New Ransomware unlocks files after you read 2 CyberSecurity articles

Parsh

Level 25
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
After the progressively engineered ransomware Popcorn, this one has come to the attention of security experts.
This RW called Koolova, will encrypt user files as usual, but demands from him to read atleast 2 articles of CyberSecurity. This way they can get the decryption key.
Discoverers say it's not professionally coded and a work in progress.
Here's the catch - it acts like the Jigsaw and runs countdown before destroying all the files once and for all.

A backdoor educator I must say. Read about it here.
 

Svoll

Level 13
Verified
Top Poster
Well-known
Nov 17, 2016
627
That is a tough decision to make let alone recommending someone a anti-ransomware.

Ransomware is ever changing and evolving, it depends on how each vendor reacts and updates their app.

At the moment I am using Norton with Sonar and Malwarebytes anti-ransomware.
 

Parsh

Level 25
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
That is a tough decision to make let alone recommending someone a anti-ransomware.

Ransomware is ever changing and evolving, it depends on how each vendor reacts and updates their app.
Certainly it is!
HitmanPro.Alert misses a ransomware when it was expected to deal with that kind of ransomware-family. Many such stories.
My only purpose behind the poll is to know if there are some anti-ransomware from the list that people have found effective, or even the popularity can be derived otherwise :)
 

Svoll

Level 13
Verified
Top Poster
Well-known
Nov 17, 2016
627
Certainly it is!
HitmanPro.Alert misses a ransomware when it was expected to deal with that kind of ransomware-family. Many such stories.
My only purpose behind the poll is to know if there are some anti-ransomware from the list that people have found effective, or even the popularity can be derived otherwise :)

You know what @Parsh I would highly recommend @frogboy method, Backups! eventho it doesn't fall under the anti-ransomware category but it is one if not the best method to stop ransomware.
 

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,714
Certainly it is!
HitmanPro.Alert misses a ransomware when it was expected to deal with that kind of ransomware-family. Many such stories.
My only purpose behind the poll is to know if there are some anti-ransomware from the list that people have found effective, or even the popularity can be derived otherwise :)
The difference between HitmanPro.Alert and some others anti-ransomware software is that HitmanPro.Alert doesn't just deal with ransomware but exploits.
 

Parsh

Level 25
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
You know what @Parsh I would highly recommend @frogboy method, Backups! eventho it doesn't fall under the anti-ransomware category but it is one if not the best method to stop ransomware.
Cannot agree less. Backups can save us like nothing else, if implemented well with control on versions.
I had read about this scary new dimension of ransomware. We need to protect our backup drives too!

The difference between HitmanPro.Alert and some others anti-ransomware software is that HitmanPro.Alert doesn't just deal with ransomware but exploits.
true. However I have seen many users bet on HMPA for a good anti-ransom protection as it claims to be one. So I thought it's worth mentioning.
 
Last edited by a moderator:

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
Pretty tricky. Zemana with Pandora enabled gets the job done. Tried out HMP.Alert, MBARW, and KasperskyAntiRansome and they all seemed pretty good. No idea if Avast in operated anything in their AV but I love their protection. :)
 

Quassar

Level 12
Verified
Well-known
Feb 10, 2012
585
No need more folkrs of Antivirus or antimalware antispyware.... etc.
You have finaly realize to get SRP and good HIPS start limit app/accounts
No more molest them by copule behavior engines & scanners... its not help.
 

bunchuu

Level 8
Verified
Well-known
Mar 17, 2015
370
No need more folkrs of Antivirus or antimalware antispyware.... etc.
You have finaly realize to get SRP and good HIPS start limit app/accounts
No more molest them by copule behavior engines & scanners... its not help.
from what I learned before, tools like cryptoprevent or bitdefender anti ransomware has core function just like SRP and folder protection. They basically restricted (white list) certain software to modifiy their file especially document folders.
 

nclr11111

Level 6
Verified
Well-known
Feb 25, 2011
277
I actually have no answer to the question asked but put my faith in the combo of: Comodo Firewall with autosandbox, Appcheck and MBRfilter against ransomware!
Never had a ransomware, except in closed virtual environment for testing, and hopefully never will!
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Based on numerous test, WinAntiRansom is a very good tool to recommend although quite expensive on the license, so an alternative can be Kaspersky because of cloud and generic detection.

As long the product can protect within 90% mark then users should not worry about.

------------

In that ransomware strain, well it's interesting although the damage exist regardless if the condition does not involve a Fee.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top