Windows 10: Bad Rabbit ransomware: A new variant of Petya is spreading

Discus and support Bad Rabbit ransomware: A new variant of Petya is spreading in Windows 10 News to solve the problem; Bad Rabbit, a ransomware infection thought to be a new variant of Petya, has apparently hit a number of organisations in Russia and Ukraine. In a... Discussion in 'Windows 10 News' started by Brink, Oct 24, 2017.

  1. Brink
    Brink New Member

    Bad Rabbit ransomware: A new variant of Petya is spreading


    Read more: Bad Rabbit ransomware: A new variant of Petya is spreading, warn researchers | ZDNet

    :)
     
    Brink, Oct 24, 2017
    #1
  2. Mitjah Win User

    Ransomeware

    According to
    bleepingcomputer.com
    petya ransomware can affects only MBR.
     
    Mitjah, Oct 24, 2017
    #2
  3. Petya/Goldeneye ransomware

    Hi JM,

    There are three specific steps you can take to mitigate against this new ransomware:

    • Ensure you have the latest security updates installed.
    • Ensure you have the latest AV Signatures from your preferred AV vendor.
    • Do not open email/attachments from unknown/untrusted sources

    For more information about how the Petya Ransomware works and how to protect your computers against it, please check out this Windows Security blog:

    New ransomware, old techniques: Petya adds worm capabilities
    .

    Feel free to let us know if you need further information.

    Regards.
     
    Vanessa Yar, Oct 24, 2017
    #3
  4. Bad Rabbit ransomware: A new variant of Petya is spreading

    Thanks for the Heads Up Shawn *Thumbs
     
    Josey Wales, Oct 24, 2017
    #4
  5. sygnus21 Win User
    Hmmm.... we get a hacked in executive, they get a locked out media. Hardly seems fair.
     
    sygnus21, Oct 24, 2017
    #5
  6. copyer Win User
    Hi, maby stupid question, but lets say i have 3 hd in my computer, wil it encrypt all hd or just the c:/ one? and in my kodi network i have also some hd connected wil they be affected too?
     
    copyer, Oct 24, 2017
    #6
  7. linw Win User
    Most of these ransomeware attacks go for every disk on the network.
     
  8. Bad Rabbit ransomware: A new variant of Petya is spreading

    This ransomware is really original, it pretends to be a flash installer, but it still works, so whatever.

    Avoiding this one is a child's game for any administrator/user.

    1. Use SUA or UAC with a password, doh.

    2. Enable ValidateAdminCodeSignatures.


    Bad Rabbit ransomware - Securelist

    Bad Rabbit Ransomware Outbreak in Russia and Ukraine | Anomali
     
    TairikuOkami, Oct 24, 2017
    #8
  9. cereberus Win User
    Of course guys, make regular image backups, and store offline.
     
    cereberus, Oct 24, 2017
    #9
  10. So this would even go for the standalone NAS drives in my network ? I’ve got three thinking my pics / docs etc are pretty safe being backed up/mirrored in triplicate (I don’t really like cloud services) Guess I should disconnect one from the network.

    presumably if our windows is up to date and defender is on with latest definitions we are protected ?
     
    Scottyboy99, Oct 24, 2017
    #10
  11. Borg 386 Win User
    Bad Rabbit: Ten things you need to know about the latest ransomware outbreak

    Bad Rabbit: Ten things you need to know about the latest ransomware outbreak | ZDNet

     
    Borg 386, Oct 24, 2017
    #11
  12. Steve C Win User
    What's the significance of Enable ValidateAdminCodeSignatures and does using it create other installation issues?
     
    Steve C, Oct 25, 2017
    #12
  13. Bad Rabbit ransomware: A new variant of Petya is spreading

    Exe has to be digitally signed, only less used apps do not have a certificate, it costs a lot of money. But you can still run them, just not with admin rights, most do not need them anyway. You can check properties for a certificate, if it does not have one, you will get an error. I have created a script to turn it on/off, when need and shortcuts like this.


