查看: 1911|回复: 2
收起左侧

[资讯] Bitdefender Ransomware Recognition Tool

[复制链接]
petr0vic
发表于 2017-9-27 04:45:38 | 显示全部楼层 |阅读模式
Bitdefender Ransomware Recognition Tool is a new program for Windows by security company Bitdefender to identify ransomware.

One of the things that can be quite difficult when a system has been hit with a successful ransomware attack is the identification of the ransomware itself.

Identifying the ransomware is the first step in finding out more about it. It may tell you if there is a way to decrypt the data that the ransomware encrypted for free for instance.



Bitdefender's newest tool for Windows may identify ransomware for you. It is a simple program that does not need to be installed. All it takes is to run the program, accept the license, and use it to identify the ransomware.

Note: Bitdefender makes no mention of compatibility. The program ran fine on a Windows 10 Pro device. The program requires an active Internet connection according to Bitdefender.

This works by either adding the path to the ransom note, or a path to a folder that has encrypted files in it. It is necessary to add a path to one field in the program interface to continue to the next step.

You may hit the scan button after you have added a path to the program. If you have just filled out a path to encrypted files, you will receive a notification that doing so may decrease the detection accuracy.

The content of the ransom note is submitted to Bitdefender's cloud; files on the other hand are not submitted, as Bitdefender Ransomware Recognition Tool analyzes names and extensions only.

The application displays its findings afterwards. If it cannot identify the ransomware, it will tell you so. It may happen that it found multiple hits. If that is the case, it will display all hits sorted by relevancy.

The program links to decryptor programs if they are available for the ransomware in question.

Another interesting feature of Bitdefender Ransomware Recognition Tool is that admins can run it on multiple computers from the command line.

The following two parameters are available:
-note:RANSOM_NOTE_LOCATION;
-test:ENCRYPTED_FILES_LOCATION;

The program accepts absolute paths only, and requires that you add the ";" char in the end.
via ghacks.net

https://labs.bitdefender.com/2017/09/bitdefender-ransomware-recognition-tool/

Gollum
发表于 2017-9-27 08:39:30 | 显示全部楼层
新玩具
duguqiuai006
发表于 2017-9-27 09:26:09 | 显示全部楼层
勒索软件识别工具
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-22 15:59 , Processed in 0.127546 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表