|
virus
Oct 14, 2016 7:43:20 GMT -5
Post by mrpaco on Oct 14, 2016 7:43:20 GMT -5
I got hit with some sort of virus on my work PC. It has taken control of some files that I try to open. This is what I get: Any one know about this one?
|
|
|
virus
Oct 14, 2016 7:52:23 GMT -5
via mobile
Post by mrpaco on Oct 14, 2016 7:52:23 GMT -5
I really really need help asap.
|
|
|
virus
Oct 14, 2016 8:09:26 GMT -5
Post by Aleslammer on Oct 14, 2016 8:09:26 GMT -5
Not a good thing, the folks doing this have a pretty good scam going and have had some rather large companies pony up on the west coast, been in the news a couple of times is all I know about it.
|
|
|
virus
Oct 14, 2016 8:23:53 GMT -5
via mobile
Post by Vinster on Oct 14, 2016 8:23:53 GMT -5
Do you have backups? You'll need them. Change all your passwords !!! Check your email sent items to see if you resent this virus to anyone. Usually an email with a previous attachment. This normally comes in from an email from an infected attachment. Usually the email reads something like "thought I forgot to attach the file you asked for" if you opened that kind of attachment, the person that sent it to you is also having this issue and doesn't even know they passed it on. I hope you have backups... Format and secure wipe before reinstalling windows. Wish I had a better suggestion. I hope someone else does. If you pay, nothing stops them from hitting you again in a week. Vin
|
|
|
virus
Oct 14, 2016 8:26:37 GMT -5
via mobile
Post by Vinster on Oct 14, 2016 8:26:37 GMT -5
And 0.5105 bit coins is worth $325 USD...
Vin
|
|
|
virus
Oct 14, 2016 8:41:29 GMT -5
via mobile
Post by mrpaco on Oct 14, 2016 8:41:29 GMT -5
So there is no way to fix it is what youre saying?
|
|
|
virus
Oct 14, 2016 8:46:40 GMT -5
Post by Macsbeach98 on Oct 14, 2016 8:46:40 GMT -5
|
|
|
virus
Oct 14, 2016 8:58:10 GMT -5
Post by Vinster on Oct 14, 2016 8:58:10 GMT -5
So there is no way to fix it is what youre saying? my accountant got hit, his IT guy is was a specialist in security (apparently) and he was stumped. that about 10 months ago. my accountant ended up paying ($500 CAD in his case), backed up all his files and did a full sweep/format/re-install. Now he has an automated back up to an encrypted server twice a day. Other than that one case, I'd never seen it myself. I just know it can go bad quickly. Vin
|
|
|
virus
Oct 14, 2016 10:26:23 GMT -5
via mobile
Post by mrpaco on Oct 14, 2016 10:26:23 GMT -5
Totally screwed if i cant get the files decrypted. So far nothing works.
|
|
|
virus
Oct 14, 2016 11:40:12 GMT -5
Post by Mr.Scott on Oct 14, 2016 11:40:12 GMT -5
Without knowing the name of the virus I can't help you at all. All I can tell you right now is it came from Russia.
|
|
|
virus
Oct 14, 2016 11:52:08 GMT -5
Post by Vinster on Oct 14, 2016 11:52:08 GMT -5
|
|
|
virus
Oct 14, 2016 12:34:32 GMT -5
Post by Aleslammer on Oct 14, 2016 12:34:32 GMT -5
|
|
|
virus
Oct 14, 2016 12:52:41 GMT -5
Post by Vinster on Oct 14, 2016 12:52:41 GMT -5
This is my problem with paying the random, my accountant imo got lucky...
This sucks balls...
Vin
|
|
|
virus
Oct 14, 2016 18:11:10 GMT -5
Post by ozz on Oct 14, 2016 18:11:10 GMT -5
sorry to hear this frank, dont know if this is similar or will help , a mate of mine got hit with a russian scam some time ago, they posed as the Australian Federal Police as they did the same in many other countries, for their federal police, it locked your computer and to unlock you had to pay $100 in this case, he paid it and they kept it locked , so i tried for him with superantispyware and malwarebytes, did a complete pc scan for all files, discs etc and i got it unlocked. malwarebytes got it
|
|
|
virus
Oct 14, 2016 18:56:53 GMT -5
Post by mrpaco on Oct 14, 2016 18:56:53 GMT -5
Without knowing the name of the virus I can't help you at all. All I can tell you right now is it came from Russia. Thats the main problem; no where can I find the name of the file. Only know its ransome-ware.
|
|
|
virus
Oct 14, 2016 19:03:05 GMT -5
Post by ozz on Oct 14, 2016 19:03:05 GMT -5
Without knowing the name of the virus I can't help you at all. All I can tell you right now is it came from Russia. Thats the main problem; no where can I find the name of the file. Only know its ransome-ware. maybe something in here might help frank....there is a russian one in there that says its from russia id-ransomware.malwarehunterteam.com/
|
|
|
virus
Oct 14, 2016 19:07:53 GMT -5
Post by mrpaco on Oct 14, 2016 19:07:53 GMT -5
You have no idea just how many different anti-malware, decryption, antivirus programs I tried. I told my boss many years ago; never open an attachment from unknown senders, call me in first to check it. And what he do... Opens a dam zip file and launches what was in it. Now he's lost tax documents amongst AL OT of other docs. This virus is a mother@#%. lets say I go to change what program opens jpegs like windows photo viewer. It changes EVERYTHING excel, txt, word docs, etc to photo-viewer. It even infected the the back-up hard drive I had set up. Instead of him calling me AS SOON as it happened, he ofcourse tried to self medicate and made it worse.
To put icing on the cake; my boss is pissed at me that I cant fix it.
|
|
|
virus
Oct 14, 2016 19:09:36 GMT -5
Post by mrpaco on Oct 14, 2016 19:09:36 GMT -5
Thats the main problem; no where can I find the name of the file. Only know its ransome-ware. maybe something in here might help frank....there is a russian one in there that says its from russia id-ransomware.malwarehunterteam.com/Thanx Shane, But I tried that too. no good.
|
|
|
virus
Oct 14, 2016 19:26:20 GMT -5
Post by ozz on Oct 14, 2016 19:26:20 GMT -5
Thanx Shane, But I tried that too. no good. there has got to be a program to use to find and kill this bastard thing frank...trouble is.... finding it
|
|
|
virus
Oct 14, 2016 19:29:00 GMT -5
Post by Mr.Scott on Oct 14, 2016 19:29:00 GMT -5
You have no idea just how many different anti-malware, decryption, antivirus programs I tried. I told my boss many years ago; never open an attachment from unknown senders, call me in first to check it. And what he do... Opens a dam zip file and launches what was in it. Now he's lost tax documents amongst AL OT of other docs. This virus is a mother@#%. lets say I go to change what program opens jpegs like windows photo viewer. It changes EVERYTHING excel, txt, word docs, etc to photo-viewer. It even infected the the back-up hard drive I had set up. Instead of him calling me AS SOON as it happened, he ofcourse tried to self medicate and made it worse. To put icing on the cake; my boss is pissed at me that I cant fix it. It's not your fault, and he's out of line. Ransomeware is the most difficult to isolate and remove and even when you do there is only a 20% chance of recovering your files. A paid recovery service is pretty much the only option. It's expensive and still only a small percentage of chance of recovery. The company needs to look into a cloud backup service. You need to push that.
|
|
|
virus
Oct 14, 2016 19:33:25 GMT -5
Post by ozz on Oct 14, 2016 19:33:25 GMT -5
scotty is right it isnt your fault so dont go feeling guilty, you told him long ago, if it were me id try all of these even if you hit the buy button for the trial period which i think most will offer it, really, you have nothing to lose and you never know 1 might crack it for you www.techsupportall.com/best-anti-ransomware-software/
|
|
|
virus
Oct 14, 2016 19:36:55 GMT -5
Post by georgekokovinis on Oct 14, 2016 19:36:55 GMT -5
RSA-1024 is a malware that started 20 years ago and evolved to RSA-2048 and then RSA-4096. It is a malware with the native name GPcode, which, in the hands of various crooks has several names as GPencrypt. Even if the root of the malware was to be found, a strong ( 1024 bit ) decryption program would be needed to find the key.
Although nothing of the above helps in this case, it is totally wrong, for a workstation of a business, not to take, at least once daily, an encrypted back-up to a remote and secure server.
I am afraid that not much can be done. Sorry Frank.
|
|
|
virus
Oct 14, 2016 19:49:52 GMT -5
Post by Mr.Scott on Oct 14, 2016 19:49:52 GMT -5
|
|
|
virus
Oct 14, 2016 20:27:38 GMT -5
Post by mrpaco on Oct 14, 2016 20:27:38 GMT -5
thanx fellas. I know its not my fault. But because I am the so-called "IT" I'm surpassed to know everything. He'll get over it.
More info if possible about this: cloud backup service.
will try that one you post Scott. But boss didnt want me to bring the PC home, will have to do it Monday.
|
|
|
virus
Oct 14, 2016 20:48:48 GMT -5
Post by Mr.Scott on Oct 14, 2016 20:48:48 GMT -5
|
|
|
virus
Oct 14, 2016 20:52:19 GMT -5
Post by mrpaco on Oct 14, 2016 20:52:19 GMT -5
thanx will be setting that up monday
|
|
|
virus
Oct 14, 2016 20:56:53 GMT -5
Post by Mr.Scott on Oct 14, 2016 20:56:53 GMT -5
It's a sound investment. Roughly $75 a year is cheap insurance for the company's data. Incremental automatic backup too. Set it and forget it.
|
|
|
virus
Oct 14, 2016 21:31:07 GMT -5
Post by ozz on Oct 14, 2016 21:31:07 GMT -5
ill bet my arse frank your boss listens to you now mate !!
|
|
|
virus
Oct 15, 2016 17:15:56 GMT -5
Post by Macsbeach98 on Oct 15, 2016 17:15:56 GMT -5
You have no idea just how many different anti-malware, decryption, antivirus programs I tried. I told my boss many years ago; never open an attachment from unknown senders, call me in first to check it. And what he do... Opens a dam zip file and launches what was in it. Now he's lost tax documents amongst AL OT of other docs. This virus is a mother@#%. lets say I go to change what program opens jpegs like windows photo viewer. It changes EVERYTHING excel, txt, word docs, etc to photo-viewer. It even infected the the back-up hard drive I had set up. Instead of him calling me AS SOON as it happened, he ofcourse tried to self medicate and made it worse. To put icing on the cake; my boss is pissed at me that I cant fix it. Maybe that is what it is doing just changing everything to open with the same program of course none of them will. Try plugging in another formatted drive as a second drive and running Ubuntu direct off the CD then copy the data thats important to keep onto the second drive. Then take that drive home and try changing the extensions to what they should be on another system just one of your old benching installs will do, plug the drive in as a second again and see if you can change them individually. I have seen viruses before that change the extensions. Its a bugger that your boss wouldnt let you bring it home.
|
|
|
virus
Oct 17, 2016 3:31:47 GMT -5
Post by mrpaco on Oct 17, 2016 3:31:47 GMT -5
How would I do this?
If there are no backups, then the machine will have to re-imaged.
|
|