[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
So I just got infected by some Ransomware called CerberRansomware...
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 240
Thread images: 24
File: Ransomware_Blog[1].png (49 KB, 1458x833) Image search: [Google]
Ransomware_Blog[1].png
49 KB, 1458x833
So I just got infected by some Ransomware called CerberRansomware... First time I get anything like that in over 10 years.

It encrypted all my files, this is a new install, I just kept my important files which are... Now encrypted.

Do I have no choice but to pay? Am I fucked? I don't know how to feel right now. I feel super mad but at the same time what can I do about it...
>>
>>54426857
You're a retard for not making backups, and for getting infected. Highly suggest suicide.
>>
Bamp
>>
Your ducked OP. Save all your important files on an external wipe the computer and reinstall the OS. Someone will find a crack to the encrypted files some day, just gotta wait. Or pay if they are that important
>>
>he felt for the "common sense" meme
I heard that Kaspersky published a tool for breaking randsomwares
>>
>>54426857
You either have to pay or spend millions to break the encryption. Back up your shit and watch what you run.
>>
>>54426887
Only a small number of ransomware variants have been cracked or had the keys recovered after the programmers were arrested.
>>
File: 236753244_fd9f6008f1.jpg (127 KB, 500x333) Image search: [Google]
236753244_fd9f6008f1.jpg
127 KB, 500x333
>>54426857
>using windows for anything other than gaymen
>>
>>54426885
They're asking for over one bitcoin, no way I'm paying that. They are important but not that important.
>>
How did you get infected?
>>
Fine, I learnt my lesson. But I'll be sure to watch these guys' downfall when it happens.
>>
>>54426917
MS Office install
>>
>>54426948
Pirate?
>>
>>54426910
How to edit raw files on meme/os?
>>
>>54426958
You kidding?
>>
>>54426958
Well yea obviously. People are gonna tell me to get openoffice or what but I fucking hate that program.
>>
>>54426974
Maybe
>>54426985
Libre
>>
For static or behavioural analysis, you can submit files to VirusTotal or Malwr.
>>
Should I do a clean install from a USB or can I just use Windows' reset to factory settings thing?
>>
Next time, backup your files in the cloud.
Make you own server if you are a true fa/g/got (with a raspberry or anything else), or pay a thing like Dropbox.

BTW, I think MS Office have the Winrar syndrome : legit install without activation/key will work fine if you close the message at start.
>>
+ The encrypted files are "safe" right? Won't hurt to keep them somewhere?
>>
What country are the people who create these in?
>>
>>54427048
Poor side of Europe
>>
>>54427048
I think these ones in particular are Russians or Belarussians or smt
>>
>>54426985
libreoffice is literally better than ms office in terms of usability and material design.
>>
>>54426985
Open office is glitchy. Try LibreOffice. Two minutes of googling "better alternative to openoffice" would have lead you to it. Seems like 99% of peoples problems could be solved if they just googled their fucking problems. I think the real problem is people can't skim effectively through the results, or even phrase their search properly.
>>
>>54426958
No, the official microsoft office download encrypted his files. Jesus christ thanks for the best laugh i've had all night.
>>
>>54427099
which mean nothing when it's worse in terms of compatibility and features
>>
>>54426985
And what you got this time around is better?
>>
File: 1460576824784.jpg (253 KB, 1080x1283) Image search: [Google]
1460576824784.jpg
253 KB, 1080x1283
>>54426985
So instead of using software thats a tad less polished than memesoft office you got all your important files basically removed

time well spent
>>
>>54427099
More of a user than programmer...

Both have faults imho, can't find a shit in MS Office, all those trash templates are in the foreground instead of real functionality, way too much hand holding too as soon as you click or hightlight something.

Libre is still buggy in many places. Just recently created a calc file for my workout and a graph that worked just fine is now crashing the program after I try to edit anything in the graph lol. Tried to give some feedback/bug reports, but that's way too complicated and a waste of my time prly. The devs prly just do it >for free anyway and couldn't care about small bugs reported from a non-coder.

MS Office on the other hand seems to be developed for people who do databases in Word. So it will only get worse in terms of usability.
>>
>>54426857
Not gonna pass judgement on you, but curios to know, how did you get infected? Was it a torrent/porn/warez or what?
>>
>>54427253
Read the thread dum dum
>>
>>54426857
In the future, install your pirated software in a virtualbox first, and monitor the traffic on your main desktop using wireshark. If nothing looks suspicious, then you could maybe install the pirated software it on your main desktop.

