Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology > Computers
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
Reply Start New Thread
 
Old 01-27-2016, 08:33 AM
 
10,926 posts, read 22,000,411 times
Reputation: 10569

Advertisements

For those wanting to participate in the Beta visit the link below, as usual if you don't know what Beta is you might want to stay clear.

https://blog.malwarebytes.org/news/2...nsomware-beta/
Reply With Quote Quick reply to this message

 
Old 01-27-2016, 03:05 PM
 
17,596 posts, read 15,266,523 times
Reputation: 22920
Here's the downside I see to this.

It has to be installed. In general, the people dumb enough to get hit by ransomware wouldn't be smart enough to install this.

The only place I can see it being somewhat worthwhile is on an office network or similar.. Where little Randy Retard is downloading torrents and the encryption propogates across the network, infecting 'innocent' bystanders.

This should be something that Antivirus detects before it gets a foothold.
Reply With Quote Quick reply to this message
 
Old 01-27-2016, 03:32 PM
 
10,926 posts, read 22,000,411 times
Reputation: 10569
It's no more difficult to install than any other program the average home user might install.

None of the ransomware that I'm aware of targets other computers on a network (yet), it will go after mapped network drives however. I don't see how torrents fit in to anything
Reply With Quote Quick reply to this message
 
Old 01-28-2016, 11:24 AM
 
17,596 posts, read 15,266,523 times
Reputation: 22920
Not that it's technical to install.. They're just not smart enough to know that they'd need to install it. Half of them run with the copy of McAfee that comes with the PC as their "Virus Protection".. You know, the one that says it expired 300 days ago.

https://blog.knowbe4.com/new-ransomw...network-shares

Torrents come into play because many of them contain viruses. People will go out and search for "Office Serial Number" and get a nice EXE file that "generates an office key".
Reply With Quote Quick reply to this message
 
Old 01-28-2016, 11:34 AM
 
10,926 posts, read 22,000,411 times
Reputation: 10569
Quote:
Originally Posted by Labonte18 View Post
Torrents come into play because many of them contain viruses. People will go out and search for "Office Serial Number" and get a nice EXE file that "generates an office key".
Not something I see a lot of on business networks. It's more likely to get in via compromised web sites, advertisements, or emails.
Reply With Quote Quick reply to this message
 
Old 01-28-2016, 02:25 PM
 
Location: NJ
4,940 posts, read 12,148,203 times
Reputation: 4562
I already have the paid version of MWB. They should merge this new application into MWB. I don't want to install or have to pay for a second application.
Reply With Quote Quick reply to this message
 
Old 01-28-2016, 03:26 PM
 
17,596 posts, read 15,266,523 times
Reputation: 22920
Quote:
Originally Posted by NHDave View Post
Not something I see a lot of on business networks. It's more likely to get in via compromised web sites, advertisements, or emails.
Depends on the business.

I got a PC in from a restaurant.. was their back office PC. It had been hit with one of the ransomware variants. Just wiped the drive and reloaded. I've had other PCs come in that just had so much porn it should have been illegal.

And, they've come in with torrent software running on them. Thankfully, the kazaa/napster days are over.

The encrypting ransomware ones.. At least with those.. I don't even try to unencrypt them. I presume that "Windows Antivirus 2012" thing is still out there. The one that would basically lock the PC and only show the link to download some bogus antivirus program.. That one was such a massive pain in the butt to clean up. And, the bad part is.. It CAN be cleaned up, so, I'd do it. I'd have saved myself an assload of time just formatting the thing.
Reply With Quote Quick reply to this message
 
Old 02-17-2016, 10:01 AM
 
10,926 posts, read 22,000,411 times
Reputation: 10569
Quote:
Originally Posted by NHDave View Post
It's no more difficult to install than any other program the average home user might install.

None of the ransomware that I'm aware of targets other computers on a network (yet), it will go after mapped network drives however.
Newer versions of crypto type ransomware will now go after any network shares, mapped or not. I'm surprised it took this long.
Reply With Quote Quick reply to this message
 
Old 02-17-2016, 01:18 PM
 
1,333 posts, read 883,798 times
Reputation: 615
Quote:
Originally Posted by Labonte18 View Post
Here's the downside I see to this.

It has to be installed. In general, the people dumb enough to get hit by ransomware wouldn't be smart enough to install this.

The only place I can see it being somewhat worthwhile is on an office network or similar.. Where little Randy Retard is downloading torrents and the encryption propogates across the network, infecting 'innocent' bystanders.

This should be something that Antivirus detects before it gets a foothold.
You're not paranoid enough.
Consider the following scenarios:

1. You download software X from legitimate source Y. Legitimate source Y's download servers have been compromised and are handing out infected copies of software X. You don't bother running a checksum on the software, because you downloaded it from legitimate source Y. You install and you see this sweet little message:
"Hello! Your files have all been encrypted but they're still safe!"

2. You visit trusted site Z who uses ad provider W. Ad provider W was compromised and has a rogue server handing out ads that utilize several Flash Game over exploits. You trust site Z, so you allow web content to run. Thanks to Adobe's wonderful software design, you see this message:
"Hello! Your files have all been encrypted but they're still safe!"

3. You fall victim to any one of the latest zero days that in the past allowed things such as transferring files without authentication to a victim computer, local privilege escalation, auto-execution of code from plugging a flash drive in, escaping the "secure" chrome sandbox and breaking into your computer, etc. These things have all happened and there's no reason to suspect they aren't still happening.



If you use Adobe Reader, Outlook, Skype, Microsoft Word, a computer etc. etc. there is no reason to think you're immune because you're more tech literate. No doubt if you keep your software up to date, you have a better chance than the lay user who does not; but you are NOT invincible.
Reply With Quote Quick reply to this message
 
Old 02-18-2016, 02:19 PM
 
Location: NJ
4,940 posts, read 12,148,203 times
Reputation: 4562
I guess this is another reason why people should not store personal files on their local hard drive. Personally I use Google Drive cloud storage. Not to say that couldn't be compromised either, but at least then someone else is responsible for the cleanup.
Reply With Quote Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Reply
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology > Computers

All times are GMT -6. The time now is 10:33 PM.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top