Are All AV's Vulnerable to Encryption Virus?

Discussion in 'other anti-virus software' started by jjc225, May 5, 2016.

  1. boredog

    boredog Registered Member

    https://decrypter.emsisoft.com
    That is a decryptor for autolocky, which is a copy cat of the real locky.

    AutoLocky is a new ransomware written in the popular scripting language AutoIt. It tries to imitate the complex and sophisticated Locky ransomware, but is nowhere near as complex and sophisticated, which makes decryption feasible.

    Victims of AutoLocky will find their files encrypted and renamed to *.locky. Unlike the real Locky ransomware however, AutoLocky will not change the base name of the file. So if a file named picture.jpg is encrypted, AutoLocky will rename it to picture.jpg.locky while the actual Locky ransomware will change it to a random name. In addition victims will find a ransom note on their Desktop with the file name info.txt or info.html.
     
  2. boredog

    boredog Registered Member

  3. boredog

    boredog Registered Member

    ScreenHunter_12 May. 07 13.43.jpg Here is a screen shot
     
  4. Moose World

    Moose World Registered Member

    Salutations/Greetings!

    I guess the real is how to protection the files/documents from being encrypted? And which files/documents ect...
    will be encrypted? And the complete removal of various-es ransomware? Maybe using encryption of itself but stronger?
    With all the above!

    Any thoughts?
     
  5. NormanF

    NormanF Registered Member

    Install Secure Folders/Privacy Fence and make your folders containing your documents read-only.

    Ransomware can encrypt all but operating system files.... malware authors don't want to render a computer unbootable - they only want files on it held hostage they can release back to a victim for a fee, of course!

    The best way is prevention by backing up data offline and to secure sites in the cloud. And never ever open an attachment from someone you don't know. When in doubt, delete, delete, delete!
     
  6. digmor crusher

    digmor crusher Registered Member

    I would think that Emsisoft Antimalware would do quite well because of its behavior blocker.
     
  7. Marcos

    Marcos Eset Staff Account

    Not only. Also ESET provides very good protection against file cryptors as long as you use the latest version of ESET Smart / Endpoint Security and have LiveGrid enabled and working.
     
  8. taleblou

    taleblou Registered Member

    check in here and there are several anti-ransomeware or fix videos that may help you. Videos made by a computer expert

    https://www.youtube.com/user/Britec09/videos
     
  9. taleblou

    taleblou Registered Member

    Also try secureaplus plus AV and in the locking mode as it protects against ransomwares.
     
  10. hawki

    hawki Registered Member

    For protection against ransomeware, in addition to those mentioned above:

    Bitdefender Products, 21015 and later, have an anti-ransomeware feature that is supposed to prevent ransomeware from encrypting files. There is a default set of protected files and you can ad others.

    No one mentions HitmanPro Alert?

    Did you try to remove the ransomeware and try a System Restore , Recover Files, Shadow Copies?
     
  11. erikloman

    erikloman Developer

    I am also surprised by the fact dat no one mentioned HitmanPro.Alert in this thread. It is the first anti-crypto-ransomware solution, since 2013: https://www.wilderssecurity.com/thre...discussion-thread.324841/page-32#post-2301675

    I admit we haven't really marketed HMPA, but I would have expected most Wilders members would know we have this feature for a long time.
     
  12. itman

    itman Registered Member

  13. ttomm1946

    ttomm1946 Registered Member

    My Own dumb question..If i got ransome ware would re installing win 10 work?
     
  14. ttomm1946

    ttomm1946 Registered Member

    i just mostly keep games that i can re-down:geek:
     
  15. IvoShoen

    IvoShoen Registered Member

    I also prefer to use Zemana AntiMalware Premium along with my other security apps.
     

    Attached Files:

    • ZAM.jpg
      ZAM.jpg
      File size:
      157.5 KB
      Views:
      17
  16. Amanda

    Amanda Registered Member

    I wouldn't trust an Antivirus for more than basic virus scanning, be it paid or free. If doubts arise, VirusTotal is a very good tool.

    While working on Windows, I Sandboxed pretty much every program, specially LibreOffice and Firefox (both ran as "Limited" on COMODO), so any changes would not be permanent. HIPS was on Safe Mode, and Firewall on Custom Ruleset with Very High prompts (meaning every new change was prompted for confirmation). I also used EMET (W7, not necessary for 10) and a limited account on a day-to-day basis.
     
  17. daman1

    daman1 Registered Member

  18. boredog

    boredog Registered Member

    "I had McAfee LiveSafe and Zemana Antimalware."

    your missing the point. it was not just mccrappy that screwed up but zemana also.

    I had the same thing happen with powerlics. Norton said it found something , cleaned it but it just came back.

    offline with out auto mode set it good. or at least use a program where backups are not just added on to existing one but separate and by date.
     
  19. Triple Helix

    Triple Helix Specialist

    The Topic!
    Are All AV's Vulnerable to Encryption Virus?
    I would say no the AV's are safe but executing unknown files in emails from people you don't know well that's the problem, Security is more than your AV, AM you have to use the thing between your ears and education is the best defense IMO.

    Daniel
     
  20. ProTruckDriver

    ProTruckDriver Registered Member

    The importance of "Backup your files" ;)
     
  21. boredog

    boredog Registered Member

    newest bitdefender added anti-ransomeware added another one. petya
     

    Attached Files:

  22. itman

    itman Registered Member

    Ransonware is rapidly evolving. As such, latest strains are employing advanced infection methods also increasingly being used by the latest non-ransomware malware; namely using the OS against itself as noted here:

    Ref.: http://www.csoonline.com/article/3095956/data-breach/the-history-of-ransomware.html
    As such, a security solution with behavior or HIPS capability to monitor API and system process usage and be able to differentiate adverse malware from valid system behavior is the only way to stop these recent and future ransomware.

     
  23. boredog

    boredog Registered Member

    nice article itman

    wonder what was meant by "In 2016, TeslaCrypt authors gave up their master decryption key to ESET."
     
  24. itman

    itman Registered Member

  25. boredog

    boredog Registered Member

    that is nice eset didn't have to even pay for it :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice