Ransomware defense.

Options
13567

Comments

  • Jivesinger
    Jivesinger Posts: 1,221 Forumite
    First Anniversary Combo Breaker
    Options
    Neil_Jones wrote: »
    All variations of this going back to the early Cryptolock days can do this as they go off looking on the computer, then go off after connected drives (external drives, USB drives etc) and then the network connected drives - those that appear as Drive Z ("Docs on Server\Share" for example) and encrypt the entire lot.

    Some can go after the unmapped network shares as well ("\\server\docs" for example) and if that is the case nothing is safe if its in a shared folder on a network with a computer under ransomware.
    My understanding is that Cryptolock etc. weren't worms that start executing on another computer though. They would just encrypt all the files they could see (which might be on a shared drive etc.)

    This latest one can look for other computers on the network and infect them with no requirement for a user to click on anything. So all linked computers (at least the vulnerable ones) are encrypting their own local storage, even though users on those linked computers haven't clicked on anything.
  • henm2
    henm2 Posts: 721 Forumite
    First Post First Anniversary Combo Breaker
    Options
    Just dump Windows and install a better operating system such as Linux Mint. That is your best defence against malware.
  • DavidP24
    DavidP24 Posts: 957 Forumite
    Options
    ha ha ha ha that is SO funny
    Thanks, don't you just hate people with sigs !
  • Deneb
    Deneb Posts: 420 Forumite
    First Anniversary First Post
    Options
    HitManPro.Alert


    Runs alongside a normal AV. The company have just been bought by Sophos who are implementing the technology in their own AV product.


    https://www.hitmanpro.com/en-us/alert.aspx
  • Browntoa
    Browntoa Posts: 49,305 Forumite
    Name Dropper Photogenic First Post First Anniversary
    Options
    Don't be an idiot and click on every link in an email

    Don't be an idiot and click yes when a web site says you need to "install some software to view"

    Don't be an idiot and click yes when something asks for administrative rights

    Don't be an idiot and download so called free or hacked versions of paid for software
    Ex forum ambassador

    Long term forum member
  • DavidP24
    DavidP24 Posts: 957 Forumite
    Options
    Or in this case, where it is spread by a network protocol

    Don't be an idiot and plug into a network

    Hell don't be an idiot and turn on your computer
    Thanks, don't you just hate people with sigs !
  • DavidP24
    DavidP24 Posts: 957 Forumite
    Options
    Deneb wrote: »
    HitManPro.Alert

    Runs alongside a normal AV. The company have just been bought by Sophos who are implementing the technology in their own AV product.

    https://www.hitmanpro.com/en-us/alert.aspx

    That was quick response to opportunity of FUD

    Of course you need a Core I7 to run it
    Thanks, don't you just hate people with sigs !
  • Browntoa
    Browntoa Posts: 49,305 Forumite
    Name Dropper Photogenic First Post First Anniversary
    Options
    DavidP24 wrote: »
    Or in this case, where it is spread by a network protocol

    Don't be an idiot and plug into a network

    Hell don't be an idiot and turn on your computer

    That's true for some people , cleared a friends PC of malware , explained about no clicking on links etc , went to loo and came back to them clicking on link in strange email . I felt like cutting the main screen lead
    Ex forum ambassador

    Long term forum member
  • bengalknights
    bengalknights Posts: 5,021 Forumite
    First Anniversary First Post
    Options
    henm2 wrote: »
    Just dump Windows and install a better operating system such as Linux Mint. That is your best defence against malware.

    Agree with this run Ubuntu and your pretty safe
  • Leon_W
    Leon_W Posts: 1,813 Forumite
    First Post Combo Breaker First Anniversary
    Options
    All I can say after having to deal with one of these cryptolocker type viruses earlier this year is. BACKUP ! It is the ONLY sure fire way of not losing all those pictures and documents you have accumulated over the years. I'm not an idiot, didn't click on anything suspect and consider myself technically proficient.

    My personal laptop was infected earlier this year and this thing set about encrypting every picture file and document I had. It was too late before I realised, and there is NOTHING that can be done to reverse the process, you're files are encrypted, end of.

    My backup was a few weeks old so I did lose some stuff, but you really don't realise how serious this is until it happens to you.

    All it takes is a new strain to slip through any virus software you have installed and you've had it so the only SUREFIRE way to protect yourself is BACKUP to a separate REMOVABLE drive (for gods sake don't leave it connected !)

    Hope this helps.
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.4K Banking & Borrowing
  • 250.1K Reduce Debt & Boost Income
  • 449.8K Spending & Discounts
  • 235.5K Work, Benefits & Business
  • 608.4K Mortgages, Homes & Bills
  • 173.2K Life & Family
  • 248.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards