Analysis of Locky ransomware
- 
 @BRRABill said: As usual, I asking for the smaller case. The Uncle using a single PC. How does that poor fellow protect himself from Crypto-viruses? Get them a chromebook. 
- 
 
- 
 @BRRABill said: As usual, I asking for the smaller case. The Uncle using a single PC. How does that poor fellow protect himself from Crypto-viruses? Chromebooks are best. 80% of the time at least, I think. For everyone else... there are backups. Real backups, not images, no short cuts. BackBlaze is good. Lots of options. 
- 
 @BRRABill said: As usual, I asking for the smaller case. The Uncle using a single PC. How does that poor fellow protect himself from Crypto-viruses? I have my parents setup with Backblaze. They have 800GB-1TB of pictures on their computer, it took several weeks to back them all up. 
- 
 @scottalanmiller said: For everyone else... there are backups. Real backups, not images, no short cuts. BackBlaze is good. Lots of options. Wouldn't the encrypted files just be backed up to BackBlaze? 
- 
 @BRRABill said: @scottalanmiller said: For everyone else... there are backups. Real backups, not images, no short cuts. BackBlaze is good. Lots of options. Wouldn't the encrypted files just be backed up to BackBlaze? Backblaze keeps a ton of versions of files. I don't remember how many but it is a lot. Backblaze also isn't a sync client. It is a true backup client. 
- 
 @coliver said: Backblaze keeps a ton of versions of files. I don't remember how many but it is a lot. Backblaze also isn't a sync client. It is a true backup client. I'm just imagining the process of restoring 150GB of data as individual files. Ugh. 
- 
 Remember, in the BackBlaze client, it throttles the upload speed by default. So dive into the settings and you can set it to upload more. I backed up 50GB in a couple of hours from the UK. 
- 
 @Breffni-Potter said: Remember, in the BackBlaze client, it throttles the upload speed by default. So dive into the settings and you can set it to upload more. I backed up 50GB in a couple of hours from the UK. Yep... my parents are on a crappy DSL connection. 
- 
 @BRRABill said: @coliver said: Backblaze keeps a ton of versions of files. I don't remember how many but it is a lot. Backblaze also isn't a sync client. It is a true backup client. I'm just imagining the process of restoring 150GB of data as individual files. Ugh. They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download. 
 https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/
- 
 @Nic said: They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download. 
 https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/$189 isn't actually a bad deal AND you get to keep the drive. I wonder how that works, though. I mean, you obviously don't want the actual backup, as the encrypted files have probably been uploaded. So can you get the previous version of every file? You know what I mean? That seems messy. 
- 
 @BRRABill said: @Nic said: They'll overnight you a flash drive with your data on it for a fee, if you can't wait for the download. 
 https://www.backblaze.com/blog/4-tb-usb-restore-drives-are-here-yay/$189 isn't actually a bad deal AND you get to keep the drive. I wonder how that works, though. I mean, you obviously don't want the actual backup, as the encrypted files have probably been uploaded. So can you get the previous version of every file? You know what I mean? That seems messy. How is it messy? I need the backups from 11/1/2015. They send you a drive with those backups on there. You plug it in and restore. Not sure where the issue is? 
- 
 Well you can go into the console and look at and download individual files. I imagine if you needed a restore from only before the infection date then they'd be able to do that. Let me ping @aaron for more details, since he works for them. 
- 
 @Nic said: Well you can go into the console and look at and download individual files. I imagine if you needed a restore from only before the infection date then they'd be able to do that. Let me ping @aaron for more details, since he works for them. Haha ... I was doing the same thing. He might not get the ping though since it's later in the day. I sent him a PM. 
- 
 This post is deleted!
- 
 @aaron Awesome info. That might just be the solution. 
- 
 Look what hit my quarantine. So I delivered it. OMG! I owe them $298,39 Wait what? comma 39 cents? What the f[moderated] is that. This is an admin email account at a client. If the admin account has it, it is only time before someone does all the things. 
- 
 this is why I turned off Doc and DOCX files via the spam filter. 
- 
 @Dashrender said: this is why I turned off Doc and DOCX files via the spam filter. What if your users legitimately need those files? 
- 
 @BRRABill said: @Dashrender said: this is why I turned off Doc and DOCX files via the spam filter. What if your users legitimately need those files? Much better ways to share documents than through email 






