Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

CryptoWall 4.0 the nastiest strain yet
iTnews.com.au ^ | Nov 10 2015 9:16AM (AUS) | Allie Coyne

Posted on 11/10/2015 6:00:08 AM PST by Utilizer

The fourth version of the CryptoWall ransomware has landed in the wild, equipped with better evasion techniques and tactics to thwart antivirus protection and detection.

Ransomware attacks computers and encrypts user files and folders via infected email attachments, with attackers demanding ransom payments to unlock the scrambled documents.

Users are told to make the payment by a specific deadline or risk having the private key to unlock the files deleted.

The active CryptoWall ransomware spawned from CryptoLocker, which is thought to have extorted more than $3 million from victims before the botnet used to distribute it - Gameover Zeus - was taken down last year.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Computers/Internet
KEYWORDS: malware; security; trojan; windows; windowspinglist
The newest of the Ransomware variants has struck. Apparently all versions of the 'doze OS, but the article has more info and might be worth a read.
1 posted on 11/10/2015 6:00:08 AM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

TechRepublic also has some info in a related article;

http://www.techrepublic.com/article/cryptowall-what-it-is-and-how-to-protect-your-systems/


2 posted on 11/10/2015 6:00:23 AM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

I want the people that create such programs to suffer a miserable, painful, humiliating death that takes years.


3 posted on 11/10/2015 6:04:06 AM PST by Fai Mao (Genius at Large)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer

I want the people that create such programs to suffer a miserable, painful, humiliating death that takes years.


4 posted on 11/10/2015 6:04:10 AM PST by Fai Mao (Genius at Large)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

5 posted on 11/10/2015 6:05:21 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

There are myriad prevention mechanisms, both computer-based and self-education, that can keep you from contracting this nastiness. Do a search for cryptolocker prevention and get educated.

If you are using the Professional version of Windows (7, 8, 10), you can edit either AppLocker or security policy settings to prevent applications from running in your appdata space. This restriction is VERY effective but can be a bit of a pain when installing some products that unload their installers to the appdata part of your local profile.


6 posted on 11/10/2015 6:19:39 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fai Mao

You’re much too nice. I would want worse.


7 posted on 11/10/2015 6:29:44 AM PST by meatloaf
[ Post Reply | Private Reply | To 4 | View Replies]

To: meatloaf
You're much too nice. I would want worse.

As a software engineer I take what these {expletives} do personally. It is an insult to all us software types. I ever meet one of these guys, they had better hope and pray there are witnesses around. If there are not... What happens to them is going to violate the Geneva Convention. They had better have voice recognition on their computers, they are never typing again.

8 posted on 11/10/2015 6:38:50 AM PST by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer

Wow, these b*stards should be nuked from orbit.

9 posted on 11/10/2015 6:50:38 AM PST by McGruff (Trump-Cruz 2016. Make America Great Again.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fai Mao
I want the people that create such programs to suffer a miserable, painful, humiliating death that takes years.


10 posted on 11/10/2015 6:52:16 AM PST by Bobalu (Even if I could take off, I could never get past the tractor beam!)
[ Post Reply | Private Reply | To 4 | View Replies]

Where Would You Go Without FR.......


Click The Pic To Donate

Support FR, Donate

11 posted on 11/10/2015 7:07:20 AM PST by DJ MacWoW (The Fed Gov is not one ring to rule them all)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fai Mao
I want the people that create such programs to suffer a miserable, painful, humiliating death that takes years.

That's not nice - to the rest of us. It leaves them alive to create newer and better programs of this sort until the very end. Much better if they have an "accident" which cuts off their criminal behavior. Frankly, I'm surprised that no person or organization that's been victimized by this has, uh, taken care of business.

12 posted on 11/10/2015 7:11:07 AM PST by Ancesthntr ("The right to buy weapons is the right to be free." A. E. van Vogt)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

This is apparently the price people pay for not backing up their data.


13 posted on 11/10/2015 9:04:13 AM PST by zeugma (Teach your child a love for motorcycles, and he'll never have money for drugs.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
Regarding your tagline--I totally understand.

I just purchased a new set of tires.

14 posted on 11/10/2015 9:07:02 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ShadowAce; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Ransomware strikes again ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to ShadowAce for the Tech ping!!

15 posted on 11/10/2015 9:30:01 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 5 | View Replies]

To: Fai Mao

Why should they have to die? Just have “large” gay men sodomize them for all eternity.


16 posted on 11/10/2015 9:38:43 AM PST by Tolerance Sucks Rocks (Democrats and GOP-e: a difference of degree, not philosophy)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

I’d like to see a one penny tax per email to fund an internet police force to track down such perps.


17 posted on 11/10/2015 10:53:55 AM PST by aimhigh (1 John 3:21)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

we blocked it at my work using a custom rule in Mcafee. We discovered all of the variants want to use the base appdata folder from the user’s logged in profile to execute. Well, usually no one programs their apps to execute just from the root directory they usually create a folder to run from. So we stop this thing by preventing .exe’s from running from that root \\users\user profile\appdata folder. Now, this isn’t an option for everyone as some apps with sloppy programming might get blocked but this does work.


18 posted on 11/10/2015 12:13:57 PM PST by miliantnutcase
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Be sure to have a good backup that is not on line with the PC that can be infected.

Keep backups up to date.

Rebuild and restore is hit.

Do not pay these scum a dime.

These guys will help and you can save on another drive locally if you like:

http://www.code42.com/crashplan/

Free backup:
http://www.veeam.com/endpoint-backup-free.html
Creates an Boot ISO for restores.

Don’t get caught by these $#*!!-heads.


19 posted on 11/10/2015 2:20:49 PM PST by Only1choice____Freedom (As long as America's tolerence of failure is not overwhelmed by a desire to succeed, we will fail.)
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson