New ransomware vaccine kills programs wiping Windows shadow volumes

Discussion in 'malware problems & news' started by mood, Oct 5, 2020.

  1. mood

    mood Updates Team

    Joined:
    Oct 27, 2012
    Posts:
    38,113
    New ransomware vaccine kills programs wiping Windows shadow volumes
    October 4, 2020
    https://www.bleepingcomputer.com/ne...kills-programs-wiping-windows-shadow-volumes/
    Raccine
     
  2. mood

    mood Updates Team

    Joined:
    Oct 27, 2012
    Posts:
    38,113
    ShadowGuard
    Website + Download
    Download (Majorgeeks)
    New App: ShadowGuard
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    9,342
    Location:
    U.S.A. (South)
    d7xtech :thumb:

    Now why hasn't someone done this before now?

    D/L & Installed 8.1- Best part shouldn't interfere with my regular registry backup apps RegBak-Tweaking.com Registry Backup
     
  4. mood

    mood Updates Team

    Joined:
    Oct 27, 2012
    Posts:
    38,113
    Raccine got some additions/improvements in the meantime (simulation mode, batch installer, logging to a file, etc.)
    Excerpt of recent changelogs:
     
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    9,342
    Location:
    U.S.A. (South)
    Interesting details-improvements etc.

    Long well known badware's first cruddy adventure is getting to the O/S native Shadow Copy ensuring no easy peasy quick fix back to normal from inbuilt window system.
     
  6. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    726
    Location:
    U.S. Citizen
    Hey there,

    Anybody know if ShadowGuard will still prevent you from Raccine? Umm!
     
  7. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,963
    Location:
    Poland - Cracow
    o_O Both apps offers similar protection but ShadowGuard seams to cover more.
    BTW - SG is developed by the same person who developed CryptoPrevent
    https://www.d7xtech.com/cryptoprevent-shadowexplorer-and-vssadmin/

    Two screenshots of ShadowGuard
    201023120315_1.jpg
    201023120818_2.jpg
     
    Last edited: Oct 23, 2020
  8. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    726
    Location:
    U.S. Citizen
    @ichito,

    Thank you ,sharing, appreciated......

    Moose
     
  9. mood

    mood Updates Team

    Joined:
    Oct 27, 2012
    Posts:
    38,113
    Raccine v1.4 Released (November 14, 2020)
    Website
    Download
     
  10. mood

    mood Updates Team

    Joined:
    Oct 27, 2012
    Posts:
    38,113
    Raccine 1.4.2 Released (March 23, 2020)
    Website
    Download
     
  11. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    9,342
    Location:
    U.S.A. (South)
    All of which screams to users to already utilize daily backup images, then the intruders can fudge all they want in a wasted effort.

    Still those apps (Raccine & Shadow Guard) have their place to some degree for unaware users.
     
  12. mood

    mood Updates Team

    Joined:
    Oct 27, 2012
    Posts:
    38,113
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.