Results 1 to 9 of 9

Thread: New Fantom Ransomeware uses Windows Updates

  1. #1
    Banned

    Join Date
    Jan 2008
    Location
    Under the Boardwalk AC USA
    Posts
    2,119
    Thanks
    1,471
    Thanked 3,031 Times in 777 Posts
    Rep Power
    0
    Reputation
    54367

    Default New Fantom Ransomeware uses Windows Updates

    "The Fantom Ransomware uses an interesting feature of displaying a fake Windows Update screen that pretends Windows is installing a new critical update."




  2. The Following 6 Users Say Thank You to cmangle For This Useful Post:

    CrYpto (02-09-16),mickstv (01-09-16),OSIRUS (31-08-16),pheggie (09-10-16),Tiny (01-09-16),tristen (31-08-16)



Look Here ->
  • #2
    LSemmens
    lsemmens's Avatar
    Join Date
    Dec 2011
    Location
    Rural South OZ
    Posts
    10,609
    Thanks
    11,886
    Thanked 7,073 Times in 3,346 Posts
    Rep Power
    3159
    Reputation
    132832

    Default

    Interesting thing, though, if they encrypt your machine, how are you supposed to e-mail them?
    I'm out of my mind, but feel free to leave a message...

  • The Following 2 Users Say Thank You to lsemmens For This Useful Post:

    cmangle (31-08-16),Rick (31-08-16)

  • #3
    Premium Member
    hoe's Avatar
    Join Date
    Jan 2008
    Age
    60
    Posts
    6,371
    Thanks
    266
    Thanked 4,599 Times in 1,950 Posts
    Rep Power
    1822
    Reputation
    70588

    Default

    It only encrypts certain file extensions. .doc/.xlx/.jpg etc....

    Sent from my SM-G935F using Tapatalk

  • The Following 2 Users Say Thank You to hoe For This Useful Post:

    cmangle (31-08-16),pheggie (09-10-16)

  • 31-08-16, 09:38 PM

    Reason
    do not make irrelevant posts so you can send PM

  • #4
    LSemmens
    lsemmens's Avatar
    Join Date
    Dec 2011
    Location
    Rural South OZ
    Posts
    10,609
    Thanks
    11,886
    Thanked 7,073 Times in 3,346 Posts
    Rep Power
    3159
    Reputation
    132832

    Default

    There's a bloody great long list of them so I'd be surprised if it worked. Here's a thought, if it only encrypts certain extensions a good way of protecting your files would be to change the extensions to one that is not on the list. It might be a nuisance when you need access to said files.....but.
    I'm out of my mind, but feel free to leave a message...

  • #5
    Senior Member
    mickstv's Avatar
    Join Date
    Jan 2010
    Age
    51
    Posts
    4,173
    Thanks
    2,225
    Thanked 2,404 Times in 1,392 Posts
    Rep Power
    681
    Reputation
    18426

    Default

    Found a program some time back that may provide protection from this type of malicious crap, it's called sandboxie.

    Thought I would post a link to the sandboxie site, if anyone is interested.


  • The Following 4 Users Say Thank You to mickstv For This Useful Post:

    mtv (01-09-16),pheggie (09-10-16),Tiny (02-09-16),tristen (02-09-16)

  • #6
    Administrator

    Join Date
    Jan 2008
    Location
    Newcastle, Nsw
    Posts
    4,604
    Thanks
    815
    Thanked 2,531 Times in 1,138 Posts
    Rep Power
    1179
    Reputation
    41376

    Default

    I use Sandboxie all the time, it comes in handy when you want to use a keygen but aren't sure if it has a virus or you're just getting a false positive.
    Also I sometimes run my browser in a sandbox to see what dodgy websites like to dump onto computers.

  • The Following 3 Users Say Thank You to WhiteOx For This Useful Post:

    mtv (02-09-16),peter3535 (02-09-16),tristen (02-09-16)

  • #7
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    they are real nasty these things
    virus's have nothing on them
    normally you can recover files, format & virus gone in 2 hrs or so

    a lot of av's have protection now, they say
    < free
    https://www.facebook.com/philquad68

  • #8
    Banned

    Join Date
    Jan 2008
    Location
    Under the Boardwalk AC USA
    Posts
    2,119
    Thanks
    1,471
    Thanked 3,031 Times in 777 Posts
    Rep Power
    0
    Reputation
    54367

    Default

    Malwarebytes entry into the Anti-Ransomeware arena!




  • #9
    Banned

    Join Date
    Jan 2008
    Location
    Under the Boardwalk AC USA
    Posts
    2,119
    Thanks
    1,471
    Thanked 3,031 Times in 777 Posts
    Rep Power
    0
    Reputation
    54367

    Default

    From Malwarebytes, "It is important to note that this program is still currently in a beta stage, which means bugs will occur during its use. Even though the program has been proven to work against almost all ransomware that has been thrown at it including Cryptowall, TeslaCrypt, and CTB-Locker, bugs may occur that allow something to slip through."
    Last edited by cmangle; 02-09-16 at 09:28 PM.

  • The Following User Says Thank You to cmangle For This Useful Post:

    allover (02-09-16)

  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •