LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-18-2017, 07:48 PM   #16
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941

Meh... why "I am done here?" Ducks manage to stay dry, no matter what the weather . . .
 
Old 01-18-2017, 08:39 PM   #17
kilgoretrout
Senior Member
 
Registered: Oct 2003
Posts: 2,987

Rep: Reputation: 388Reputation: 388Reputation: 388Reputation: 388
I'll try and answer your questions without lecturing you on the importance of doing backups.

There are certain assumptions in your scenario that I'm not sure are valid. Obviously, the encryption process started by the ransomware cannot be instantaneous which gives rise to your scenario. At a given point in time while the ransomware is executing, some of the files have been encrypted and some not. You then posit a situation where a backup is then done to an external USB drive resulting in a backup where some of the files are encrypted and some intact as that was the state of the source at the time of the backup. The assumption here is that the files being backed up will be accessible for backup during the ransomware encryption process. That may not be true depending on how the ransomware software is written. It may very well be that once the target files for encryption are identified by the ransomware and the encryption process started, access to the files by other processes will be blocked until the ransomware has finished encrypting.

But let's say that's not the case and you can wind up with a backup with half encrypted files and half intact, non-encrypted files.Then in answer to your question:
Quote:
Question: what will happen if backup USB disk will be attached to healthy/another PC?
I think the only sensible answer to your question is option "c":
Quote:
a. healthy files can be restored/safely copied and PC will not be infected.
b. USB's files will continue to encrypt and will also infect PC
c. depending from ransomware it might be A or B.
My reason being that it is likely possible to code your ransomware to behave like option "b" although I don't know enough about ransomware to know if that is commonly done. I think the more likely scenario is for the ransomware to be coded in such a way that option "a" would be right.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
serious infection crazy8 Linux - Server 16 01-15-2017 03:36 PM
[SOLVED] Possible malware infection on Mint 13 -- need help loshakova Linux - Newbie 39 02-25-2015 03:35 PM
[SOLVED] Chances of an MBR infection? junior-s Linux - Newbie 4 10-06-2013 05:31 PM
Malware infection in Linux snatale1 Linux - Software 12 01-12-2012 02:29 PM
*sigh* Virus infection.... xodustrance Linux - Newbie 3 07-14-2003 03:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration