Page 2 of 2 FirstFirst 12
Results 21 to 29 of 29

Thread: Anti-Child Porn Spam Protection ransomware

  1. #21
    Ft. Couch! morbidpete's Avatar
    Join Date
    Mar 2002
    Location
    W. Warwick RI
    Posts
    7,073
    Awesome! If its a nas, You should be able to access the data via SMB or NFS, File system shouldn't matter on a nas

  2. #22
    SG Enthusiast RaisinCain's Avatar
    Join Date
    Jun 2009
    Posts
    1,233
    Just dealt with a customer that was infected with this. I booted into Safe Mode and ran Process Explorer. Killed the running process and deleted the offending files using CCleaner. Rebooted again into Safe Mode and ran ComboFix. I then installed MSE and scanned- removed a bunch of crap. I then ran UnHide and everything is back to normal.

  3. #23
    Administrator Philip's Avatar
    Join Date
    May 1999
    Location
    Jacksonville, Florida, United States
    Posts
    8,145
    Blog Entries
    6
    The backup is on some Seagate NAS with blown 12v power supply, and a 1TB drive... The drive itself is out of the NAS, it will be put on a linux box to transfer the files. Alternatively, he'll swap the power supply on the NAS.

  4. #24
    Moderator YeOldeStonecat's Avatar
    Join Date
    Jan 2001
    Location
    Somewhere along the shoreline in New England
    Posts
    49,833
    Ken and Philip..(and others)...some more info on this malware...including how it attacks, and what it does.
    http://blog.emsisoft.com/2012/04/11/...ndows-servers/
    MORNING WOOD Lumber Company
    Guinness for Strength!!!

  5. #25
    SG Enthusiast RaisinCain's Avatar
    Join Date
    Jun 2009
    Posts
    1,233
    I firmly believe that having Acrobat, Flash and Java up to date is critical in avoiding this type of infection (as well as the obvious).

  6. #26
    Ft. Couch! morbidpete's Avatar
    Join Date
    Mar 2002
    Location
    W. Warwick RI
    Posts
    7,073
    Quote Originally Posted by YeOldeStonecat View Post
    Ken and Philip..(and others)...some more info on this malware...including how it attacks, and what it does.
    http://blog.emsisoft.com/2012/04/11/...ndows-servers/
    Thanks for the info Cat, After reading on BC that he uses RDP, I imediatly disabled it on my clients. I use TV anyways so no need to have it enabled.

  7. #27
    Moderator YeOldeStonecat's Avatar
    Join Date
    Jan 2001
    Location
    Somewhere along the shoreline in New England
    Posts
    49,833
    Quote Originally Posted by RaisinCain View Post
    I firmly believe that having Acrobat, Flash and Java up to date is critical in avoiding this type of infection (as well as the obvious).
    Usually never installed on a server in the first place. This "problem" doesn't happen to a server because the end user is surfing the 'net...it's a direct attack against the server via port 3389 tcp.
    The guy is hacking into systems using the DUBrute tool against remote desktop...selecting common user names (Admin, Administrator, Root, Sales, Support, Scanner, Test1, Test2...basically a list of 25 or so very common user names that will be in AD (active directory users)...and then grinding against them with dictionary and smart guess passwords. Eventually getting into systems where the "guessed" usernames are present, and the passwords are simple and able to be overcome by the DUBrute tool.
    MORNING WOOD Lumber Company
    Guinness for Strength!!!

  8. #28
    Moderator YeOldeStonecat's Avatar
    Join Date
    Jan 2001
    Location
    Somewhere along the shoreline in New England
    Posts
    49,833
    Quote Originally Posted by RaisinCain View Post
    Just dealt with a customer that was infected with this. I booted into Safe Mode and ran Process Explorer. Killed the running process and deleted the offending files using CCleaner. Rebooted again into Safe Mode and ran ComboFix. I then installed MSE and scanned- removed a bunch of crap. I then ran UnHide and everything is back to normal.
    Then it was not //this// particular ransomware that you were dealing with....please read (and importantly...understand) this particular exact topic. The files are not RASHED...they are all packaged in an encrypted file, and the originals are completely and utterly erased. Combofix and typical geek squad malware removal tools are BB'guns on an elephant hunt for this particular subject.
    MORNING WOOD Lumber Company
    Guinness for Strength!!!

  9. #29
    SG Enthusiast RaisinCain's Avatar
    Join Date
    Jun 2009
    Posts
    1,233
    Quote Originally Posted by YeOldeStonecat View Post
    Then it was not //this// particular ransomware that you were dealing with....please read (and importantly...understand) this particular exact topic. The files are not RASHED...they are all packaged in an encrypted file, and the originals are completely and utterly erased. Combofix and typical geek squad malware removal tools are BB'guns on an elephant hunt for this particular subject.
    My bad. Yes I have ran into this one and have had no success in dealing with it on a personal basis (please don't compare me to GS).

Similar Threads

  1. No Jail for Man who said Child Porn is Therapeutic
    By minir in forum General Discussion Board
    Replies: 0
    Last Post: 06-04-06, 06:14 AM
  2. More than 500 Australians in child porn inquiry
    By Croc in forum General Discussion Board
    Replies: 6
    Last Post: 10-02-04, 02:16 PM
  3. Please don't tell the cops about my child porn.
    By RoundEye in forum General Discussion Board
    Replies: 9
    Last Post: 07-25-04, 12:06 AM
  4. 15 yr old charged with child porn...
    By Immortal in forum General Discussion Board
    Replies: 12
    Last Post: 03-31-04, 06:09 AM
  5. Global Child Porn Raids
    By gmcd33 in forum General Discussion Board
    Replies: 12
    Last Post: 11-29-01, 11:31 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •