Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Sunday, September 27, 2015

Cryptowall is back on the prowl, so watch your back...


Back in 2014, a nasty virus called "Cryptowall" reared its unsightly head in the computer world, and it proceeded to leave a fair deal of pandemonium in its wake.
Of course once antivirus definitions the world over became aware, the threat was largely eradicated and peace reigned in the Kingdom of CPU.

These things are like a bad rash though, and there has of late been a resurgence of this particular bad boy on PC's all over the place.
Hell, Carte Blanche even featured an article on the virus a few weeks back - I'm sure the wonderfully talented humans who coded it must be awfully proud! Well done guys! 

Anyway, back to the post - in short, watch your back as you normally would when dealing with the internet, email, flash drives from other PC's, pretty much as you would do when walking down a dark alley at night.
This particular threat entices the hapless victim by means of links on dodgy sites, links within the attachments of spam mails and a variety of other sneaky tactics.
Once the user clicks on the link, if not stopped by an antivirus, the virus will then initiate and continue to install itself in memory, and as a startup item on the infected PC.

Symptoms of Cryptowall (how you know that you are infected...):

  • Cryptowall scans the PC for folders which contain your meaningful data - here we are talking about the Desktop folder, My Documents etc.
    It also scans mapped network drives - these will become infected as well, but only specifically mapped drives.

  • Next, it encrypts every "work" file that it finds - this includes Word documents, Excel documents and PDF documents, among others.

  • Finally, it dumps approx. 4 files into every folder that it has encrypted, named "HELP_DECRYPT.ext" - each of these files provides instructions on how to decrypt your data, and it's pretty simple - pay up. Yup, all this virus amounts to is extortion.
    The variation of the infection that I recently dealt with wanted payment in Bitcoins, but I'm sure they take Diners Club, AMEX, VISA and many other forms of payment too :)

  • Any attempt to now open an encrypted file will result in a generic program error, as if the data within the file is corrupted.
    At this point, panic may set in.
    This is justified, since there is no way to decrypt the files without paying up, unless you have a recent intact backup of your files. Do not plug your backup drive in, until you are 100% sure that your PC is clean again.
    For a very technical rundown of the threat, including cleaning and recovery options, check out:
    http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information
You DO NOT want to see these files on your hard drive...
So in essence it's a pretty simple virus, but the impact that it can have on a business with a lot of data is HUGE.
After going through a rough few days taking one of these bad boys down recently, my advice to end users is simple - protect yourself in every possible way, and that isn't limited to antivirus software.
Sure, getting yourself a great antivirus like Avast is a non-negotiable, however always tread carefully when making use of a public domain like the internet.

Watch where you browse. 
Triple check who sent you that not-so-kosher looking email.
Don't click on that link in the body of a "banking" email, and if you do end up being on the very unfortunate receiving end of one of these, make sure that your data is backed up somewhere off your PC - preferably on an external drive.

Thursday, April 22, 2010

OMG THE OLYMPIC TORCH VIRUS... is a frikkin hoax. So please stop sending it to EVERYONE YOU KNOW!!!

If I receive one more email warning me about the so-called "Olympic Torch" virus, or the "Black in the White House" virus, which miraculously "burns" your whole hard drive, and "destroys zero sector, where vital information is kept", I will personally track down the sender of the email and make them eat their computer.

How many times must this ridiculous hoax circulate and waste our time and bandwidth?
I suppose Joe Public is just being cautious, but I get tired of informing Joe Public that this threat is actually very much non-existent.

As a guideline, if you receive an email which warns of some impending Armageddon Virus which will erase your children, it will most likely try to use some big computer / company names (eg. Microsoft, Mcafee, Symantec, CNN etc.) to back up the outrageous claims that it is making...

Still don't believe me? Snopes it here:

http://www.snopes.com/computer/virus/invitation.asp

If you are still not sure, please comment on this post and I will check it out for you.

Tuesday, February 23, 2010

How to get infected while browsing the internet... a DIY guide!

Despite the presence of antivirus software, firewalls and anti-spam software, many people still fall for the sneaky tricks of virus-spreaders online all the time.
Avast - my antivirus software of choice (and it's free!)
AVG - another decent free antivirus program

One of the tricks I have come across of late happens when the webpage that loads, looks exactly like a Windows Explorer window, which (apparently) shows your hard drives, DVD Drives etc.
A fake "scan" then runs on top of this window and alleges that you are infected by millions of viruses and spyware.
The entire "scan" window is a giant hotspot, and at the end of the "scan" you are encouraged to click a link to fix the problem.
If the link is clicked, you then open yourself up to an actual threat, possibly a downloaded script, dodgy website or some other malicious means of infecting your PC.
Nicely done, you fiendish skanks...!

How to get your self into a fix... buying into this nonsense is a great way to get started!

So in order to get you to click on their dodgy links, they first play on the paranoia of being infected.
Once they have convinced the gullible user that they are in fact in some kind of grave danger, the paranoia then drives the user to click anything that promises to make it all better.

So what to do if you think this may have happened to you?
Well if you went ahead and clicked the link, you will no doubt know if you have been infected because you are probably being bombarded by a message along the lines of "Your system is being infecting by serious bad virus", or some other similarly dodgy message.

A key giveaway here is the unusual / incorrect usage / incorrect spelling of the English language - antivirus companies like to uphold a professional image and appearance, by using well constructed sentences, perfect spelling, and by following the general rules of a language.
Virus creators on the other hand, despite their allegedly massive levels of intelligence, cannot seem to grasp the very basics of how one puts a proper sentence together. Spelling too, it seems is beyond their primitive level of understanding.

If you are infected, get yourself a free copy of Avast or AVG fast...

Grab your inverter now and be prepared for Load Shedding!

Shop HP Printers here!

Low on ink? Shop Genuine HP Ink and Toner here!

Shop Targus laptop bags, USB hubs, accessories and gadgets here!

Popular Posts