RansomOff

Discussion in 'other anti-malware software' started by co22, Mar 28, 2017.

  1. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Probably sounds like a broken record but soon. We found a few issues during testing today (stupid UAC) that we want to clean up before releasing. But glad to hear things are running smooth on your end.
     
  2. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Will have to wait for the documentation that accompanies the new release to better understand what each setting does.
     
  3. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Funny you should mention that. Just updated the documentation a little bit ago. https://www.ransomoff.com/docs.php
     
  4. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Hi Dave - with HIPS-Lite, which options are on by default?

    I have them all enabled now, so I have forgotten which ones were on by default ... is it as per the top most snapshot in the documentation link above?
     
  5. imuade

    imuade Registered Member

    Joined:
    Aug 4, 2016
    Posts:
    751
    Location:
    Italy
    OK, thanks for the answer :)
     
  6. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Can't wait! :D
     
  7. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    great! Thanks for this instruction doc update. Nice list!
     
  8. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Always the best to everyone!

    For Windows 10 Users:mad:
    Hoping that fix this issue with Heilig RansomOff

    From: shmu26

    https://malwaretips.com/threads/ransomoff-kills-a-rat.76623/#post-684816
    Post: # 9

    FYI
    A week ago I went to the Heilig RansomOff website, downloaded the version that was being featured (RC) and it totally borked my system, because the drivers are not co-signed by Microsoft, so on Windows 10 you must disable secure boot, or your computer simply won't boot.
    I don't know what installation files you people are using, or what version of Windows you are installing it on, but be careful. The dev told me that he would mod the installation file to check the system for this potential problem, I don't know for sure if he did that quite yet. I am hoping he did...
    If, during installation, Windows gives you a warning about unsigned drivers, you must uninstall the program immediately, before you reboot, or else say hello to your system image restore CD. Actually, you could also opt to disable secure boot, if you so wish.

    Agree 100% and hoping that will fix this problem with Windows 10! The above!!!:(
    This has been going on for awhile.

    Please listen! So that one does not have to disable secure boot!!!!*puppy*

    Moose

     
  9. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    This would apply to anyone that had done a fresh install Win 10 1607+. For anyone that upgraded from Win 7 to Win 10, it does not. Microsoft code cert. driver enforcement only applies to fresh Win 10 1607+ OS installs.

    And ........... those Microsoft code driver certs. are very expensive.

    Only good for that boot session. So you will have to do so on every boot.
     
  10. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    The HIPS-Lite is a combination of some existing features from the previous version plus some new additions. So the things that were already being done will be enabled by default. But everything else will need to be turned on if desired.
     
  11. NiteRanger

    NiteRanger Registered Member

    Joined:
    Nov 15, 2016
    Posts:
    651
    Location:
    Far East
    Hi

    Can your program work offline or requires an internet connection? Thanks
     
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I might can answer that plainly I think.

    With Ransomoff on (2) machines i have, those are always offline. I test it more aggressively without "live" net connection.

    Still works just fine either way for me. Windows 10.
     
    Last edited: Oct 31, 2017
  13. NiteRanger

    NiteRanger Registered Member

    Joined:
    Nov 15, 2016
    Posts:
    651
    Location:
    Far East
    Thanks.

    From what I know RO is a sig-less software NOT using AI/ML. I supposed it uses some kind of behavior-based or heuristics to detect ransomware.

    As such it's more of an offline software for protection. Of course online is more for updating the software in areas like compatibility issues, vulnerabilities, bug fixes and new features.

    If this is the case then having RO connecting to its cloud and using AI/ML would definitely boost its detection and capability, no?
     
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    OK I see. BTW, I just saw the new screenshots in the updated manual, it's looking good! A small request, perhaps you can make the images open in a new tab.
     
  15. jimb949

    jimb949 Registered Member

    Joined:
    Jul 6, 2017
    Posts:
    129
    Location:
    LA
    The download for RO should be taken down from the website if it's going to destroy someone's windows 10 computer. Are at least have a warning on the website about this problem.
     
  16. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
  17. jimb949

    jimb949 Registered Member

    Joined:
    Jul 6, 2017
    Posts:
    129
    Location:
    LA
    Thanks, My bad!
     
  18. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks for everyone's patience. We just uploaded 5.2017.306.5218 for wide release.

    Obviously the big changes are the UI and the HIPS-Lite features. So enjoy and if you find any issues or have problems please let me know.
     
  19. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    @HeiDef et al,
    anything to consider for Sandboxie users?
    anything to consider for Shadow Defender users?
    Thanks
     
  20. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    RO is signature-less. Ransomware is different than other types of malware. You can characterize ransomware fairly well and build detection methods around that. Malware in general is a bit more nebulous (bad is sometimes in the eye of the beholder) so it makes sense to use ML techniques. For RO though, if something is detected on one system then every other system will also detect it without needing updates or sharing data through the cloud because again it's signature-less. The same heuristics apply.
     
  21. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Well considering those wipe changes there's probably not much utility in using RansomOff in conjunction with SB or SD. But for compatibility purposes, I'm not sure what the issues may be between them.
     
  22. jimb949

    jimb949 Registered Member

    Joined:
    Jul 6, 2017
    Posts:
    129
    Location:
    LA
    With the new version it takes 3 minutes for the RO icon to load in my taskbar.
     
  23. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Didn't you have load time issues with the previous version as well? Is this on your newer Win 10 machine or your Win 7?
     
  24. Houley456

    Houley456 Registered Member

    Joined:
    Feb 9, 2007
    Posts:
    198
    No issues so far....using EAM, HMP.A...
     
  25. jimb949

    jimb949 Registered Member

    Joined:
    Jul 6, 2017
    Posts:
    129
    Location:
    LA
    I did have issues before. I installed this on my Windows 7 computer.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.