LINUX LITE 7.2 FINAL RELEASED - SEE RELEASE ANNOUNCEMENTS SECTION FOR DETAILS


Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Ransomware On Google Chrome
#1
Got a call from a friend this morning running linuxlite 2.8x64.

The chrome browser was frozen with ransomeware.

He told me openly he had been at some "Adult Sites"

He does not have sudo access to the system...Only I have.

First thought was to remove chrome and re-install the browser.

Decided in the end to reformat and install Linuxlite 3.2

Not something you see every Day.

Jocklad  Smile
Reply
#2
Not sure how ransomware installs without sudo access.  Perhaps an adblocker would be advantageous and/or using the browser in incognito mode to cut down on storing cookies, history, etc. when visiting sites he's unsure about. 

In addition to that, if he doesn't have sudo access, then he isn't able to run his own updates.  He's somewhat at your mercy then.  A non-updated PC, particularly one with an out of date browser, is an easier mark for ransomware like this.  It might be worth giving him sudo access so he can update his own computer.
Want to thank me?  Click my [Thank] link.
Reply
#3
(12-07-2016, 09:13 PM)torreydale link Wrote: Not sure how ransomware installs without sudo access.  Perhaps an adblocker would be advantageous and/or using the browser in incognito mode to cut down on storing cookies, history, etc. when visiting sites he's unsure about. 

In addition to that, if he doesn't have sudo access, then he isn't able to run his own updates.  He's somewhat at your mercy then.  A non-updated PC, particularly one with an out of date browser, is an easier mark for ransomware like this.  It might be worth giving him sudo access so he can update his own computer.

and Chrome just had a 46.5 mb redo.
changed from Windows 10 to a REAL OS
Reply
#4
Quote:Not sure how ransomware installs without sudo access

I have no idea........but it did.

Quote:if he doesn't have sudo access, then he isn't able to run his own updates.

Friend has severe medical problems and it was agreed with him that he would not have sudo access.

I updated his system at least weekly.

Will see how he gets on with LL 3.2

Jocklad
Reply
#5
(12-07-2016, 07:36 PM)Jocklad link Wrote: Got a call from a friend this morning running linuxlite 2.8x64.

The chrome browser was frozen with ransomeware.

He told me openly he had been at some "Adult Sites"

He does not have sudo access to the system...Only I have.

First thought was to remove chrome and re-install the browser.

Decided in the end to reformat and install Linuxlite 3.2

Not something you see every Day.

Jocklad  Smile

I suspect it was not real ransomware, just scary pop-ups designed to LOOK like ransomware.

My father-in-law regularly calls me to rescue him from having somehow   Tongue ended up stuck with full-screen closure-resistant bogus virus warning windows of a kind that seems endemic to such "grownup" sites, although he never admits he's been to them.  Adding to his self-imposed difficulty is that he sets his screen resolution lower than default in an effort to make fonts and icons bigger, but which also makes it harder to close full-screen windows when the widgets end up off-screen.

He also constantly gullibly installs bogus browser extensions that purportedly hide search history and such.

Sigh, good thing he's not on MS Windows!
Reply
#6
Carney,

I agree.  Ransomware wouldn't allow you to uninstall and reinstall the browser, at least not while logged into the desktop environment. 

I had someone I helped who thought they had ransomware.  I saw no evidence of it, but I did take the opportunity to update his machine (he wasn't doing it), I showed him how to update going forward, and I installed an adblocker for his browser.  This friend of mine was on Linux, but not Linux Lite.  I think it was just some persistent popup he wasn't familiar with, and I think the adblocker, cleared cache, and cleared history will help.
Want to thank me?  Click my [Thank] link.
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)