Raccine 1.4.1
Author:
Florian Roth
Date: 12/21/2020 02:55 PM Size: 90.1 MB License: Open Source Requires: 10|8|7 Downloads: 2217 times ![]() |
Raccine is meant as a simple portable ransomware vaccine intended to protect against attacks that target shadow copies for deletion via vssadmin.exe.
Ransomware will often delete all shadow copies using vssadmin; Raccine intercepts that request and kills the invoking process. Raccine is a binary that first collects all PIDs of the parent processes and then attempts to kill all parent processes.
There are several advantages for Raccine, the method is generic, no replacement of a system file (vssadmin.exe or wmic.exe), which could lead to integrity problems and could break the "raccination" on each patch day, these changes are easy to undo, and finally, there is no running executable or additional service required (agent-less).
You have two different installation options:
Automatic
Download Raccine.zip from the Release section
Extract it
Run raccine-installer.bat
Manual
Apply Registry Patch raccine-reg-patch-vssadmin.reg to intercept invocations of vssadmin.exe
Place Raccine.exe from the release section in the PATH, e.g. into C:\Windows
(For i386 architecture systems, use Raccine_x86.exe and rename it to Raccine.exe)
Consider using Malwarebytes for complete antivirus protection and to protect your devices, data, and privacy.
Similar:
What's the Best Antivirus and Is Windows Defender Good Enough?
How to Tell the Difference Between a Virus and a False Positive
Which Anti-Malware App Is Best and Can It Run Alongside My Antivirus
What to Do When Your Norton or McAfee Antivirus Expire
Ransomware will often delete all shadow copies using vssadmin; Raccine intercepts that request and kills the invoking process. Raccine is a binary that first collects all PIDs of the parent processes and then attempts to kill all parent processes.
There are several advantages for Raccine, the method is generic, no replacement of a system file (vssadmin.exe or wmic.exe), which could lead to integrity problems and could break the "raccination" on each patch day, these changes are easy to undo, and finally, there is no running executable or additional service required (agent-less).
You have two different installation options:
Automatic
Manual
(For i386 architecture systems, use Raccine_x86.exe and rename it to Raccine.exe)
Consider using Malwarebytes for complete antivirus protection and to protect your devices, data, and privacy.
Similar:

Comment Rules & Etiquette - We welcome all comments from our readers, but any comment section requires some moderation. Some posts are auto-moderated to reduce spam, including links and swear words. When you make a post, and it does not appear, it went into moderation. We are emailed when posts are marked as spam and respond ASAP. Some posts might be deleted to reduce clutter. Examples include religion, politics, and comments about listing errors (after we fix the problem and upvote your comment). Finally, be nice. Thank you for choosing MajorGeeks.