My neighbor had ransomware last week and neither malware bytes trend etc scans removed it all. I found it using process explorer and winpatrol (and prayer). Both should come with windows.
We noted yesterday that the two most popular Web threat tools used by hackers to distribute malware, the BlackHole Exploit Kit (BHEK) and the Cool Exploit Kit (CEK), already included the latest Java exploit. Before we dive in to how CEK is already being used to push ransomware, heres a bit of background information.
Created by the same guy, CEK is the high-end version of BHEK ($10,000 per month versus $1,500 per year). 0-day exploits are first incorporated into the former and only added into the latter once they have been disclosed.
For those who dont know, ransomware is a very profitable type of threat which restricts access to the computer it infects, spamming the user with prompts that demand a ransom paid for functionality to be reinstated. Access is limited either by encryption or locking the system.
CEK has been used to distribute ransomware before, but now its also using this latest Java vulnerability to do so. Trend Micro has detected the exploits in question as JAVA_EXPLOIT.RG and HTML_EXPLOIT.RG, as well as the ransomware payloads as Reveton (TROJ_REVETON.RG and TROJ_REVETON.RJ).
Reveton is one of the most common ransomware threats in existence today; these lock user systems and show spoofed notifications from local police agencies, Trend Micro says. These inform users that to unlock their system, they must pay a fine ranging from $200 to $300. -http://thenextweb.com/insider/2013/01/11/latest-java-vulnerability-possible-since-oracle-didnt-properly-fix-old-one-now-pushing-ransomware/
The second setting is to increase the security level of the Java runtime, which can also be done in the same Security section of the Java Control Panel. The default security level is Medium, but you can increase this to High or Very High. At the High level, Java will prompt you for approval before running any unsigned Java code, and at the Very High level all Java code will require such approval, regardless of whether or not it is signed.- http://reviews.cnet.com/8301-13727_7-57563567-263/new-malware-exploiting-java-7-in-windows-and-unix-systems/
I found no effect except ...
I don't go to FR as my homepage without logging in and password
I've been in "convenient" setting for FreeRepublic for 14 years and I have never had to re-enter my screen nasme nor password.
I can boot up in the morning, click "Internet" in my start-up, and go immediately to FR, which is my home page .. no log-in etc.
So, being lazy, I re-installed Java, checked up that I have the latest version and shut down, re-booted and I STILL have to log into FR.
I changed my setting to "more convenient" andf it didn't make a difference. NOW, I can't get into FR without logging in and password.
I don't like that.
Can anyone help me on this ?