CryptoMonitor - Stop all known crypto-ransomware before it encrypts your data!

starbuck

Malware Removal Specialist - Administrator
In Memory
Joined
Jul 16, 2014
Messages
1,147
Location
Midlands, England
CryptoMonitor is a new Anti-Ransomware solution that was developed to protect your computer or server against the wave of encrypting Ransomware that has been in the wild the last few years.

These infections, like CryptoWall, CryptoLocker, CTB Locker, CryptorBit, KeyHolder, TELSA, Operation Global, TorrentLocker, CryptoDefense, ZeroLocker (And Many Many More.), will use numerous exploits or other methods to get onto the victims machine and once launched encrypts/locks all personal files. When completed the Ransomware will then hold true to its name, and demand a ransom in order to get your files back, or forever face life without them.

All too often victims do not have backups of their files, cannot or will not pay the criminals, or their Anti-Virus software simply wasn't enough to prevent these attacks. With all of this in mind, CryptoMonitor was created to prevent your data being encrypted even when the ransomware bypasses your installed anti-virus solution.

CryptoMonitor does not rely on definitions to protect you from encrypting ransomware, but instead relies on behavioral detection that allows it to detect encrypting ransomware before it has a chance to encrypt your data. With this type of approach, even brand new crypto-ransomware infections will be stopped in their tracks without you having to worry about updates to the software. In fact, 90% of the time CryptoMonitor will lay in your system tray silently protecting you until the day you need it, and if that day comes your data will be safe.

CryptoMonitor currently has 2 types of protection included in it (There will be add on protection methods in the future). There protection methods are called Entrapment Protection and Count Protection. Entrapment is the main protection method that is recommended to always be on, and is the quickest and most accurate way to detecting Ransomware. Count Protection is the secondary "Double Protection" that is optional. Count Protection is a very thorough and sensitive method and should be used when you want the most extreme protection from Ransomware. Count Protection can also have false positives at times.

Entrapment Protection
Entrapment Protection lays numerous different types of traps all around your system that a Ransomware Infection cannot resist to touch. These traps send encrypted pattern signals back and forth between CryptoMonitor and themselves constantly. When a Ransomware Infection falls into one of these traps, the pattern is broken and CryptoMonitor immediately takes action. Once this happens, the machine is locked down and you are alerted about the infection and prompted for your decision on what actions to take. During this time, no file modifications are allowed, so your files are safe while you think about your course of action. With this protection enabled you may notice a few hidden files, registry keys, folders, and services running, but don't worry, they are there to protect you!

Count Protection (Pro Version Only)
Count Protection is a feature in the Pro version that is a offers double protection to your machine from Ransomware. This option is extremely sensitive and is the highest setting currently available to protect your files. CryptoMonitor Count Protection will constantly scan processes and use heuristics to categorize them into absolute trusted, unknown, and suspicious. While doing this, Count Protection will also log every time a process that isn't trusted calls API's to modify a personal file. Depending on the setting you set, when the process modifies over a certain number of personal files, under a certain time, then a flag is raised and CryptoMonitor will prompt you to take action.


Source and Download:
http://www.bleepingcomputer.com/for...ypto-ransomware-before-it-encrypts-your-data/
 
Starbuck interesting read. I was wondering if you have any experience with this software In actually stopping infections? Also what is the system impact upon usage of such software? Is this going to slow my computer to a crawl or have any other negative effects we should be aware of?
I also noticed this is a new company with no prior history, do you have any knowledge about said company or contact within said company or it's software authors?
 
Last edited:
I was wondering if you have any experience with this software In actually stopping infections?
Not personally as I've never had a ransomware infection on any of my systems.

Also what is the system impact upon usage of such software? Is this going to slow my computer to a crawl
CryptoMonitor 1.5.0.0

GUI Library removed that was found to cause CPU problems, which now keeps CryptoMonitor under 3% CPU on normal use even on a single core machine.

any other negative effects we should be aware of?
If you click on the link I provided it will take you to Nathan's thread on BC.
He's been gathering feedback from the thread and updating the program accordingly.
You will find all the info there.

All I know is that he is a Security Colleague over at BC.
The site owner at BC did state:
A very very promising tool and one that should be used by everyone. I tested it against numerous ransomware (Cryptowall, CTB Locker, CryptoFortress, and TeslaCrypt) and it stopped it in its tracks.
 
Back
Top