Wouldn't suggest it though. Installing pirated exes in this day and age is just dumb.
>>
>>54427253
He answered that already >>54426948
>>
>>54426857
how did u get infected
>>
>>54426985
Get MS Office ISO from MS
Get Microsoft toolkit from MDL
>>
>>54427151
>>54427157

Well when you see it like that it's pretty funny, it's true.
>>
But how did he get infected with teh malware??
>>
thanks putin
>>
>>54427285
Then what, you pay for all your shit or use lesser free versions of the shit you need?
>>
File: mr_rogers_thumb.jpg (223 KB, 598x631) Image search: [Google]
mr_rogers_thumb.jpg
223 KB, 598x631
>>54426857
>I feel super mad

When I feel mad or sad, I think about all the people in the world who love me. Think about those who have made sacrifices so that you can have a better life.
>>
>>54427353
>Then what, you pay for all your shit
Yes. You should have a job and make some money. If you're a jobless NEET or underage and can't afford paid software, then you are stuck with gratis alternatives.
>>
>>54426948
that's what you get for being a pirate
>>
>>54427353
The only time you really "need" software is when it's mandatory for school or work. The latter should be paying for license keys, and the former probably won't.

If you have to have Microsoft Office for school, then you can probably get by with a free alternative. If you can't, you're gonna have to work at McDonalds for 2 days in order to acquire enough funds to purchase the software.

Of you can gamble by potentially installing more Ransomware. Your choice.
>>
>>54427388
nah, smart pirates don't get ransomware, stupid people do
op seems to be as smart as a paint drinking zika baby
>>
>>54427371
>then you are stuck with gratis alternatives.

dude needs to learn a valuable life lesson that applies to almost everything.

>beggars can't be choosers

too many entitled goobers around here.
>>
sorry op just pay the fine or files encrypted there is really nothing you can do besides that
>>
>>54426857
Op, how did you get infected in the first place?
>>
Ransomware takes time to encrypt the files, you can boot into Ubuntu or another licuck distribution and back the files that are still intact.
>>
>>54426857
wat did u download to get virus
>>
>>54427510
>>54427526
>>54427253
>/g/ in a nutshell

You should know other people care just as much as you, why wouldn't you read the thread first
>>
>>54427510
>>54427526
Read the thread, faggots.

>>54427524
The message won't pop up before it's too late. Maybe you're lucky and notice it before, but apparently most people don't.
>>
>>54426857
Just try the solutions to others ransomwares in this ransomware.
>>
File: 1460318590128.png (101 KB, 292x257) Image search: [Google]
1460318590128.png
101 KB, 292x257
>windows problems
>>
>>54427820
>ransomware doesn't exist on Linux or OS X
I hope you don't believe this anon. It is incredibly fucking stupid of you.
>>
>>54427848
You'd have to be a drooling idiot to get ransomware on Linux.
>>
>>54427820
Post desktop.

>>54427848
>exist on Linux
Proof?
>>
>>54427873
It's just default Plasma 5.
>>
This is a troll thread, pretty much all Ofice ISOs on KAT are from verified uploaders

OP you really had to some extraordinary stupid to get infected
>>
>>54427869
You have to be a drooling idiot to get ransomware anywhere
>>
>>54427928
True, but it's substantially easier to "click the monkey" on Windows.
>>
>>54427048
adidas country
>>
Lesson to be learned.

Only download chingliu or firstuploads torrents from kat.cr.
>>
>>54426857
> using Windows
>>
>>54427928
pdf xp
>>
>>54427991
>chingliu

he stopped uploading like a year ago on kat
>>
>>54428000
PEBKAC
>>
Nigga how poor to you have to be to not buy office. Office 365 is like 10$
>>
>>54427873
Because Google is hard.

https://en.wikipedia.org/wiki/Linux.Encoder.1
>>
>>54426857
How the fuck does someone from /g/ even get this I would understand my grandmother opening an untrusted exe but on /g/. Like come on
>>
Could it still infect a write protected drive?
>>
>>54428074
I got the most downloaded MSOffice from piratebay without actually looking. I know I'm retarded okay, but at least I learnt
>>
>>54428117
Wait, so you're saying the most seeded Office is ransomware? I find that hard to believe
>>
>>54428157

