain AntiRansomware on a live production rig but NEVER TEST MALWARE OF ANY SORT on the same.
     
  3. plat1098

    plat1098 Guest

    On a dedicated test machine, yes, and would prefer this over a virtual machine any day. On my personal workstation? Never.
     
  4. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Well since there is VMaware stuff out there you have to test on a real system, but since you use MR it shouldn't matter.
     
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I just had a crazy thought or better yet question.

    Testing on a live system with VM how can you be 100% sure that some of today's really crafty stuff doesn't find a way onto the host unseen and at worse snuggle in there until a certain time before going active on the host?

    I almost left out that I absolutely have run m-ware on a production environment under Shadow Defender.

    Don't ask me how but for some reason old SD still seems to hold up very well.
     
  6. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    In a virtual environment the guest os runs in a separate environment from the host os.

    Ransomware infecting the guest os can only harm that system. You can shut down the infected vm it installed to and remove it poof - its gone!

    I wouldn't advise ransomware testing on your host os. No telling whether your security software can recognize and block it before it starts encrypting files.
     
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    SD will hold up well until if and when it becomes as popular as SBIE. Then it shouldn't be to hard for malware authors to beat. Easter as to your VM question. A ways back Barb_C advised me to add all my VMware processes to my guarded app list in Appguard. That way they are protected with Memguard and it just enhances the isolation.

    But now back to the main thing I was getting at.

    As many might know, I run MZwritescanner, FIDES, Appguard ERP and SBIE. I also run Macrium on an hourly schedule. I see them protecting me every day. If I forget about them I can' t even uninstall anything no less install. So good stuff can't get on my system without me knowing so I know I am protected about the bad stuff. Testing in the vm only confirms nothing, malware ransomeware or something I want, can run without me letting it.

    But if you are going to count on something to protect you specifically from Ransomware, how do you know it will work without testing on your rig? This is why I've said in the past if you are going to count on something it has to be 100%
     
  8. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,807
    Location:
    .
    I'm always under the shadow.
     
  9. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    That's good then. Sort of like Shadow Defender but far more feature rich and wide reaching (installing O/S's, saving images etc)

    I only tinkered with Virtual Box and even VMware but that was a long long time ago and although seemed pretty flawless those VM's taxed their portion of the system resources. I imagine they are much better now at handling that then before.

    File infectors of any sort are notorious as is ransomware.

    Looks like @Peter2150 has had a few go arounds testing various antiransomware programs that left him rather flat and not impressed.
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    VM's aren't always 100%, Vmware just did a patch on Workstation that was essentially a memory leak between host and VM
     
  11. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    I'm running Oracle VB on Windows 10.
     
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    How do you like it? Do you test anti-ransomware apps in it to test their ability?

    I agree with Pete that it's too late once a system gets poked by this stuff but I also respectfully disagree that it's too late if a formidable enough antiransomware app also has a qualifying rollback procedure built-in to them too.
     
  13. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    No. I run Linux on it.

    A good antiransomware app like KAR should not only be able to block the attack but to roll back files to their previous state.
     
  14. Nitty Kutchie

    Nitty Kutchie Registered Member

    Joined:
    Apr 10, 2015
    Posts:
    160
  15. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499

    Me too. A month ago I noticed MS will let you download and install windows 10 and others in VB. They say it will stop working after 90 days and so be sure to create a snapshot. Not sure why a snap shot would keep working after 90 days.

    Easter: on my machine VB still runs slower then my real OS but think it always will and I am running 16 gigs of RAM
     
  16. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  17. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    The best ransomware protection is to install SRP. Simple and forget it protection.
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
  19. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    All I've been using is common sense for emails and a script/ad blocker for the web browser, and that's been working fine for me. And with full system images as well as my personal and important data backed up offline, I've really no concerns.
     
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  21. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    They said Avast was one of the best anti ransomeware tools around so it must be true....lmao
     
  22. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I just looked at a utube video using the mac interceptor....
    McAfee Ransomware Interceptor (Pilot) ..... Here is another video with the Mac Interceptor ...
    Fight Back Against Ransomware
     
  23. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  24. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    And was it any good? I'm going to check it out later, but the end result isn't always clear in these kind of videos.
     
  25. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    BTW, NeuShield Data Sentinel looks quite interesting, does anybody know more about it? They claim to have a unique protection method, it's called "mirror shielding".

    https://www.neushield.com/products/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.