Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: [1] 2

Author Topic: And now it's Ransomware for Win10 Install  (Read 11096 times)

tbailey2

  • Kitizen
  • ****
  • Posts: 1245
And now it's Ransomware for Win10 Install
« on: July 31, 2015, 11:40:18 PM »

Wait, STOP – Are you installing Windows 10 or ransomware?
This one will be an 'absolute bastard,' say security bods

The Register again - this time scam mails apparently from MS to upgrade to Win 10 have a CTB-Locker payload....
Logged
Tony
My Books!
Plusnet 80/20 - DSLstats - HG612/TG582n - ECI

licquorice

  • Reg Member
  • ***
  • Posts: 977
Re: And now it's Ransomware for Win10 Install
« Reply #1 on: August 01, 2015, 08:55:14 AM »

Great, just what we need. Thanks for the heads up.
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: And now it's Ransomware for Win10 Install
« Reply #2 on: August 01, 2015, 12:22:55 PM »

That is really nasty.

Its akin to someone coming into your home and taking all your processions and saying you cant have them back until you pay us  :'(
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

NewtronStar

  • Kitizen
  • ****
  • Posts: 4898
Re: And now it's Ransomware for Win10 Install
« Reply #3 on: August 01, 2015, 09:08:42 PM »

Or just paranoia creeping in  ;)
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: And now it's Ransomware for Win10 Install
« Reply #4 on: August 01, 2015, 11:13:29 PM »

Nope its not paranoia NS - sadly ransom-ware such as this is very real and out there. Its nothing to do with Microsoft btw, its progression and evolution of the virus.
 
Many years ago I used to make a bit of beer money cleaning out viruses/trojans etc.. having studied them at degree level I found them fascinating and at one time it was a satisfaction challenge to get rid of it on other peoples PCs.   These days I wont do it any more because its way too time consuming and viruses have got more sophisticated.

I think people like HP who do stuff like virus cleaning will understand just how time consuming it can be particularly if people want you to be able to recover all their files.. and how they expect it done for little money.  Its why the likes of PCworld will only wipe the drives and anything you had on there gone forever.

Ive gotten rid of various scareware which presents itself as ransomware, but in recent years the viruses & trojans that use encryption mean that you have no chance of being able to do anything when the other side holds the key.  The only option is to payup.

Ransomware can be a very lucrative multi-million dollar industry. Its estimated that Cryptolocker procured $27 million between 15th Oct - 18th Dec 2013.  CryptoLocker was just one of many variants of ransomware thats out there :(
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

tbailey2

  • Kitizen
  • ****
  • Posts: 1245
Re: And now it's Ransomware for Win10 Install
« Reply #5 on: August 01, 2015, 11:36:39 PM »

Ransomware can be a very lucrative multi-million dollar industry. Its estimated that Cryptolocker procured $27 million between 15th Oct - 18th Dec 2013.  CryptoLocker was just one of many variants of ransomware thats out there :(

As a matter of interest, I've run CryptoPrevent on all my Windows terminals for some time with no problem. It does crash quite a lot (looking at Events Manager) but restarts itself each time. There's a free version and a Premium version, the latter autoupdates etc. It did fire off once on a site I wasn't too careful about looking where I was going but no damage ensued  :-[ I have no association with them BTW.

CryptoPrevent is an Anti-Virus/Security Software Supplement, originally designed to prevent infection from the CryptoLocker threat which emerged in late 2013. Since that time, CryptoPrevent has grown into a robust solution, providing protection against a wide range of ransomware and other malware.
Logged
Tony
My Books!
Plusnet 80/20 - DSLstats - HG612/TG582n - ECI

Dray

  • Kitizen
  • ****
  • Posts: 2361
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: And now it's Ransomware for Win10 Install
« Reply #7 on: August 02, 2015, 01:12:56 AM »

@Tony - Cheers just downloaded and installed it.  With the amount of driveby infections around best be safe than sorry especially when things like this can infect whole local networks and therefore rendering many backup systems open too.

@Dray -  Thanks for that link, lots of good info in there but the opening paragraph of  "In many ways this guide feels like a support topic on how to pay the ransom, which sickens me. Unfortunately, this infection is devious and many people have no choice but to pay the ransom in order to get their files back." shows just how serious it is :(   I note they also recommend CryptoPrevent.


Although the original CryptoLocker and its servers have now been shut down, there are many copycat verions of it, of which this latest  "windows10" is just one.
The original creator of Cryptolocker is still at large and wanted by the FBI with a reward of $3m  Judging by the FBI report he's responsible for 100's of $millions of losses now.