>what are bots?
>>
>>54428117
>piratebay
You probably got it from the Flash ads.
>>
>>54428180
nah man, just type office in piratebay, check the most seeded, check the comments (which weren't there at the beginning)
>>
Ransomware devs generally have a sort of 'thief's honor' so if you pay you'll probably get the data back.
>>
>>54428117
Sometimes the s/l numbers are faked.
>>
>>54428223
What happens when you pay? They give you the key, but where do you enter it?
>>
>>54426878
ransomwares also encrypt network mapped devices retard
>>
can you get ransomware on osx?
>>
>>54428263
You can, but it's much more rare
>>
>>54428223

Sure just give me a bitcoin no problem
>>
>>54428251
why the fuck is your backup drive perma connected
>>
>>54428245
Probably depends on the program. They will probably tell you how once you pay. They want people who pay to get their data back because more people will pay up if they're sure they will get their files back.
>>
>>54426857
>>54426857

LOL how did u even get a virus in 2016? torrent?
>>
>>54428278
so much this
if it's perma connected then it's not really a backup as it entirely misses the point of a backup
>>
>>54428263
yes, peoples first reaction is to think their OS isn't windows so they can't get infected, virus makers know this and will target those people

http://9to5mac.com/2016/03/06/first-os-x-ransomware-detected-in-the-wild-will-maliciously-encrypt-hard-drives-on-infected-macs/
>>
>>54426857
>So I just got infected by some Ransomware
>It encrypted all my files

so ready for encryption to be illegal so this type of shit will stop. when normal people (who don't need it) have access to encryption, so do the bad guys
>>
Why do you come here seeking help for being a retard? Did you think that for one moment /g/ is a helpful place where we hand hold you to resolve your problems. UR A FAGGET
>>
File: 13123154.jpg (27 KB, 367x451) Image search: [Google]
13123154.jpg
27 KB, 367x451
>>54428251
Are you one of those retarded stupid as fuck certified low IQ dumbfucks who whined about Networked Attached Storage being superior to Backup Drive Enclosures that require manual plugin because plugging in a Drive Enclosure is "too much hassle"?

You must feel stupid as fuck and retarded, just as you were born and still are right now.
>>
>>54428276
>>54428314
for now I've only installed pirated photoshop, premiere and logic, I fear the worst while installing pirated dmg files
>>
>>54428117
Someone download it and run it in a VM/unused computer
>>
>>54428338
what are you even saying? define normal people?
packet hacking exists, if the packets weren't encrypted then data would just be stolen/infected in transit
>>
Do these randomwares actually unlock your shit if you pay? I figured they would just take your money and run if you were dumb enough to actually pay them.
>>
>>54428338
It is useful in a good way for some people though
>>
File: 1432500818880.png (576 KB, 881x506) Image search: [Google]
1432500818880.png
576 KB, 881x506
these threads have to be jokes
>>
File: tyrone20years.png (178 KB, 500x540) Image search: [Google]
tyrone20years.png
178 KB, 500x540
>>54427099
>Libreoffice
>material design
How fucking baked are you senpai?
>>
>>54428393
>inb4 it breaks out the vm and encrypts all your shit

That would be funny as hell
>>
>>54428405
>Do these randomwares actually unlock your shit if you pay? I figured they would just take your money and run if you were dumb enough to actually pay them.

Of course.

If they did that then word would get around and people would stop paying.

Plus it's not like it costs them anything to unlock it
>>
>>54426857
try this
https://noransom.kaspersky.com/

alternatively you could try manually decrypting.
many of these people with ransomware are stupid and use the same key for everything.
look up a phoronix post about this.
>>
>>54428405
I honestly wouldn't be surprised if they actually gave you your files back.

If i were some rich fuck i would deliberately inflict myself with that shit and pay, just to see what happens
>>
>>54428405
They do give you the key, they want people to give up and pay up instead of just formatting. Giving the key after people pay is far more lucrative for the scammers.
>>
>>54428441
How would it do that, is that possible at all?

If you had bridged connection with separate private IP than your host PC i don't see how it can happen
>>
>>54428441
>is unleashed on some vps
>breaks out and encrypts the entire fucking server
I would applaud someone that could write a monster like that
>>
Why do /v/ faggots fall for ransomware, and why do they post on /g/ about it?

/g/ is not your personal tech support hotline
>>
>>54428314
I really hope they charge a good 20% premium.
>>
>>54428478
It pretty much is though. For every three Anons telling /v/tards to fuck off, there's one enabling them.
>>
>>54428478
If /g/ was not /v/'s second board, then faggots like you wouldn't be making gamer hardware threads like Razer threads or GeForce/Rx GPU threads.
You'd be making proper peripheral threads and proper /g/ related threads of proper GPUs like Quadro and FirePro.

But you are a /v/ faggot, and as such you use gaymer hardware like GeForce or AMD Rx series GPUs, and gaymer peripherals,
so who are you to command what and where other people should post?
>>
>>54428310
>if it's perma connected then it's not really a backup as it entirely misses the point of a backup
Prior to the upsurge of ransomware, backups were mainly protection against drive failure. In that sense it does not at all miss the point of a backup.
>>
>>54426857
>windows problems
>>>/v/
>>
>>54428519
>Prior to the upsurge of ransomware, backups were mainly protection against drive failure.
And protection against drive failure is usually done by not having HDDs run 24/7 like a retard, but using them for periodic backups while they rest in-between.
Of course, it takes a non-retard to understand this basic nlogic.
>>
>>54427128
An there I was wondering what MS business model was giving Win10 away for free.
>>
>>54428562
>Hi there, My name is Bill Gates, i encrypted your files and you have 72 hours to switch to Win10 or face total wipe of your HDD. P.S. send 1 bitcoin
>>
>>54427157
>a tad less polished

It's quite a bit more than a tad. LibreOffice hasn't even attempted an answer to OneNote
>>
>>54428516
>muh gee pee juu
>>
>>54428550
No. It is very unlikely that both HDDs (main one + backup) fail at the same time. If one fails, you get a new one and copy all the stuff over.
Unless maybe your PC falls victim to a fire or flood. Then you're fucked either way and only an external backup would help you.

Of course it is better to have an offline backup as well, especially with ransomware that encrypts all your files on the rise. But until recently, that wasn't the main purpose of backups.
>>
File: asdas.jpg (34 KB, 208x199) Image search: [Google]
asdas.jpg
34 KB, 208x199
>>54428680
What you are thinking is server redundancy, not backup redundancy, or workload RAID redundancy (for video editing fags and such).

For backup purposes, only complete and utter retards use NAS instead of periodic manual backup to an off-line backup enclosure. This thread being a perfect example of why, as well as the fact that you want your backup drives to endure as much as possible instead of being constantly wore down like always on server or workload drives.

You need to make these 3 distinctions.
>>
>>54428205
>>54428180
I personally think he got it from the flash ads too, PirateBay has had an issue with those lately.
Set your flash to 'Ask to Activate' or better yet, 'Never Activate' and this wouldn't have happened.
>>
>>54428519
>backups were mainly protection against drive failure
Wrong.
This is the same as saying that RAID is backup.
Backups are for when some retard deletes or overwrites an important file.
That is to say that OP is one too for keeping his backups on an online disk
>>
>>54428731
It's still a backup.

>>54428852
You can copy old files over from an always-online disk. I don't see the issue with that.

From Wikipedia:
>In information technology, a backup, or the process of backing up, refers to the copying and archiving of computer data so it may be used to restore the original after a data loss event.
>>
>>54428922
>It's still a backup.
It's not a backup, it's redundancy.
A server has a function that is not backup but operational.
A RAID has a function that is not backup to video editors, but a performance operational function.
A backup has no operational function. It is pure and simple backup, and the definitions of backup is maximum redundancy with the least amount of operation.

As i said, learn your distinctions.
You are basically saying that getting someone to hand you their password, and then using it on their account without consent, is "hacking". It's the same stupid grasping for a rationalization.
>>
>>54428978
It is a backup, faggot. You can't change the definition of a word just because it doesn't suit you.
>>
>>54429019
The definitions of the process of backing up, and the definitions of a backup drive, are two different things retard. And server and RAID (arguably) drives aren't backup drives. Get it you triple nigger?
>>
>>54428922
>From Wikipedia:
Which works best if your backups are actually intact and not encrypted.

What you essentially just said is that if you copy a file from "my documents" to desktop you can call it a backup.
It's not.

You have multiple people disagreeing with you, yet here you are trying to justify yourself in with technicalities. Stop, it's annoying
>>
>>54429041
I see, even though you are obviously wrong you just refuse to acknowledge this. There is no point in further arguing with you.
>>
File: wikipedia_again.png (40 KB, 1411x313) Image search: [Google]
wikipedia_again.png
40 KB, 1411x313
>>54429097
wrong picture, sorry.
>>
>>54426857
let me guess, you were using CommonSense® 2016?

haha. faggot
>>
>>54429019
>I don't like what the mean man is explaining! He's wrong! Wrong wrong wrong wrong!
>>
File: this.png (71 KB, 1015x411) Image search: [Google]
this.png
71 KB, 1015x411
>>54428117
>>54428157
>>54428205
Was it the first one? I compared the files' descriptions and they seem the same person. Recently uploaded torrents, lots and lots of seeders.
>>
>>54429066
>What you essentially just said is that if you copy a file from "my documents" to desktop you can call it a backup.
Yes. You can call that a backup. Sometimes you make a copy of a file as backup (maybe with an ending like .bak) before editing/updating it. That is a different kind of backup, but it still is one.

>>54429066
>You have multiple people disagreeing with you
Oh, I didn't know this was a case of democracy.

>>54429132
Funnily enough, this is exactly what you are doing right now.
>>
>>54429159
toplel the guy decided to get some money for vacation
>>
>>54429162
>Oh, I didn't know this was a case of democracy.
It's more a case of you being a smartass and others not liking it.
And you see what good online backups have done in OP's case. Even the screenshot you posted showed that it is one of the worst backup types you can use, short from just copy pasting
>>
>You guys are still arguing
Semantically it is still technically a back up

Leaving a harddrive always attached is also indeed missing the point of a HARDDRIVE backup, failure was one concern by viruses spreading through connected drives has been a long standing concern too, ransomware is just another virus it didn't invent the concern
>>
I don't even feel bad, you deserve this.
>>
File: 1426046368002.jpg (37 KB, 461x461) Image search: [Google]
1426046368002.jpg
37 KB, 461x461
cortana

bing search me free microsoft office download online

ah yes,

free-download-online-ms-office.co/download-free-online.php

this looks good, thanks cortana
>>
>downloading microsoft activators from somewhere else than forums.mydigitallife.info
>>
Care to share how do you get infected?
>>
>>54428469
>How would it do that, is that possible at all?
A security flaw. It happened a few months ago in qemu and got a whole pseudo-marketing campaign ala Heartbleed. Oh, here it is http://venom.crowdstrike.com/
>>
>>54426895
>spend millions to break the encryption
>>
>>54428041
It's free if you attend college once

At least here in Nevada it is
>>
File: small loan of one million keks.jpg (500 KB, 728x640) Image search: [Google]
small loan of one million keks.jpg
500 KB, 728x640
>>
>>54428416
yeah if you're a pedophile
>>
>doesn't just recover data from looking at deleted files on computer
>ransomware is so shitty it encrypts stuff then deletes it and doesn't zero the data
>>
File: 1335122159242.png (4 KB, 386x308) Image search: [Google]
1335122159242.png
4 KB, 386x308
>>54429115
>wikipedia as a valid source
>>
>>54426985
>LibreOfiice
That software is so incredibly shit it makes me angry.
At least on OS X.
>>
File: 1432665522384.jpg (58 KB, 640x360) Image search: [Google]
1432665522384.jpg
58 KB, 640x360
>mfw when i pirated and installed office 10 mins ago

Am I fucked
>>
If i keep my external HD connected to my PC and i get infected, will it get fucked too?
>>
OP which side did you get the installer from?
>>
>>54430230
He said tpb already.
>>
>>54426902
I really hope these faggots are getting ass-raped in jail.
>>
Goddamn,you should post this in the ylyl thread because it's fucking hilarious.
>>
>>54428292
Would be pretty bad for business if they had a reputation of not decryptning after payment. People whould have no incentive to pay, as it would be a fools errand.
>>
>>54426948
Can you link me to it? I do research for a university, and I'm always looking for new malware.
>>
>>54427285
>virtualbox
>all that shit
fuck you, im not going to do all that fucking work for one fucking DOC file
>>
>>54430192
Yes as it's a mapped drive.
>>
>>54430133
> using this stale meme
>>
>>54428064
it only targets servers running unpatched Magento. Desktops are safe.
>>
>>54428580
Don't you dare give MS any ideas
>>
>>54426857
You deserve this for being a retarded Micucksoft user
>>
>>54432317
le ebin maymay redditor XD °_° lol
>>
This shit makes me mad and scared, i have a network drive with over 20 tb of storage and really important files. I suggest people to make an account at stack storage, 1tb for free and that will be enough for the most important files
>>
>>54432363
top kek look at the damage control
>>
>>54428613
use google keep
>>
File: 12323523.png (428 KB, 1444x1974) Image search: [Google]
12323523.png
428 KB, 1444x1974
Use this next time anon
>>
>using Windows

you deserve it, cuck
>>
>>54427307
How do I know this isn't a virus either?

