RansomOff

Discussion in 'other anti-malware software' started by co22, Mar 28, 2017.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Try SD without registry exclusions. I've never used them
     
  2. korben

    korben Registered Member

    Joined:
    Nov 5, 2009
    Posts:
    917
    Do not take my words for dissatisfaction - for a product that you received zero $ from me - it rocks!
    Still, I cannot resign from using ShadowDefender - unless there is another freeware product to substitute it for.

    On a side note - now with CybereasonRansomFree - no change in system behaviour - still errors resulting in forced reboots or switch-off grrr

    P.s.
    Never have I used the Reg Exclusions in SD - just a thought that originated from the errors I have been getting...
     
  3. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Win 7 home prem 64bit ransomoff v1.0.0.0 has an error an will quits after working in older versions.
    "timeout waiting for ransomoff to load agent cannot continue."

    "HDRansomOffSvc.exe" is still running in processhacker though but interface dies.
     
  4. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks. We've seen this happen on slower systems. In the next release, we'll increase the wait and add some more checks before throwing the error.
     
  5. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    ok good to know but i am on a quad core 6600 and a ssd so shouldnt be that slow.
    Maybe there is too much stuff in startup then?
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Quick question. (doing some catch-up) Fantastic advances made and it's GUI-Menu is a dream. Cool stuff.

    Windows 10 1803 am running only Windows Defender full-on w/o (Controlled Folder Access)-Don't know yet how it might clash together. Will try that later.

    Anyway i am trying to remove a Folder from Folder Protection services box i added for testing. I keep getting no matter what is tried this
    [there was an error removing the selected folder]

    Got it! Duh, a small matter of tapping to bring up the checkmark before removing.

    On an aside, my compliments on the reusable file to kick in additional type various Folder Protections, as well as sharpening other features as finely tuned as a fresh razor.

    Probably just my absence from recent developments/changes Ransom0ff has done with the new improvements. It's likely not doable given what's involved with coding such a feature-rich Anti-Ransomware as this is become, BUT, just to throw it out there anyway, would it be of any chance to consider some method that automatically shift the Folder Protection modes from DENY-DECEIVE-READONLY-HIDE selections instead of manually removing then inserting anew into the separate preferences that apply to user's preferred Folder choice. One can assume it's the nature of the way Windows is coded which prevents that possibility? Still not a suggestion at all but question only. As is this app is Superb!

    This latest release is totally awesome. :thumb:
     
    Last edited: Apr 8, 2018
  7. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    That's not slow for sure. The RO service is definitely getting caught up with something that's taking awhile on load. It may be just from the competition of all the other things loading but I wouldn't expect that with a SSD. Does it happen every time you boot or just occasionally?
     
  8. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks EASTER. This can actually be done quite easily with the RO Server which we are actually planning on releasing for wide use shortly. But adding that to the UI is a good suggestion and shouldn't be too difficult.
     
  9. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Every boot up.
     
  10. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    pm for you HeiDef
     
  11. sdrubble

    sdrubble Registered Member

    Joined:
    Oct 8, 2016
    Posts:
    4
    Location:
    Belo Horizonte, Brazil
    @HeiDef

    Hello - 1st posting here !!! :)

    I'm having exactly the same issue as @trott3r - running on an AMD A6-3420M laptop from 2012, which is extremely slow nowadays. Win 7 SP1, fairly outdated, plus Avast anti-virus. The AV gets updated on every reboot (usually every 10-12 days), and is then immediately manually disabled thru a service stop.

    The timeout msg appears a looong time after I manually activate HWiNFO64.exe v4.1.1.0 (this version is from 2013, and I usually don't update anything on this potato when it's already working). Would try an updated version though, if you require it for testing - HWINFO is a 'portable' install here anyway, so that multiple versions can co-exist in the HD.

    HWINFO will only show its windows AFTER RO has failed. Could also be something else as well, as on startup there's a bunch of stuff auto-launching, plus another manual bunch including .BAT files that stop / start services, disable firewall rules and kill processes.

    In addition to what trott3r has reported, I've also noticed that HDROAgent.exe remains running. Aaand I'm also running the long-deceased SystemExplorer.exe v7.0.0.5356 (from 2015), though it doesn't look relevant to RO's issues.

    I also noticed that RO requires outbound access to 3 different CDN providers - I have allowed these, but this seems irrelevant to the timeout issue.

    I found RO to be a very interesting piece of software - just started trying it as a (seemingly much better) replacement for the (former) free version of CryptoPrevent which has recently been killed by its dev. :mad:

    I'll happily try to help debugging this (despite the loooong and painful reboots it will probably require ...). It's for a noble and worthy cause, hehe.

    Cheers :D
     
  12. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    sdrubble: glad you posted, hopefully you can shine some light on the situation :)
     
  13. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Thanks @sdrubble and @trott3r.

