RansomOff

Discussion in 'other anti-malware software' started by co22, Mar 28, 2017.

  1. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    :thumb:
     
  2. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Dan

    Just seen the posts about AppPacApp and so can see that you have been busy. However, am just wondering if there is any news in to the RansonOff RC? The last beta that I installed on one of my systems has been performing flawlessly (at least for me) and am thinking that you must be close to being where you want to be before formally release?

    Anyway, all good things come to those who wait...so patient we will have to be...in the hope of something new to test soon...;)

    Keep well, and don't work too hard, Maestro.

    Regards, Baldrick
     
  3. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks! We got a bit behind with RO but should be releasing an update shortly. Glad to hear it's working well for you still. Externally there aren't many new things but we did re-do a big chunk internally to clean up the code and also hopefully reduce FPs. We identified an issue that was introduced two versions or so ago that seemed to cause a bunch of unnecessary FPs so that's hopefully fixed. I'm sure I sound like a broken record but the next release really should be soon.
     
  4. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Dave

    Good to hear from you. Thanks for taking the trouble to respond...much appreciated
    Sounds like what with the chunk of code rewrite we still have some more checking out to do for you...well, bring it on (when you are ready that is, of course :)).

    We are ready and waiting.

    Regards, Baldrick
     
    Last edited: Mar 19, 2018
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    RansomOff Change Log :thumb:
    5.2018.81.6662 - 22 Mar 2018

    • Added new HIPS setting to notify on protected folder write.
    • Removed ransomware protection dependency for folder protections.
    • Improved RansomOff Server support.
    • Other bug fixes and UI tweaks.
     
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Looking forward to testing
     
  7. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Already on it....and looking GOOOOOOOOOOOOOOOOOOOOOD! :):thumb:

    Baldrick
     
  8. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Good to hear! Please let me know if you run into any issues.
     
  9. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    This is IMHO and for all good purposes a cutting edge state of the art sort which is a rarity but absolutely priority relevant given recent published reports for just one example, Atlanta's City systems which as of this very day today front n center news on their/those series systems still in a state of been (ransomware) neutralized. (HeiDef, you guys should contact them-negotiate).

    I tested it while yet in infancy and throughout many releases and it wasn't boring, I can tell you that.
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I agree, it is looking real good.
     
  11. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Do you have a POC? That'd be a great win.

    It is amazing though that major organizations are still getting nailed with ransomware. It just shows it's a threat that's not going away.
     
  12. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Got reports of a few hick ups but I think they were more system related vice RO. Hopefully it stays that way.
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Going to test some of the nasties I have tomorrow
     
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I could have sworn that I already posted this a couple of days ago: It's the SamSam ransomware that gets installed via RDP. I suppose a tool like RansomOff would be able to stop it, here some more info:

    https://www.secureworks.com/research/samsam-ransomware-campaigns
     
  15. korben

    korben Registered Member

    Joined:
    Nov 5, 2009
    Posts:
    917
    Just now installed instead of CybereasonRansomFree having noticed it is no more in beta stage.

    Any tips on how to set it up the proper way or simply install and forget about it?

    I am curious about HIPS mainly.
     
  16. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Just turn on all the protections and be prepared to allow alerts.
     
  17. korben

    korben Registered Member

    Joined:
    Nov 5, 2009
    Posts:
    917
    All of them literally?

    edit//
    just noticed I cannot run HWMonitor 1.34 unless R-Off is not operating causing freezes

    How to go about this issue?
     
    Last edited: Mar 27, 2018
  18. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    It's really user dependent. Turning on all the HIPS like @Peter2150 said will generate a lot of alerts but they can be tuned to reduce some of the noise. If you are running other security software, some of the HIPS may be redundant so it's something you'll need to figure out based on your setup. RO is packed with features which allows for lots of tuning but it can be just installed and run with the default configuration without much intervention. We've been meaning to update the docs and add more info so it's easier to figure out what to do.

    As for the HWMonitor issue, not quite sure what's going on there. If you disable ransomware protection does HWMonitor run? Is the system freezing or just HWMonitor? Did you try to add HWMonitor to the exemptions list? That generally clears up problems although we will look into it to try and figure out the underlying cause.
     
  19. korben

    korben Registered Member

    Joined:
    Nov 5, 2009
    Posts:
    917
    Only HWMonitor freezes.
    When I turn off R-Off- it becomes active and can be operated on.

    Is it possible to make exceptions?

    One a side note - HeiDef, it is a job well done, for real!


    edit//
    found the exceptions - NICE!
     
    Last edited: Mar 28, 2018
  20. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks. Did adding the exception work for HWMonitor?
     
  21. korben

    korben Registered Member

    Joined:
    Nov 5, 2009
    Posts:
    917
    Yes, that did the trick.
     
  22. korben

    korben Registered Member

    Joined:
    Nov 5, 2009
    Posts:
    917
    Despite listing exclusions / adding exes / folders to the exemptions list, I can tell you that R-Off and ShadowDefender 1.4.0.648 are in conflict.

    Windows was unable to restart and or be turned off without generating errors - chkdsk was deployed by system and R-Off exe generated errors too regularly. After ca 20 failures I had to uninstall R-Off, alas.

    My guess? Registry Exclusions List in SD has to be properly configured but I don't know how to achieve it.
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Dave - RO 5.2018.81.6662 now purring away on machine 1 below ;), advanced mode, default settings, external USB backup folders protected.
     
    Last edited: Apr 2, 2018
  24. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    We never tested extensively with RO and SD but given how they both work, it's not surprising there is conflict. Thanks for the feedback though. It's something we can try to look into.
     
  25. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Great to hear.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.