作者swattw (Swat-未来模式)
看板AntiVirus
标题[情报] BitDefender Anti-Ransome
时间Mon Apr 11 09:18:45 2016
软体名称:BitDefender Anti-Ransome
版本号:1.0.11.26
官方网站:
https://labs.bitdefender.com/2016/03/combination-crypto-ransomware-vaccine-released/
https://goo.gl/XWQvRz
官方下载连结:
http://download.bitdefender.com/am/cw/BDAntiRansomwareSetup.exe
官方说明:
Combination Crypto-Ransomware Vaccine Released
Bitdefender anti-malware researchers have released a new vaccine tool which
can protect against known and possible future versions of the CTB-Locker,
Locky and TeslaCrypt crypto ransomware families by exploiting flaws in their
spreading methods.
“The new tool is an outgrowth of the Cryptowall vaccine program, in a way.”
Chief Security Strategist Catalin Cosoi explained. “We had been looking at
ways to prevent this ransomware from encrypting files even on computers that
were not protected by Bitdefender antivirus and we realized we could extend
the idea.”
The new tool is available for download on the .
A conducted by Bitdefender in November 2015 on 3,009 Internet users from the
US, France, Germany, Denmark, the UK and Romania offers a victim’s
perspective on data loss through crypto-ransomware:
50% of users can’t accurately identify ransomware as a type of threat that
prevents or limits access to computer data.
Half of victims are willing to pay up to $500 to recover encrypted data.
Personal documents rank first among user priorities.
UK consumers would pay most to retrieve files
US users are the main target for ransomware.
效果:阻挡除了常见的Crypt系列以外,还有Ransomware系列勒索软体。
教学:
1. 下载下来以後安装
2. 安装完毕以後长这样
http://i.imgur.com/T0worxM.png
3. 在设定里面三个都打勾
分别是
开机自动运行,自动运行最小化到系统列,按XX会最小化到系统列
http://i.imgur.com/d9gWob3.png
--
CPU: Intel core i7-4790K @4.5Ghz 1.25V →
Swat-PC002:
http://i.imgur.com/sHaQPB2
RAM: Kingston hyperX Fury DDR3- OC2133 8GB*2
MB : MSI Z97S-SLI PLUS
VGA: NVIDIA GTX980
SSD: Curcial MX200 250G
HDD : Seagate 2TB 7200rpm
APU: Asus Xonar DX
PSU: Antec EDGE 650W
CASE: Corsair Graphite 230T
OS : Windows 10 Pro 64Bit
键盘 Corsiar K70 RGB
滑鼠: Razer DA Chroma
耳机 Logitech G633
鼠垫 Logitech G940
摇杆: Nvidia Shield
--
※ 发信站: 批踢踢实业坊(ptt.cc), 来自: 114.35.164.154
※ 文章网址: https://webptt.com/cn.aspx?n=bbs/AntiVirus/M.1460337529.A.73B.html
1F:→ abram: 谢谢分享 有了这个就比较放心点了 04/11 11:19
2F:→ noname123: 跟MBAE会相冲吗? 04/11 14:02
3F:推 tennyleaz: 想知道跟KIS会冲吗? 04/11 14:17
4F:推 qxxrbull: 我个人用过 确定跟comodo HIPS不会冲突 04/11 14:46
5F:→ swattw: 我自己跟防毒软体不冲突 04/11 14:49
6F:推 Kreen: 感谢分享~ 04/11 15:32
7F:推 silentazure: 没冲突+1 谢谢分享 04/11 15:53
8F:推 howard098112: 推 感谢分享 04/11 20:39
9F:→ mayuyu: cruelsister1有做测试 BitDefender Anti-Ransome 04/11 22:41
10F:→ mayuyu: 无法挡住TeslaCrypt v3(已经出现几个月,不是新变种 04/11 22:41
11F:→ mayuyu: 而且BitDefender Anti-Ransome宣称可以对抗这种病毒) 04/11 22:41
12F:→ mayuyu: 所以这个软体只能防护有限的勒索病毒种类 04/11 22:41
13F:→ mayuyu: 甚至对它专门对付的种类的防护都不完全 04/11 22:42
14F:→ mayuyu: 所以cruelsister1建议选择其他软体 04/11 22:42
16F:推 x52013: 那麽请问一下楼上有更好的推荐吗? 04/11 23:08
17F:推 mayuyu: cruelsister1的影片有测其他软体 04/12 01:36
18F:→ mayuyu: 据他测试的结果WinAntiRansom防勒索目前还没有失手过 04/12 01:36
19F:→ mayuyu: 例如像Petya这种MBR加密的病毒 当时HitmanPro.Alert 04/12 01:36
20F:→ mayuyu: 和MalwareBytes Anti-Ransomware都无法阻挡Petya 04/12 01:36
22F:→ mayuyu: 而WinAntiRansom有成功挡住 他还有测ESET的HIPS很强 04/12 01:37
23F:→ mayuyu: 可是我觉得勒索软体日新月异 方法推陈出新 04/12 01:37
24F:→ mayuyu: 迟早有人又找出新漏洞或新方法 挡得了一时挡不了永久 04/12 01:37
25F:→ mayuyu: 所以可能还是虚拟机或沙盒、影子系统比较保险 04/12 01:37
26F:→ mayuyu: 像是Shadow Defender的测试 04/12 01:38
28F:→ mayuyu: 不管怎麽乱搞系统 重开机就恢复原状 04/12 01:38
29F:→ mayuyu: 只是沙盒或影子系统会担心被keylogger盗取密码 04/12 01:38
30F:→ mayuyu: 然後连上网路传出去 像影片中最後的测试。 04/12 01:38
31F:→ mayuyu: Sandboxie可以限制在沙盒内能够启动的程式 04/12 01:39
32F:→ mayuyu: (除了浏览器和其他必须的程式以外都不允许启动 04/12 01:40
33F:→ mayuyu: 不要使用IE就好 因为你总不能限制iexplore.exe不能上网xD) 04/12 01:41
34F:→ mayuyu: 限制可以连网的程式 04/12 01:41
35F:→ mayuyu: (除了浏览器和其他必须的程式以外都不允许连网) 04/12 01:41
36F:→ mayuyu: 限制可以存取的资源(资料夹、登录库) 04/12 01:41
37F:→ mayuyu: 同时降低沙盒内程式的权限 再另外搭配防火墙和防毒 04/12 01:42
38F:→ mayuyu: 就可以避免影片中被记录键盘输入盗取密码的机会 04/12 01:42
39F:→ mayuyu: 一些病毒在启动时都会检测自己是否在沙盒内 04/12 01:42
40F:→ mayuyu: 如果发现是在沙盒内为了避免被分析和追踪就会自己自杀 04/12 01:42
41F:→ mayuyu: 所以有一些病毒即使你允许让他执行他也不会有动作。 04/12 01:42
42F:→ mayuyu: 因为HIPS对於一些注入行为还是没有防御 04/12 01:42
43F:→ mayuyu: 然後利用浏览器漏洞、Flash漏洞、作业系统漏洞 04/12 01:42
44F:→ mayuyu: 让你一开启网页就注入系统程式连网 开始下载病毒 04/12 01:43
45F:→ mayuyu: 我觉得防不胜防 防毒软体要很全面很强 光靠云端还不够 04/12 01:43
46F:→ mayuyu: 启发模式要很强 也能够阻挡利用漏洞入侵的攻击 04/12 01:43
47F:→ mayuyu: 要做到这样可能一套防毒还不够 04/12 01:43
48F:→ mayuyu: 所以还是用虚拟化加上限制启动和存取、 04/12 01:43
49F:→ mayuyu: 降低权限的方式保护系统档案不被破坏应该是最安全的方法 04/12 01:43
50F:→ mayuyu: 现在测病毒很多都是用虚拟机来隔离测试 04/12 01:44
51F:→ mayuyu: 可以拿来测病毒就知道是目前比较安全的方法 04/12 01:44
52F:→ mayuyu: 应该是共识 cruelsister1本身也是建议用沙盒或虚拟机 04/12 01:44
53F:→ swattw: 他一次买五台授权,等等开团购好了 04/12 16:29
54F:→ noname123: WinAnti 始终会显示 error,只好移除。 04/13 22:55
55F:推 DINJIAPC: 他是使用特徵库去拦的 本来就会漏 06/03 08:28