| Line 172: |
Line 172: |
| | | | |
| | How deep would I have to go? The NSA leaks on Windows zero-days make me concerned. I'd rather not lose twelve years of data. --[[User:Pious|Pious]] ([[User talk:Pious|talk]]) 23:39, 19 May 2017 (EDT) | | How deep would I have to go? The NSA leaks on Windows zero-days make me concerned. I'd rather not lose twelve years of data. --[[User:Pious|Pious]] ([[User talk:Pious|talk]]) 23:39, 19 May 2017 (EDT) |
| | + | |
| | + | |
| | + | ==Regarding Ransomware== |
| | + | I've been a bit out of the IT loop, but I can think of a few ideas for defeating it, at least on a Windows OS, in degrees of severity. |
| | + | :1. Booting from the OS installation DVD and going a few system restores back. |
| | + | :2. Reinstalling Windows. |
| | + | :3. The above, plus updating the BIOS. |
| | + | :4. The above, plus swapping out the CPU and motherboard physically. |
| | + | :5. The above, plus having all your information backed-up to an external hard drive or flash drive pre-infection. |
| | + | |
| | + | How deep would I have to go? The NSA leaks on Windows zero-days make me concerned. I'd rather not lose twelve years of data. --[[User:Pious|Pious]] ([[User talk:Pious|talk]]) 23:39, 19 May 2017 (EDT) |
| | + | |
| | + | :Sorry for the delayed response. You're certainly on the right track, but there are a few important factors to consider while following that line of reasoning. Since most ransomeware encrypts the entire drive, the OS disk does not see any system to run system restore on. Therefore, that is not an option. Actually, in my experience, system restore is almost always useless when dealing with malware, since the "bad guys" know all about it, and want to defeat it. Secondly, the CPU is just a calculator--it cannot be locked or corrupted. The only available attack on a processor which I know of is to force it to run far too many calculations so that it burns out. Regarding your points specifically, therefore: |
| | + | :# Not going to work, as explained. |
| | + | :# That should work fine--the attack is usually designed to lock data. If you reinstall the OS, there is not much they can do to stop you, in most cases. |
| | + | :#Updating the BIOS would only be needed if the BIOS has been corrupted. If it has, it may also have been somewhat protected against updating. However, the BIOS is generally not targeted, since it is different from one computer to another. While one kind can be attacked, scores of others will be safe. |
| | + | :#Replacing the CPU would be pointless, but replacing the board replaces the CMOS. That will remove the potentially infected BIOS from the equation. If the ransomware comes back, this is a good thing to try. |
| | + | :#Always a good idea! Back up all of your personal files, and keep the storage device disconnected from the PC at all other times. If you get infected while that drive is attached, it will probably be locked as well. |
| | + | :Something I like to do is to also take complete drive backup. This will take substantial external storage, but is a safe way to protect your files, settings, and perhaps most importantly, your software licenses. Take a system snapshot, then if the system is compromised, restore the image to the drive. This demolishes all data on the drive, and replaces it with the old information. Ideally, you should be able to just reboot after the restore, and the system will initialize as it always used to. My favorite program for doing that is [https://www.runtime.org/driveimage-xml.htm DriveImage XML] (which is free for private use). |
| | + | |
| | + | :It can go deep--the BIOS can be compromised, so you will be unable to boot to anything but the infected drive. This will prevent you from restoring a complete drive backup, even if you have one. The only way I know to deal with that is to swap out the motherboard, and run a boot disk (I like [[Hiren's BootCD]]). Using DIXML on the boot disk, then restore the XML backup to the infected drive. Make sure to wipe the drive first, just in case--at least a full format would be smart. Then try booting to it, with your external backup drive (any all other storage devices, except the restored hard drive) disconnected. Then you can try playing around, cleaning your BIOS and other storage devices, if you have any. |
| | + | |
| | + | :For now, just keep make sure to get all Windows updates, make regular backups (and if you take complete drive backups, keep a few older versions as well as the newest), never visit links you don't trust (especially in e-mails), and maybe get some good [[Anti-virus software]] and perhaps anti-malware software, like [[Spybot Search & Destroy]]. |
| | + | :A more radical option you could use is to switch to a [[Linux]] system. [[Linux Mint]] might be a good one, since the interface is designed similar to that of Windows. It would take some getting used to, and you will need to find and learn some new software to replace the Windows software you may use now, but that will shelter you from those zero-day vulnerabilities. Linux can have vulnerabilities too, but very few attackers pay any attention to them, since so few people use each version of Linux. |
| | + | |
| | + | :I hope this helps some--anything I didn't cover well? I know it's a lot to take in and especially a lot to do. --[[User:DavidB4|<font color="ForestGreen">David B</font>]] <sup>([[User talk:DavidB4|TALK]])</sup> 23:33, 23 May 2017 (EDT) |
| | | | |
| | ==Congressman John Fleming== | | ==Congressman John Fleming== |