PS moving this to the security section as this type of ransomware is applicable to all Windows users (plus there's several versions for Apple too)
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

tbailey2

  • Kitizen
  • ****
  • Posts: 1245
Re: And now it's Ransomware for Win10 Install
« Reply #8 on: August 02, 2015, 07:56:40 AM »

@Tony - Cheers just downloaded and installed it.  With the amount of driveby infections around best be safe than sorry especially when things like this can infect whole local networks and therefore rendering many backup systems open too.

The basic config screen looks like this and there are also advanced options....

Logged
Tony
My Books!
Plusnet 80/20 - DSLstats - HG612/TG582n - ECI

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: And now it's Ransomware for Win10 Install
« Reply #9 on: August 02, 2015, 11:40:45 AM »

Thanks -  I set mine as 'Default'.  Yet when I check the settings page then I have the same options as you have so Im not sure exactly what the difference is between the 2.   

I also asked it to whitelist my installed legitimate programs, but Im not quite sure where it keeps that list. 
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

tbailey2

  • Kitizen
  • ****
  • Posts: 1245
Re: And now it's Ransomware for Win10 Install
« Reply #10 on: August 02, 2015, 01:14:39 PM »

Thanks -  I set mine as 'Default'.  Yet when I check the settings page then I have the same options as you have so Im not sure exactly what the difference is between the 2.   

I also asked it to whitelist my installed legitimate programs, but Im not quite sure where it keeps that list.

Er that may be me... The Screens don't actually match the settings as they were grabbed at different times and the setting I am using is Default like you.

If you do a lot of screengrabs BTW, LightShot (free for Win and Mac) is by far the best I've ever used and quicker than Snip tool. You can also annotate and highlight things before saving it directly from the interface, Use Print Screen key to activate - see attachment  :)
Logged
Tony
My Books!
Plusnet 80/20 - DSLstats - HG612/TG582n - ECI

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: And now it's Ransomware for Win10 Install
« Reply #11 on: August 02, 2015, 03:21:14 PM »

Quote
If you do a lot of screengrabs BTW, LightShot (free for Win and Mac) is by far the best I've ever used and quicker than Snip tool.

Just had a look at that and it seems very good so Ive added it to the free graphics software page.
As I have a graphics program I bought many years ago which despite its age is a decent full blown graphic editor that has an integrated screen grab button its not something I personally need, but Im sure it would be very useful for others. :)


*Dont laugh Im still using Jasc's PSP Anniversary Edition.  This has got to be the best £70 investment ever when it came to a full boxed graphics program because in its heyday it beat even photoshop for what you could do in it.    Unlike photoshop its fast and opens instantly, but saying that its usually open anyway because I can do certain things so much faster in it than photoshop.  Its also brilliant for customised screen grabs.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

tbailey2

  • Kitizen
  • ****
  • Posts: 1245
Re: And now it's Ransomware for Win10 Install
« Reply #12 on: August 02, 2015, 03:34:27 PM »

* Er  :cool: I have to say, I have a copy here of Jasc PSP8 (one version up on you) from the recent stone age that I still use! Best prog ever for allowing you to place multiple piccies on a canvas and move/resize them where you want for printing! CS6 is useless in that respect.
Logged
Tony
My Books!
Plusnet 80/20 - DSLstats - HG612/TG582n - ECI

tonyappuk

  • Reg Member
  • ***
  • Posts: 589
Re: And now it's Ransomware for Win10 Install
« Reply #13 on: August 02, 2015, 04:57:21 PM »

Just to put in my two pennyworth I still use PSP5 which came on a magazine CD yonks ago. You have reminded me to reinstall cryptoprevent after my recent PC rebuild. Thanks
Tony
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: And now it's Ransomware for Win10 Install
« Reply #14 on: August 02, 2015, 10:12:55 PM »

//Off topic Alert!

Quote
I have a copy here of Jasc PSP8 (one version up on you)

I actually have the PSP8.exe upgrade somewhere.  I bought it via an upgrade offer from Jasc/Corel as it was offered as an online download for about £8 for existing registered Anniversary users.   I think Corel had bought them out by about this time and tbh I found it slower to load than my old Edition.. yet it didnt have much new and iirc I was a bit disappointed with that version compared to my old.  Perhaps thats why that offered it at such a low price to existing Anniversary holders?
The previously bought the boxed Anniversary Edition which was a special with loads of extra freebies and plugins, filters, brushes etc etc thrown in.   

So now when I do a PC  re-install its just easy for me to get out the Jasc CD and use that..  I dont bother with the separate update .exe  I think by the time Corel had done a full workover on was it called 'X'? I really didnt like it.. but by that time I'd bought a students licence edition of Photoshop from college when I did a Macromedia/Adobe certification night school course.   Despite having newer software (but still comparitively old version of PS), its PSP that I use most often.   Like you say despite its age, its capable of doing some things that PS cant and much quicker.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker
Pages: [1] 2
 

anything