![]() |
|
#1
|
||||
|
||||
|
Quote:
full story |
|
#2
|
||||
|
||||
|
Hardly call this new, but ok.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#3
|
||||
|
||||
|
Quote:
but as to their analyzing, i guess it's just skiddie worm...first it supports old version of windows not latest ones(like vista or seven) second its way of propagation seems like simple third, password long but only numbers ..which makes it more easily be bruteforced the only thing i find interesting is "locking documents" as it's new symptom for me but i was wondering, if file was set to "read only" does it have the ability to lock it? or thats impossible ? |
|
#4
|
||||
|
||||
|
Searching ransom @ MMPC reveals a few of many types of variants that do this. For example, the search failed to bring up this from 2009: https://www.microsoft.com/security/p...Win32/Gpcode.H
It is very scary indeed ![]()
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#5
|
||||
|
||||
|
Quote:
ooh...thanks alot for the info and links...actually never heard them before so that worm has nothing new at all...then i am wondering why great company like panda would take this seriously btw, do you know a good source to get samples of ransom trojans? or if you can pm me with links Thanks in advance |
|
#6
|
|||
|
|||
|
From the article:
Quote:
|
|
#7
|
||||
|
||||
|
Quote:
One would hope that AV companies take all malware threats seriously ^^ But if you want my opinion of it, AV companies sometimes like to race to be "first" to document a new threat. This generally increases sales/awareness of product as the articles are technically advertising the product company writing it. If you want to go further there are sometimes users that actively switch AV product because they are told AV product X detects new threat Y, but I don't think that's a very common thing.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#8
|
||||
|
||||
|
Quote:
very true, maybe they dont like but they have to ![]() PS : i havent tried panda for long time, panda can fix this infection, i mean delete the password from infected files? anyone have an idea? |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|