You guys wonder how we end up paying for software here but it takes some knowledge to not just download a virus if you wanted to get free Adobe After Effects for example.
>>
>>54428205
This is 2016 you can't just do that and expect to avoid viruses
>>
>>54433726
Brain needs tech literacy plugin retard
>>
File: Serial_Experiments_Lain_0.gif (1016 KB, 500x357) Image search: [Google]
Serial_Experiments_Lain_0.gif
1016 KB, 500x357
>>54426857
Please share link to exe that infected you? I wanna have a look see!
>>
>>54439081
Read the thread
>>
>>54430133
Not any less valid than any other encyclopedia
>>
>>54431359
hope all your uni computers get encrypted
>>
>>54439466
The CS network run on Debian servers, and all computers use Ubuntu.
>>
File: 1461304030222.png (623 KB, 443x650) Image search: [Google]
1461304030222.png
623 KB, 443x650
>>54428922
I maintain a RAIDz, triple pairity RAID1, and a RAID0 across 3 disks.

It
is
not
backup

I keep a 3TB drive in a safe part of the house in anti static bags with my most important files.
>>
>>54426857
Interesting.
I've been looking for a ransomware to do some research.
Can you provide a link?
I want to know if WINE get effected, and how does such programs do under sandbox or VB?
>>
>>54439544
He said a MS office torrent from TPB
>>
>>54427099
Now tell me about that compatibility.

The concept is nice and all, but what's the point if it has abysmal compatibility when opening up the same documents in official MS Office applications.
>>
>>54429115
gtk kuck detected
>>
>>54436206
>How do I know this isn't a virus either?
How do I know you're not a retard?
>>
File: 1314315910023.jpg (81 KB, 370x370) Image search: [Google]
1314315910023.jpg
81 KB, 370x370
>>54439429
>>
>>54426966
with an editor u fucking retard
>>
I have a 3TB machine with another 3TB of backup drives sitting on my table. Sunday is prime for making backups.

Anyway depending on the ransomware there might be a decryption tool. I suggest you use a liveusb or some such to boot and tinker about. Maybe edit the time somehow. Don't you have something like a system restore? Norton Ghost? DeepFreeze? Windows' own system restore? Hard disk image? Something like that.
>>
>>54426985
There are two versions of Office on tpb, one is infected and the other is not. Both have thousands of seeders. Don't you fucking check the comments?
>>
>>54433123
Send invite please?
>>
>>54430133
What part of that image is inaccurate?
>>
>>54429041
>And server and RAID (arguably) drives aren't backup drives.
What mythical space-age drives made of unobtainium are backups stored on, then?
>>
>>54428064
did you even read the text you linked? It's a flaw in a third party shopping cart software. How many people run some shopping cart server on their on desktops? Where they also do their daily computing?

also
> this malware affected at least tens of Linux users

lol

a real threat
>>
>>54440741
>Linux.Encoder.1 is remotely executed on the victim's computer by using a flaw in Magento, a popular Content management system app.
okay.jpg
>>
>>54428338
no normie would stop using encryption, people living in russia writing ransomware won't. You can't get rid of encryption software taking a file and moving through each byte adding a number to the value is encryption and I can do that in a few lines of C.
>>
You are fucked OP. It would be like me telling you to guess the 256 character password I have in my head.
>protip you would die before a computer could ever stand to successfully brute force it.
>>
>>54426857
How did you even get infected

Serioulsy HOW DO PEOPLE GET INFECTED BY THESE
>>
>>54441005
read the thread retard

someone put the MSOffice torrent on TPB with thousands of seeder bots, it was No1 place in search

Honestly, anyone could have fallen for this, i always look if it's verified uploader but i forget it sometimes
>>
question about ransomware

wouldnt it take several hours to encrypt 500gb of data or whatever

how does this happen without anyone noticing
>>
>>54441031
Probably working in the background
>>
>>54428251
how dense can you possibly be to permanently connect your backup storage to your daily driver. You are seriously too dumb to use the internet
>>
>You don't have permission to access this folder
>Click continue
>Still denied
>As built in admin
>AFTER PASSING OWNERSHIP OF C:/ TO BUILT IN ADMIN FROM THIS NEW TRUSTEDINSTALLER BULLSHIT.

