Bitcoin Forum
May 08, 2024, 08:35:59 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: {Warning}: Fake 'Lost Files' Data Wiper Poses as a Windows Security Scanner  (Read 161 times)
Baofeng (OP)
Legendary
*
Offline Offline

Activity: 2590
Merit: 1658



View Profile
October 03, 2019, 10:55:03 PM
Merited by DdmrDdmr (1), dkbit98 (1)
 #1



Quote
A Windows Security Scanner that states it encrypted your files is being distributed by spam, but whether by bug or design, it instead corrupts binary data in a victim's files.

A few minutes later, it will show what appears to be a ransom screen from the Lost Files Ransomware. This screen tells you that you need to send $500 USD in bitcoins to the 13nRGetwvc7UZF8P5KM9bWqHGK6tMk7wyf bitcoin address in order to decrypt your files.




https://www.bleepingcomputer.com/news/security/lost-files-data-wiper-poses-as-a-windows-security-scanner/

Just giving everyone a heads-up specially that the cyber criminals are asking for BTC here.

So far no one has fallen for this trick because it was detected early. Unlike WannaCry wherein it has amassed  thousands of dollars. So just be careful!!!

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
1715200559
Hero Member
*
Offline Offline

Posts: 1715200559

View Profile Personal Message (Offline)

Ignore
1715200559
Reply with quote  #2

1715200559
Report to moderator
The grue lurks in the darkest places of the earth. Its favorite diet is adventurers, but its insatiable appetite is tempered by its fear of light. No grue has ever been seen by the light of day, and few have survived its fearsome jaws to tell the tale.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715200559
Hero Member
*
Offline Offline

Posts: 1715200559

View Profile Personal Message (Offline)

Ignore
1715200559
Reply with quote  #2

1715200559
Report to moderator
1715200559
Hero Member
*
Offline Offline

Posts: 1715200559

View Profile Personal Message (Offline)

Ignore
1715200559
Reply with quote  #2

1715200559
Report to moderator
1715200559
Hero Member
*
Offline Offline

Posts: 1715200559

View Profile Personal Message (Offline)

Ignore
1715200559
Reply with quote  #2

1715200559
Report to moderator
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2310
Merit: 10759


There are lies, damned lies and statistics. MTwain


View Profile WWW
October 04, 2019, 06:11:29 AM
 #2

Sounds like the modern version of those scum lowlifes that call you pretending to be from Microsoft support, claiming that you have a "virrrusss" on your computer, which they will kindly remove after you give them remote access to install their removal tools.

All things said, one should never download and run any programs, less of all if it comes "proactively" via email. We should take the extra 5 or 10 minutes it takes to validate everything against the alleged original source (in this case Microsoft) to see if there is such a tool, and of there is, download it from there if (and only if) necessary.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5643


Blackjack.fun🎲


View Profile WWW
October 04, 2019, 12:36:49 PM
 #3

So far there is no payment to posted address, but that does not mean that no one has become a victim of this ransomware. The majority does not want or can not pay the requested amount, or they want to pay, but they don't understand how to do it with BTC.

The best protection from ransomware is a regular backup, but even better is to prevent something like that from happening. Always be careful what you download, use good antivirus/antimalware/firewall with updated definitions, to put it more simply lock the door of your device to prevent unwanted guests from visiting you.

Some security programs have ransomware protection (Malwarebytes Premium), the only question is how effective it is when the attack occurs.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
MichaelX
Newbie
*
Offline Offline

Activity: 27
Merit: 27


View Profile
October 04, 2019, 01:35:49 PM
 #4

This is a modern form of a social engineering attack.

They fool you into downloading and running the trojan by posing as some authority or someone you know or trust.

The prudent thing to do is open a new browser window and type in some of the words that appear, to search for them, and see if you come up with anything.

If you really need some sort of functionality, it is better you look for it yourself. A good data wiper would be something known like Eraser, or to wipe the drive would be DBAN.
MATHReX
Sr. Member
****
Offline Offline

Activity: 861
Merit: 281


View Profile
October 04, 2019, 07:39:14 PM
 #5

The only reason I have a virtual machine on my PC when I want to download some stuff to check.
That's the thing with anti-virus software, they won't protect us from human error. That's why it is so important to think thrice before opening even a file from an unknown source.
nakamura12
Hero Member
*****
Offline Offline

Activity: 2268
Merit: 669


Bitcoin Casino Est. 2013


View Profile
October 04, 2019, 09:03:31 PM
 #6

So far there is no payment to posted address, but that does not mean that no one has become a victim of this ransomware. The majority does not want or can not pay the requested amount, or they want to pay, but they don't understand how to do it with BTC.

The best protection from ransomware is a regular backup, but even better is to prevent something like that from happening. Always be careful what you download, use good antivirus/antimalware/firewall with updated definitions, to put it more simply lock the door of your device to prevent unwanted guests from visiting you.

Some security programs have ransomware protection (Malwarebytes Premium), the only question is how effective it is when the attack occurs.
It may be true that there are people who fell for this trick already that these criminals made. They may have change the bitcoin address shown in there to make it look like they haven't steal bitcoins from their victims. IMHO, some antivirus/antimalware doesn't protect your device that much especially the free ones. As you mentioned, you are not even sure about the protection even if it's premium.

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
Orange Mango
Member
**
Offline Offline

Activity: 130
Merit: 10


View Profile
October 04, 2019, 11:34:23 PM
 #7

This happens with many ant-virus, prizes, inheritance and many other things, forst they create panic and then they shorten the time you have to react so that you panic while trying to quickly make a decision because you are afraid of the consequences that you are being "warned about" you can tell that by the red clour they put around the message so it screams at you. When I read messages like this I just ignore them. Most are filtered.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5643


Blackjack.fun🎲


View Profile WWW
October 05, 2019, 10:48:01 AM
 #8

That's the thing with anti-virus software, they won't protect us from human error.

In fact, in most cases good AV which is regularly updated with the latest av/antimalware definitions and heuristic analysis can protect us from our own mistakes. 
That's exactly what security software is for, for prevention and not only for cleaning the operating system when it is infected with virus/malware.

Ransomware protection is work in way that such software is trying to disable access to the location where ransomware is first trying to encrypt user data. Another method is to create fake files, something like bait for ransomware, and if such files get changed in any way, security software will try to delete/quarantine ransomware.

Any kind of protection is better than none, but the paid solutions of reputable companies are my only choice when it comes to protecting my computer.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!