RansomOff

Discussion in 'other anti-malware software' started by co22, Mar 28, 2017.

  1. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Well we just tested Xdata with the latest and it worked. Not sure about earlier versions but we are always tweaking the heuristics so it's possible that Evjl's Rain's test conditions just exploited a gap as you mentioned.

    Can you pass the hashes of the FilecoverFV and ShellLocker you used? We would like to get those in our test cycle as well.
     
  2. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks for the suggestions but the problem is how do we alert until we know for sure that the process is actually ransomware? In the case of Hades, the main executable sounds to be just an orchestrator of sorts whose main focus is launching the actual ransomware payloads. But if it is not performing any ransomware behaviors, it's can't be detected as such.

    However, RansomOff's cleanup process is supposed to track a ransomware process back to the source so it should be terminating the Hades process and then deleting the file. Again, please pass the hash on that so we can see where the process cleanup is failing.
     
  3. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Absolutely, We have a couple more explainer videos in the queue but just haven't gotten to them yet. Once we work out some of these latest issues we should be able to finish up a video or two.
     
  4. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    :geek:RansomOff Beta Revisited by cruelsister1 on posted on YouTube!

    Only miss one! Your thoughts/opinions?
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    with ransomware one is too many
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Thanks. Will want to have a see about the new features and of course early feedback.
     
  7. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    It was a miss due to a programming bug that only appears to impact Win7. As we posted, RansomOff easily stops XData on Win10 so it is not an issue with our underlying detection methods but a simple mistake of not initializing a value properly. But as Peter2150 says, it is one too many so we will make sure to do better next time.
     
  8. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Sure, but it is still beta :). And your effort and engagement still make me want to back RO.

    @Peter2150, I know your views on prevention vs. detection, but check out it's folder protection. Pretty elegant, compared to 'competition'. May be worth considering spinning that off as a small standalone for those who only want that.

    I haven't played with Lockdown yet.
     
  9. cloggy49

    cloggy49 Registered Member

    Joined:
    Oct 6, 2015
    Posts:
    93
    Location:
    The Netherlands
    Run into another issue (but it might be my ignorance). After I added a folder to Folder Protections and want to add a process to be exempted, I get the following error window:

    upload_2017-5-21_12-45-24.png

    I can click on OK and then select the designated program to be added to the Exempted Processes. Why this window?

    Note that I get the same error window when I want to add a program to the Exempted Software (Add -> Browse and then I get that Window)..
     
  10. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Greetings/Salutations!

    On updating of RansomOff's do you install over the existing software? And/or do you uninstall and then reinstall?

    Kind Regards,

    Moose
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I understand the concept. I've been using a program AJCsoft's Active Back for years, and they way it stores the files so far ransware has proven untinterested. But I will look at it.
     
  12. guest

    guest Guest

    With earlier betas the previous version had to be uninstalled, but now it is possible to install it over-the-top.
     
  13. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    @mood

    Thank you! Appreicated!:)
     
  14. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    That's an interesting one. Thanks for the heads up.
     
  15. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks @paulderdash
     
  16. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Salutations/Greetings!

    Just wondering, if you have an uninstall tool/ removal tool just in case there is a problem?
    Or the best to uninstall? If needed?

    Kind Regards,

    Moose
     
  17. mWave

    mWave Guest

    If no problems have been yet experienced with uninstallation by users then how would they approach making a removal tool in case? Since it'd be doing the same as the uninstaller...
     
  18. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    This product is looking better every day....
     
  19. cloggy49

    cloggy49 Registered Member

    Joined:
    Oct 6, 2015
    Posts:
    93
    Location:
    The Netherlands
    Cosmetic issue? When I select the option 'Only allow admin group user to close' and trying to exit RO, I get the following message:

    upload_2017-5-21_16-34-23.png

    Note that I'm an administrator.

    upload_2017-5-21_16-37-10.png
     
  20. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I been waiting for someone else to post to that box issue.

    Also get the exact same one and while cannot add directly to the Browse Desktop because of it, you can or should be able to go the long route drilling down to Desktop from My Computer/ThisPC etc to get around it.

    Windows 10 x64 (no AU no CU)
     
  21. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks. What's your UAC setting?
     
  22. Circuit

    Circuit Registered Member

    Joined:
    Oct 7, 2014
    Posts:
    939
    Location:
    Land o fruits and nuts, and more crime.
    Backup, only way to make sure computer was the same as it was.
    Had to take it off, the only thorough way.
    No uninstaller can remove all traces.
     
    Last edited: May 21, 2017
  23. cloggy49

    cloggy49 Registered Member

    Joined:
    Oct 6, 2015
    Posts:
    93
    Location:
    The Netherlands
    My UAC setting is: Never Notify
     
  24. cloggy49

    cloggy49 Registered Member

    Joined:
    Oct 6, 2015
    Posts:
    93
    Location:
    The Netherlands
    What could be wrong with this one:

    upload_2017-5-21_20-14-17.png

    upload_2017-5-21_20-18-11.png

    This the first time I'm getting these Alerts..and a few times in a few minutes. I've now set it Allow - Add Permanent Exemption..
     

    Attached Files:

  25. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    False alerts sometimes happen with security software. It mistakes a legitimate process as malware behavior.

    Malware can run like a legitimate process so its not always easy to tell them apart. You may want to set a temporary block to investigate and allow it to run later.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.