I cant find the IPs to add to hosts to disable big brother mode.

or a program to turn built in admin into the god mode it HAS ALWAYS BEEN
>>
File: 1457549429044.jpg (59 KB, 593x491) Image search: [Google]
1457549429044.jpg
59 KB, 593x491
>>54428064
>this malware affected at least tens of Linux users
>at least tens of Linux users
>tens of Linux users
Way to prove his point, retard
>>
>>54441070
Hey that's like 50% of the whole Linux userbase!
>>
>>54429159
>MUH TORRENTS
jesus you guys can't be helped

just get the OFFICIAL ISO from Microshit and then get some serial or download some semi-legit activator from MDL

sure in all fuck all those shitty torrents will contain trojans and ransomware for cheap idiots who can't be bothered to back up their files

I have no sympathy for criminals, but it's a tough world fuckbois and this happens when you are a literal idiot
>>
>not running warez on your VM first
Done fucked up son.
>>
>>54441031
>wouldnt it take several hours to encrypt 500gb of data or whatever
Depends on how fast your hard drive is. As a best case scenario, a 6 Gbps SSD running a block cipher could write 500 GB in a matter of 10 minutes.

That said, hard drives are generally slower and on top of this cryptolockers may want to avoid block ciphers because it implies having the decryption key on the host machine at least somewhere. (Although if you can detect this and abuse that fact early enough for it to matter, you might as well just prevent the cryptolocker from running altogether)

Due to this and other reasons, cryptolockers generally don't try to encrypt the entire hard drive - but instead they scan for “important” documents (pictures, excel spreadsheets, word documents, password databases, etc.)

For those, you can even do the encryption in a temporary directory (as long as you have enough free space) slowly over time (to prevent suspiciously high CPU usage) and then once you're done with the entire set of files, overwrite the originals by your copies in a single, fast operation.
>>
>>54441085
Activator could have been also a trojan, you make no sense

Even if it's from MDL
>>
>>54441031
The one this guy got is called cerbus. Read the malwarwbytes blog, but the jist of it is that it encrypts only a small portion of each file, so it's not accessible, and only certain files and folders are encrypted. This is so it is fast
>>
>>54426910
> sharing an smb share in my home network (in fact multiple different smb shares, but this is not important)
> daily runner is a linux laptop
> homeserver hosting the smb share naturally runs linux
> one day wife's work laptop catches a ransomware
> also everything in her smb share folder is now encrypted

thanks, bill gates
>>
>>54441121
That's why I said semi-legit. It's not open-source after all, but those guys on MDL built up trust and a pretty strong userbase. The official versions (check hashes) have been tried and tested over years without packaged malware.

That of course doesn't prevent them from adding malware later on or their accounts getting hacked and fake activators being distributed, but my point still stands.
>>
>>54440375
i dont see the bad version unless its the one with 2000~ seeds and nothing under it
>>
>>54441207
probably deleted by now, it was there yesterday, i checked it out, top seeded one
>>
>>54441207
>>
Genuine question, how do you not notice your drive being encrypted?, not notice a process taking significant memory and sucking up Ghz?

Or does it wait for you to leave to start its shady wrongdoings?
>>
>>54441258
Also note how it's not a trusted/vip user.
>>
>>54441270
>>54441116
>>
>>54441270
Completely depends on how it's programmed. Very difficult to detect besides some consistent disk access pattern.
>>
>>54441116
>Depends on how fast your hard drive is. As a best case scenario, a 6 Gbps SSD running a block cipher could write 500 GB in a matter of 10 minutes.
Oh, this is also assuming malware programmers could write good/fast crypto code.
>>
>>54441270
A lot of people who get infected have shitty first gen i3 Acer Laptops with 2GB of RAM and a fragmented 500GB HDD from 2011, their computer is already so slow and shitty they don't notice another process in the background
>>
Have you tried Windows restore from safe mode, or maybe booting with a rescue CD to try and clean the malware?