    We think we identified the timeout issue as a problem with our SQLite database configuration. RO uses the database as a communication path between the service and agent so when the database becomes corrupted or a serious error is thrown, then messages get missed. Booting is the trickiest time for RO, so any mis-step by the database can cause issues. So there are a few problems here that we are working to resolve mainly with better error handling and recovery. We should have an update out by this week though. I'll send you both PM's in a few days with a link for a nightly build so you can give it a pre-test to see if our fixes have worked.
     
  14. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    Hi Dave

    Hope you are well? Thanks for the heads up. Looking forward to it.

    Regrds, Baldrick
     
  15. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Hey @sdrubble Not sure what the issue is but it's not letting me send you a PM. Try to start a conversation with me so I can send you a test build to see if it solves your problem.
     
  16. sdrubble

    sdrubble Registered Member

    Joined:
    Oct 8, 2016
    Posts:
    4
    Location:
    Belo Horizonte, Brazil
    I guess my low post count doesn't allow me to send PM's yet (couldn't find a 'send PM' label in my profile options). I DO have an 'Inbox', but it's empty for the moment.:(

    Maybe you, as an established developer, could request an exemption to the PM restrictions from the forum admins ... :mad:
     
  17. guest

    guest Guest

    I'm not sure but i assume that at least 5 posts are needed until you will be able to send a PM.
     
  18. sdrubble

    sdrubble Registered Member

    Joined:
    Oct 8, 2016
    Posts:
    4
    Location:
    Belo Horizonte, Brazil
    Would that impede me to REPLY to a PM I've received ?
     
  19. sdrubble

    sdrubble Registered Member

    Joined:
    Oct 8, 2016
    Posts:
    4
    Location:
    Belo Horizonte, Brazil
    @HeiDef -

    I've just read this in another thread:
    View attachment 259819

    Might it be the case that you've ticked / not ticked the right box(es) when sending the PM to me ?
     
  20. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    the latest build now works after it initially failing.

    (Restarts itself)
     
  21. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Been having issues with RO 5.2018.81.6662 lately, task bar icon disappears (crashes?) when I try to open it (double-click or right-click). Could possibly be due to a failed automatic update to version 5.2018.136.7699 (?).

    Tried installing over the top, 'service still running', disabled the service, restarted, uninstalled with CP, installed latest, same issue.

    Used Revo Uninstaller, same result, though it didn't seem to remove everything, so I have now manually removed these, though not some leftover registry entries ...

    Will try a clean install again later.

    Edit: Nope, no luck. Didn't have this problem until recently (machine 1 in sig).
     
    Last edited: Jun 5, 2018
  22. HeiDef

    HeiDef Developer

    Joined:
    Apr 6, 2017
    Posts:
    388
    Location:
    Arlington, VA
    Hey Paul.

    Are any components running still when the icon disappears? You mention you tried to re-install but got the service is running error so I'm assuming that the service is still running. Just FYI, if no user interface instances are running you can kill the service via the task manager. Is anything showing in the Windows Applications event logs indicating a crash? Does it happen randomly or all the time? And does it disappear the first time you click or are you able to open the interface at all?
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    The service is still running when the icon disappears. If I remember correctly I couldn't stop the service, but I was able to disable it, so it was not running on restart.

    After rebooting, it seems to happen every time, the icon disappears (after a short while) on first click - can't open the interface.
    IIRC I was able to open it once, after RO had run overnight.

    I did not check Windows Application event logs ... if I try again I will have a look.

    Edit: It didn't happen till recently, that is why I wondered if it had something to do with trying to update to v136.7699 ...
     
  24. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Still no luck with RO, clean installing current (or previous) version, simple mode. Right-click or double click of task bar icon > icon just disappears after a short delay. Can't open RO. Service still running. Something is messed up..

    No dump, no crash in Windows Applications event logs. After last install:

    Info: Heilig Defense RansomOff starting.
    Version: 5.2018.136.7699

    Info: A new user has logged on with session id (1). Starting Heilig Defense RansomOff user agent.

    Info: Heilig Defense RansomOff is starting the update process...

    Error: Current Heilig Defense RansomOff version is already the latest. There is nothing to update.

    Info: License is 'HOME LICENSE (TYPE:FREE, EXPIRES:NO, STATUS:VALID)'

    Uninstalled again. Was using RO primarily to protect backup USB folders. Looks like I'll have to go back to Secure Folders or Pumpernickel :doubt:.

    Edit: Dave, this is not my previous cranky machine, but a new Dell XPS 13. EAM, HMPA, but I've recently run it successfully alongside the same software.
     
    Last edited: Jun 16, 2018
  25. pdl1985

    pdl1985 Registered Member

    Joined:
    Aug 3, 2018
    Posts:
    1
    Location:
    argentina
    hi. its secure your software? i currently user of trend micro ransom buster
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.