    Code: reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "ValidateAdminCodeSignatures" /t REG_DWORD /d "0" /f start "" "E:\Software\Windows_Repair_Toolbox.lnk" reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "ValidateAdminCodeSignatures" /t REG_DWORD /d "1" /f[/quote]
     
    TairikuOkami, Oct 25, 2017
    #13
  14. ThrashZone, Oct 25, 2017
    #14
  15. essenbe Win User
    Mike, my guess would be that not everyone has switched over to the new standard. If they did away with flash right now, too much content would be unavailable. I think it is on it's way out though. It just may take more time.
     
    essenbe, Oct 25, 2017
    #15
Thema:

Bad Rabbit ransomware: A new variant of Petya is spreading

Loading...
  1. Bad Rabbit ransomware: A new variant of Petya is spreading - Similar Threads - Bad Rabbit ransomware

  2. .VYIA files Ransomware Attack Variant

    in AntiVirus, Firewalls and System Security
    .VYIA files Ransomware Attack Variant: So, basically I downloaded a virus, and most of my files became .VYIA files. I tried OneDrive backup, but it also backups the .VYIA files. I don't know how to access the previous things that I saved. Neither does version history help. I can't do anything at this point. It's...
  3. New Variant for STOP ransomware with a different extension of .igvm?

    in AntiVirus, Firewalls and System Security
    New Variant for STOP ransomware with a different extension of .igvm?: Split from this thread.i got the same problem with a different extension of .igvm wahat shoul i do???????? https://answers.microsoft.com/en-us/protect/forum/all/new-variant-for-stop-ransomware-with-a-different/a1217aa4-70cd-4428-bb9c-210f636ae6a6
  4. New Variant for STOP ransomware?

    in AntiVirus, Firewalls and System Security
    New Variant for STOP ransomware?: Split from this thread.i got the same problem with a different extension of .igvm wahat shoul i do???????? https://answers.microsoft.com/en-us/protect/forum/all/new-variant-for-stop-ransomware/a1217aa4-70cd-4428-bb9c-210f636ae6a6
  5. New global ransomware attack hits East Europe and spreading

    in AntiVirus, Firewalls and System Security
    New global ransomware attack hits East Europe and spreading: Another massive attack is going on at the moment. It started in Ukraine and Russia and is already all over Europe and US too. Bitdefender Labs confirms that the GoldenEye / Petya ransomware leverages the EternalBlue exploit to spread from one computer to another....
  6. Petya ransomware encryption system cracked

    in AntiVirus, Firewalls and System Security
    Petya ransomware encryption system cracked: Petya ransomware victims can now unlock infected computers without paying. An unidentified programmer has produced a tool that exploits shortfalls in the way the malware encrypts a file that allows Windows to start up. In notes put on code-sharing site Github, he said...
  7. Warning: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa

    in AntiVirus, Firewalls and System Security
    Warning: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa: Warning: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa [img] See also here: Warning: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa 50418
  8. The Petya ransomware just got a whole lot worse

    in AntiVirus, Firewalls and System Security
    The Petya ransomware just got a whole lot worse: Make back ups before it strikes..... The Petya ransomware now bundles a second file-encrypting program for cases where it cannot replace a computer's master boot record to encrypt its file table. Before encrypting the MFT, Petya replaces the computer's master boot...
  9. Rabbit Hole

    in Windows 10 Performance & Maintenance
    Rabbit Hole: I feel like Alice falling down the rabbit hole as I am researching information in the quest to fix/improve my laptop since deciding to go into the Insider Program. I am, for the most part, learning many aspects that I need and want to know, however, if seems too many...
  10. Warning: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa

    in Windows 10 News
    Warning: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa: Latest Petya Ransomware Strain Comes with a Failsafe: Mischa [img] Warning: The Petya ransomware strain signaled a new escalation for crypto-malware when it surfaced in March. For the first time, ransomware went beyond encrypting files on local and shared drives...