Malwarebytes Anti Malware
The Malwarebytes Anti-Malware offers three different types
of scans – Quick Scan, Full Scan, and Flash Scan. The Quick and Full Scans
check the computer for possible threats while the Flash Scan is used for
analyzing auto-run objects and memory. After each scan, an option to remove all
or selected detected threats. A full report about the threats and what files
are affected are also provided. Users can also choose which system to scan
(e.g. registry, start-up items, etc). The program also features Chameleon
technology. This feature ensures that the Malwarebytes Anti-Malware program
runs on your computer without interruptions from malware.
The program also offers Protection Module. This module runs
in the background, ensuring that your computer is safe from possible threats.
If the Protection Module detects a threat, the file/files will automatically be
stored in the quarantine section of the program preventing it from being
installed on your computer. The program also offers a scheduler allowing you to
manage the scanning schedules. Protection Module, Scheduler and Flash Scans are
only available in the Malwarebytes Anti-Malware Pro version. (
press.malwarebytes.org, 2015)
·
Title:Malwarebytes Anti-MalwareFilename:mbam-setup-2.1.6.1022.exe
·
File size:20.55MB (21,546,080 bytes)
·
Requirements:Windows (All Versions)
·
Languages:en-US
·
License:Freeware
·
Date added:2012-10-05 08:25:52
·
Author:Malwarebytes Corporation
·
Homepage:http://www.malwarebytes.org/
·
MD5 Checksum:6cdeac78e5677e304477fb36351c3195
·
Malwarebytes' Anti-Malware is an application for
computers running under the Microsoft Windows operating system that finds and
removes malware.
·
Attacks relying on Macros haven’t let age dull
their ability to wreak havoc on a network, with a variety of tricks designed to
convince recipients into enabling them in Microsoft Word, believes Chris Boyd,
Malware Intelligence Analyst at Malwarebytes.
·
Malwarebytes
Anti-Malware detects Cryptolocker infections using multiple names, to
include Trojan.Ransom and Trojan.CriLock.XL, but it cannot recover your
encrypted files due to the nature of asymmetric encryption, which requires a
private key to decrypt files encrypted with the public key.( Just last month,
antivirus companies discovered a new
ransomware known as Cryptolocker. This ransomware is particularly nasty because
infected users are in danger of losing their personal files forever. Spread
through email attachments, this ransomware has been seen targeting companies
through phishing attacks. Cryptolocker will encrypt users’ files using
asymmetric encryption, which requires both a public and private key. The public
key is used to encrypt and verify data, while private key is used for
decryption, each the inverse of the other. The bad news is decryption is
impossible unless a user has the private key stored on the cybercriminals’
server.)
·
While Malwarebytes cannot recover your encrypted
files post-infection, we do have options to prevent infections before they
start. Users of Malwarebytes Anti-Malware Premium are protected by malware
execution prevention and blocking of malware sites and servers. To learn more
on how Malwarebytes stops malware at its source. Free users will still be able
to detect the malware if present on a PC, but will need to upgrade to Pro in
order to access these additional protection options. (filefacts.com, 2015)
Backup:
·
Also, the existence of malware such as
Cryptolocker reinforces the need to back up your personal files. However, a
local backup may not be enough in some instances, as Cryptolocker may even go
after backups located on a network drive connected to an infected PC.
Cloud-based backup solutions are advisable for business professionals and
consumers alike. Malwarebytes offers Malwarebytes Secure Backup, which offers
an added layer of protection by scanning every file before it is stored within
the cloud in an encrypted format (don’t worry, you can decrypt these).
·
Malwarebytes will NOT protect you against the
AFP ransomware (Australian Federal Police). It will NOT detect it once the HDD
is infected. The Malwarebytes "To The Rescue" disk will NOT boot once
the machine is infected. (reddit.com, 2015)
·
To be more exact, MB wont protect you from any
ransomware. Realtime file access protection is not in the toolset of MB. (evi.com,
2015)
From FBI: “To report potential e-scams, please go to the
Internet Crime Complaint Center and file a report.”
(FBI) Cryptolocker …
Unfortunately, once the encryption of the files is complete,
decryption is not feasible. To obtain the file specific Advanced Encryption
Standard (AES) key to decrypt a file, you need the private RSA key (an
algorithm for public key cryptography) corresponding to the RSA public key
generated for the victim’s system by the command and control server. However,
this key never leaves the command and control server, putting it out of reach
of everyone except the attacker. The recommended solution is to scrub your hard
drive and restore encrypted files from a backup.
Internet Crime Complaint Center (blog.malwarebytes.org,
2015)
References
·
https://www.reddit.com/r/Malwarebytes/comments/2v04ok/the_facts_about_botnets_malwarebytes_unpacked/
