• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Ethical Hacking

Wade Mackey

Ethical Hacking

MIS 5211.702 ■ Fall 2020 ■ Wade Mackey
  • Home
  • About
  • Syllabus
  • Gradebook

Week 6 In the News: New ransomware vaccine kills programs wiping Windows shadow volumes

October 5, 2020 by Anthony Messina Leave a Comment

A new type of vaccine has been created to help defend against ransomware called raccine.exe. The program will not stop ransomware from being installed on a PC, but it can help with the recovery process. This vaccine will terminate any processes that try to delete the shadow copies volume on a windows machine. Windows creates daily backups of your system and data files (when activated) and stores them as snapshots in Shadow Volume Copy. These snapshots are useful for recovering files if they are accidentally changed or deleted.

Many ransomware programs do not want their victims to use this feature as it can aid them in recovering their files for free. One of the first things most ransomware programs do is to delete all Shadow Volume copies on the computer. This generally executed by the command “vssadmin delete shadows /all /quiet.” The new vaccine is an executable that is a debugger for vssadmin.exe. Anytime vssadmin is executed on a computer raccine.exe will launch as well and check to see if vssadmin is trying to delete shadow copies and terminate the process.

 

https://www.bleepingcomputer.com/news/security/new-ransomware-vaccine-kills-programs-wiping-windows-shadow-volumes/

Filed Under: Uncategorized Tagged With:

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (46)
  • Week 01: Overview (3)
  • Week 02: TCP/IP and Network Architecture (6)
  • Week 03: Reconnaisance (5)
  • Week 04: Network Mapping and Vulnerability Scanning (11)
  • Week 05: Metasploit (10)
  • Week 06: More Metasploit (4)
  • Week 07: Social Engineering (7)
  • Week 08: Malware (6)
  • Week 09: Web Application Hacking (7)
  • Week 10: SecuritySheperd (6)
  • Week 11: Intro to Dark Web and Intro to Cloud (4)
  • Week 12: Introduction to Wireless Security with WEP and WPA2 PSK (7)
  • Week 13: WPA2 Enterprise and Beyond WiFi (3)
  • Week 14: Jack the Ripper, Cain and Able, and Ettercap (4)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in