If I were you I wouldn't pay shit, unless I had some insanely important documents to rescue
>>
>>54427028
Ye, keep em
>>
>>54441258
>>54441277
What's the difference between skull colors?
>>
>>54441258
ok, i thought you meant look at the comments as the comments are telling you its infected.

thank god im not an idiot and use mostly private trackers for almost all my torrenting anymore, the little i get from non private is non exe.
>>
>>54441379
vip users paid for a skull color so they can put dozens of malware in their uploads so they can make a nice botnet
trusted users already have a botnet of computers sufficient to mark themselves as trusted.
>>
>>54428338
This is b8, or you're so stupid that I'm amazed that you're able to stay seated upright for long enough to be able to post
>>
>>54441680
The joke is that this is literally the argument people use to argue that guns should made illegal
>>
Nuke, reformat, reinstall.
No, you don't have anything vital in your drives. Yes, you can re-download your videa gayms and your shitty yify rips again.
Stupid shit.
>>
Its too late OP, once you reinstall your OS it will immediately encrypt anything important. Its already flashed your hd firmware and your motherboard and replaced the UEFI keys with its own. Everytime you boot up a shadow operating system will come online on top of your OS and encrypt your valuable memes until you pay up.
>>
>>54441735
you forgot to mention the audio chip, NIC and GPU BIOS
>>
File: 1459030086777.png (301 KB, 487x391) Image search: [Google]
1459030086777.png
301 KB, 487x391
>>54441070
>tens of Linux users
So, almost all of their users?
>>
>>54428801
Or better yet, use ublock origin because it is "current year"
>>
>>54439081
you can find cerber samples everywhere you fucking retarded tripfag
>>
>>54441410
That's odd, there were hundreds of comments saying the upload was infected just a week ago. Seems that they were all deleted. Not sure if it's the browser though.
>>
>>54441070
Are you delusional? He said prove it exists.

It exists.

That's it, that's all that was necessary. Please become literate or kill yourself.
>>
>>54440741
>How many people run some shopping cart server on their on desktops?
Who's talking about desktops? Linux runs on more servers than desktops, and the ransomware is far more profitable when aimed at idiot businesses.

Again, learn to fucking read you daft cunt. Original poster said prove it exists. It exists.

There, done. End of story. Go fuck yourself.
>>
>>54441960
Way to go, lets continue this shitposting for a whole another day
>>
>>54441701

It might be the same argument, but you have to admit its a lot easier to control guns than it is to control software, after all, guns are physical items that have to be manufactured, which is out of reach due to financial and material constraints for most people, plus I think it would be difficult for a large criminal enterprise to conceal the true nature of any covert weapons manufacturing or transportation indefinitely, provided you have effective policing. However, any device with electronic memory of any kind can be used to create malware, provided you have an ability to edit that memory. The ONLY barrier to entry is knowledge, it doesn't require any vast sums of money or plots of land, any guy with a day job who isn't an idiot, could learn to produce malware given enough time.

To stop this you'd have to institute heavier censorship of information concerning software development, however this would slash the industry by dramatically reducing headcount, or adopt a no local computation policy, and prohibit ownership of any local electronic computational device, instead everyone would have communication devices that talk to a centralised and controlled computation infastructure, much like the terminal-> mainframe architecture of the 70's, only without the freedom of unix, instead it would be impossible to develop software directly, you would write source code, and then submit it to a regulatory authority, like the apple store method.

Also just to be clear I'm not condoning or vouching for anything here, I just think its necessary to point that its probably easier to apply the argument to a physical commodity than a virtual one. As after all, its probably already too late for the local computation policy, as such devices are already omnipresent, so in order to implement such a policy would be incredibly impractical as in order to eliminate local, and therefore unregulated, computation you would have to collect all of those devices.
>>
>>54441998
I hate to break your hypothetical but general computing is pretty much out of the bag and any country that tries to restrict it will find a stagnating and crashing and burning economy in their future.
>>
File: 00 - the fool.jpg (41 KB, 401x579) Image search: [Google]
00 - the fool.jpg
41 KB, 401x579
>>54426857
>Haha why do people us antivirus software haha how dumb do you have to be to ge infected haha
>>
>>54442028

Not at all, that's pretty much what I was trying to say in second para, meaning might have got muddled as I went >2000 and had to audit
>>
>>54428251
Why don't you use freenas and have at least daily snapshots?
>>
>>54441140
>not having unexposed versioning or backups on your NAS
>>
>>54426857
Can you link me to the file that you opened that was ransomeware
Thread replies: 240
Thread images: 24

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.