Trend Micro RansomBuster will stop Ransomware by protecting sensitive folders

Discussion in 'other anti-malware software' started by clubhouse1, Oct 27, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    Welcome @TrendMicro and thanks for the feedback on RansomBuster. I somewhat suspected it was a full anti-ransomware solution.

    We are all presently awaiting our resident ransomware testor, @cruelsister, to test RansomBuster and see how effective it is.
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    I was just reading a recent review of the full Trend product at PC Mag and noticed this:
    https://www.pcmag.com/article2/0,2817,2468796,00.asp

    And RansomBuster does the same:
    The folder name change is important and one to consider if using Win's Controlled Folders solution. Does it do likewise?

    As far as AV Lab tests of Trend against ransomware, MRG's last 360 test rated it the same as Eset with both receiving a 2% failure rate. I assume MRG didn't factor in the recovery procedure for these failures or these samples totally bypassed it?
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    Just saw this comment posted on Windows Club:
     
  4. TrendMicro

    TrendMicro Registered Member

    Joined:
    Oct 31, 2017
    Posts:
    3
    Location:
    California
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    Thanks for the info, so it's more advanced than I thought. I assume that it will even stop white-listed/trusted processes from encrypting files? And what flexibility does the platform provide, I still don't understand why it has to be this big, I mean it's not the full suite, right?
     
  6. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,653
    Location:
    Paris
    Brook- On the TM RansomBuster website it states: "RansomBuster provides protection against all forms of ransomware". Do you feel this may be a bit aggressively worded? It is, after all, a very diverse World...

    Second- As any antiransomware product should afford protection against file encryption anywhere on the system, do you guys feel the two folder protection max meets this requirement?

    Meghan

    (ITMan- As I know that you (as I) have a fondness for ps scriptors, just wanted to let you know that RansomBuster has further utility outside of the ransomware area. For giggles I tried a few Powershell Info Stealer scripts and was happy to see the drops prevented. The detection of CreateProcessWithCommandLine was a surprise. Again, nothing to do with ransomware protection, but interesting nonetheless).
     
  7. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    Now to those Mimikatz memory based attacks such as downloading Powershell and script to memory and executing it from there. Or again, Mimikatz memory based .Net execution of Powershell assemblies.
     
  8. TrendMicro

    TrendMicro Registered Member

    Joined:
    Oct 31, 2017
    Posts:
    3
    Location:
    California
    Hi Meghan,
    We feel that RansomBuster showcases our ability to protect a user's most valuable data. Trend Micro has been protecting data for almost thirty years. Although we are not as well known as some other consumer security brands, we have some very effective technology that we leverage from our enterprise business in our consumer products. We have been keeping a close eye on all forms of ransomware and have released this free tool to help stop the bad guys from holding innocent people's precious memories or data hostage. We hope you will put it through your own tests and let us know what you think!

    Best,
    Brook
     
  9. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,653
    Location:
    Paris
    B- Thank you for your response! Indeed TM has a long and respected track record in the Enterprise arena, and any shortcomings that may be found in RansomBuster should be understood not to reflect poorly on either TM's Corporate or Home products.

    I should have a video out this weekend (the Wilders TOS precludes a direct link to videos made by Riff-Raff).

    M
     
    Last edited: Nov 2, 2017
  10. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    It updated automatically upon bootup this morning.
    Can't tell which version I was running, and what it's up to now since there is no "about" in the program. (neither on the tray icon right click)
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    What about my question?

    Wow, nice find. :thumb:
     
  12. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    FYI - @cruelsister has done a test for RansomBuster and it is posted on her uTube web site. In summary, RB is not ready for "prime time" controlled folders protection. It does offer some ransomware protection but is deficient against the advanced stains. Also unless I missed something in the video, it does not provide default .exe lockdown against the protected folders by non-allowed processes?

    @cruelsister I just wanted to give you kudos on the quality of your videos. The text explanations along with the deliberate slowness of the tests greatly add clarification to what the tests are doing.
     
  13. plat1098

    plat1098 Guest

    Yes, I also have to say based on that video: it only allows up to two folders. If connection to its cloud is disrupted or broken, then you get considerably downgraded detections plus (big plus), other non-protected folders on the drive will naturally be encrypted--the CTBLocker being an example.
     
  14. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    No. When the Internet connection was disconnected, CTB-Locker was able to encrypt the protected My Documents folder. If this solution employed "default deny" to a protected folder, that should not have happened.
     
  15. plat1098

    plat1098 Guest

    Yes, even worse, the coup de grace @itman. As soon as I saw the other folders get encrypted regardless, I moved on--get something more comprehensive, for real. That video was an eye-opener.
     
  16. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I was also not impressed with RansomBuster, thanks for testing @ CS.
     
  17. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    Is Malwarebytes Anti-Ransomware beta any better?
     
  18. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    If you're looking for a free solution, you might want to check out RansomOff. There's a thread on it on Wilders. Also many Wilders folks seem fond of it.
     
  19. guest

    guest Guest

    TrendMicro Ransom Buster: Windows ransomware protection
    https://www.ghacks.net/2018/01/15/trendmicro-ransom-buster-windows-ransomware-protection/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.