Author Topic: Ransomware virus, help please  (Read 5621 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: Ransomware virus, help please
« Reply #15 on: August 05, 2016, 01:13:46 AM »
Hi Eddy,

that's exactly what I'm doing (restarting from scratch).
I wanted to know if Avast  would take a look at the virus (which is the worst one I met in the last 20 years probably, I remember in total not more than 5, but none as destructive as this one) and add it to the virus definitions.
I thought that reporting it they would contact me, at least for further details.
It puzzles me the lack of any feedback.
Probably I just don't realize how many viruses are reported every day.
This is a really bad one, though, and defeated Avast totally, so they should be interested in it.

I also hope one day I may recover my encrypted files (which I made a backup of), but that looks hopeless if the virus is not even acknowledged...   

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Ransomware virus, help please
« Reply #16 on: August 05, 2016, 10:02:00 AM »
Let's see if I can respond without writing a entire book ;D
Quote
that's exactly what I'm doing (restarting from scratch).
I hope you do it the correct way.
- Disconnect from the net (pull the plug out)
- Install Windows
- Install all drivers (or at least make sure they all are installed correctly if Windows provides them)
- Install a av
- Go online and download/install all updates that are available for Windows and the av (if it doesn't happen automatically already)
The following are user specific/users choice, but I recommend to do them :
- "Tweak" Windows to your needs/how you want (settings, colors and such things)
- Install the applications you normally use and make changes to the settings as you wish.
- Place back the data that you need/want from a clean backup
- Install a tool that automatically creates a backup of date/the entire system (as you want) on a regular base.
- Create a image of the drive

Create/store the backup online.
Why?
Guess what will happen if the house burns down or if there is a burglary (hope it will never happen ofcourse).
In such cases gone is not only the system, but also the backup if it is stored/kept in the same house.

Quote
I wanted to know if Avast  would take a look at the virus
avast does have a look at what someone submitted.
I can be wrong here, but I believe first analysis is done automatically and if needed a person is having another look at it.
This has to do with the huge amount of samples people sent to them each day.
On a quiet day, 350.000 new (or variants of existing) malware is found.
Analyzing them all manually would take the amount of people that live in a small country ;D
Quote
I thought that reporting it they would contact me, at least for further details.
As I said, they will contact you if they need/want more information.
Quote
It puzzles me the lack of any feedback.
I agree this a point for them to improve.
A automated email with something like :
- We have received your sample (on date, filename, hash)
- First analysis will be done automatically.
- If needed a person will have a further look at it.
- We will not contact you about this unless we need/want more information
- If the sample is found to contain new (or a new variant of existing) malware, we will add detection for it to the VPS
Quote
so they should be interested in it
They sure are interested in it.
Hence why they have the option to submit a sample ;) ;D

I do not know how far they are with the development of it, but avast is working on a tool/module for the av that detects/prevents infections with ransomware.
But it is not easy to create one without unwanted side-effects.
There are tools (Windows has it build in) that can encrypt date/entire drive content.
To say it simple, those tools do exactly the same as the ransomware does.
Difference is ofcourse that you have the key to decrypt the files.
So a tool to prevent ransomware must not detect those legitimate file/drive encryption tools.

As for the decryption of your files, keep a eye on https://www.nomoreransom.org
The keys they have there come from confiscated servers/systems from people that are behind the ransomware.
More keys will be added when they find them.
To be honest, chance that they find the key you need is small.
Have a deep breath and consider the files gone.
Learn the lesion (I think you already have) and backup frequently.

Don't forget there is always the malware first.
After being discovered, research must be done to see how it operates.
And only then it is possible to go find a protection/cure.
Meaning all new malware can (and likely will) do damage before it is stopped.

REDACTED

  • Guest
Re: Ransomware virus, help please
« Reply #17 on: August 06, 2016, 12:07:54 AM »
Hi Eddy,

thanks so much for the good advices and suggestions.
I didn't know and never could think so many malware (350K) could ever be developed everyday.
If these are official numbers, it means there's a sort of industry behind.
It's quite scaring.

About re-installing windows, that's exactly the way I would do that.

About making a regular backup: that's a bit more troublesome, but definetely I should start to do it on a regular basis.
Most of the encrypted files were already backed up or I could gather them together again from other machines (even at work).
What annoys me is the fact that I'm never sure they were all, and every now and then something I need and couldn't find  will pop up as one of the lost files.

Making a regular back up requires discipline and quite big backup HDs  :-\
Anyway I think this time I learned the lesson and I will find one of those free apps to make incremental backups.
All I need then is the patience to use it  ::)

About improving the Avast virus acknowledge service: surely they can make it better and at least send back an automatic feedback, but it's probably me not realizing they cannot simply track every single report.

Thanks for telling me about the keys: I didn't know they had key lists.
I'll try and see if mine could be on https://www.nomoreransom.org.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37582
  • Not a avast user
Re: Ransomware virus, help please
« Reply #18 on: August 06, 2016, 12:38:06 AM »
Quote
I didn't know and never could think so many malware (350K) could ever be developed everyday.
Statistic  >  https://www.av-test.org/en/statistics/malware/

TrendMicro blog > http://blog.trendmicro.com/malware-1-million-new-threats-emerging-daily/

Info about what F-Secure cloud handle on a a day (2015)
Quote
SECURITY CLOUD METRICS
Security Cloud is a high-volume system.
It is a critical component for most computers protected by F-Secure’s technology.

Number of queries per day received by Security Cloud’s servers About 5 billion per day (mid 2015)
Number of unique samples received per day by Security Cloud About 1 000 000 (mid 2015)
Average number of items (files and URLs) checked per day by a client’s local
Security Cloud module
About 28 000 per day on average


Quote
If these are official numbers, it means there's a sort of industry behind.
Just google > malware industry and you find a ton of info