Introducing the Malwarebytes Anti-Ransomware Beta

Brds7t7,
I only checked one test image file. I was able to open it after the ransomware was quarantined. Sometimes, a "non ransom note" file would be created in the same folder as the test image. I could not open or copy that file. It was in use by another program. I don't know if this was the start of the encryption process or not.

I repeated the test 5 or 6 times (deleting the ransom notes between tests). Twice, MBARW did not ask for a reboot to clear the malware. Perhaps MBARW caught the ransomware early on during those two tests.

The number of ransom notes to cleanup varied from a low of about 800 to a high of about 1200. I guess that this means the malware did something worthy of being quarantined at different times.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Since the MWARW code is building on CryptoMonitor, I would expect a bit more product maturity. Even in the BETA release.


I don't suggest CryptoPrevent for the average user. You have to know when/how to turn it off. If the Filter Module is turned on and the Windows On-Screen keyboard is started - the computer goes into an UAC loop. The user will have to hold the power button in to shut down the computer.

What? Tell us more.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
W7Pro/64
Painter,
It is unclear to me which topic you want more info on: My expectations for MBARW or CryptoPrevent's filter module and the On-Screen keyboard? See this post.

Or were you wanting more info on when/how to turn off certain CryptoPrevent features?
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
I think once they've ironed out the early bugs and incorporated this into the main program, MBAM will offer some fantastic protection against these Cryptoviruses. Malwarebytes seems to have a much larger user base than Cryptoprevent. I'd happily use them both together. I already run the paid MBAM along with Cryptoprevent, MBAE and Avast free (with the extra bloat removed). Might be overkill but I like to have as many layers of protection as I can.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate, Win 8.1 Pro, Linux Mint 19 Cinnamon (All 64-Bit)
CPU
Intel i5 4690K
Motherboard
Gigabyte Z97X-UD3H
Memory
Corsair Vengeance LP 32GB DDR3
Graphics Card(s)
MSI GTX 1060 GAMING X 6GB
Sound Card
Onboard
Hard Drives
Samsung 850 EVO 250GB SSD (x2)
Samsung 860 EVO 1TB SSD (x2)
Crucial MX300 525GB SSD
WD Blue 2TB 5400rpm Intellipark Disabled (x2)
PSU
Corsair HX750i
Case
Phanteks Enthoo Pro
Cooling
CM Hyper 212 EVO on CPU, Noctua Redux NF-P14S 1500rpm (x6)
Keyboard
Corsair K70 RGB LUX
Mouse
Corsair Sabre RGB
Antivirus
Avast Free, MalwareBytes, SAS & CryptoPrevent
Browser
Chrome
Other Info
StarTech PEXESAT322I 2 Port PCI-E SATA Card
ASUS PCE-AC56 Dual-band AC1300 Wireless Card
Akasa FC.Six Manual Fan Controller
And a Partridge in a Pear Tree!
Layers are a good thing, but each security app brings with it the risk of infection. We hope that the servers providing the updates for these apps have not been compromised. The more apps we use, the more apps we update, the more risks we take...

There is some benefit to having security layers come from different companies. It would be hard for normal* bad guys to compromise multiple companies at once. Hopefully, these security companies can withstand pressure from governments to provide them a backdoor. The more security companies that we use, the more we risk installing a backdoor.

*state actors are not normal.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Painter,
It is unclear to me which topic you want more info on: My expectations for MBARW or CryptoPrevent's filter module and the On-Screen keyboard? See this post.

Or were you wanting more info on when/how to turn off certain CryptoPrevent features?

CryptoPrevent. There are really no settings for the average user to contemplate or change - the default settings are recommended. I have used some of the other settings myself, but there are warnings associated with them. The only issue I have had while going with more protection was when doing backups - had to turn the protection off, then turn it back on after the backups finished.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
W7Pro/64
Just downloaded it earlier and felt a bit disappointed. It detected Logitech's Gaming Software and Chrome as ransomware. I'll just probably hold off until it's out of Beta.

Edit: For some reason, it cannot remove Chrome in the Quarantine. It says "Can't restore an item marked for deletion on reboot".

Edit 2: Yep. It deleted Chrome.exe after I rebooted it. Though I just copied the executable to another folder before rebooting and placed it back to the original location.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built
OS
Windows 7 Professional 64-bit (6.1, Build 7601)
CPU
Intel Pentium G3258 @ 3.80 GHz (OC'd)
Motherboard
Gigabyte Z97-HD3
Memory
Team Elite 4 GB DDR3 1600 MHz
Graphics Card(s)
Palit GTX 1060 6 GB Super JetStream
Monitor(s) Displays
HP x20 LED Series Wide LCD Monitor
Screen Resolution
1600x900 pixels
Hard Drives
Western Digital Caviar Blue WD10EZRZ 1TB @ 7200 RPM,
Western Digital 3200BEV External HDD 298.09 GB, WD Elements WDBUZG0010BBK-05 External HDD 1TB
PSU
Seasonic G-550 550W 80+ Gold
Keyboard
Corsair K70 Rapidfire RGB
Mouse
Logitech G300S and G502
Internet Speed
2.00 Mbps
Antivirus
MSE, MBAM, MBAE
Browser
IE, Google Chrome, FF, Safari.
Other Info
Old PC:
HP Pavilion P6640D, Windows 7 Ultimate 32-bit (6.1, Build 7601), Intel Pentium Dual Core CPU E6700 @ 3.20 GHz, Foxconn 2A8C, Kingmax 2 GB DDR3 1066 MHz, Palit NVIDIA GeForce GT 610 2048 MB, Western Digital WD Blue WD5000AAKX 500 GB @ 7200 RPM, Seagate Barracuda ST3320418AS 320 GB @ 7200 RPM (former drive), Bestec ATX-250-12Z 250 Watts
Weird.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate, Win 8.1 Pro, Linux Mint 19 Cinnamon (All 64-Bit)
CPU
Intel i5 4690K
Motherboard
Gigabyte Z97X-UD3H
Memory
Corsair Vengeance LP 32GB DDR3
Graphics Card(s)
MSI GTX 1060 GAMING X 6GB
Sound Card
Onboard
Hard Drives
Samsung 850 EVO 250GB SSD (x2)
Samsung 860 EVO 1TB SSD (x2)
Crucial MX300 525GB SSD
WD Blue 2TB 5400rpm Intellipark Disabled (x2)
PSU
Corsair HX750i
Case
Phanteks Enthoo Pro
Cooling
CM Hyper 212 EVO on CPU, Noctua Redux NF-P14S 1500rpm (x6)
Keyboard
Corsair K70 RGB LUX
Mouse
Corsair Sabre RGB
Antivirus
Avast Free, MalwareBytes, SAS & CryptoPrevent
Browser
Chrome
Other Info
StarTech PEXESAT322I 2 Port PCI-E SATA Card
ASUS PCE-AC56 Dual-band AC1300 Wireless Card
Akasa FC.Six Manual Fan Controller
And a Partridge in a Pear Tree!
Back
Top