Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Ransomeware attack, need advice
self | 07/16/15 | fwdude

Posted on 07/19/2015 6:34:05 AM PDT by fwdude

I have recently had the unpleasant experience of having one of the new variants of the cryptolocker malware infect our computer servers at work. In case someone doesn't know, its a computer worm that encrypts all the standard-format files on a system so that the use can't open the file without a "key," supplied by the hacker for a ransom.

My question, which I have researched extensively over over the internet, is whether it is advisable consider paying the ransom, if there is enough "honor among thieves" to trust that the files will be unlock if I pay, and if there might remains some residual malware that might reinfect our computers.

And, no, there are no backup files that were untouched, the backups were infected as well.

Some of the files are critical, or at least would take an enormous amount of work to recreate or recover otherwise. Do you consider the risk worth the reward?


TOPICS: Computers/Internet
KEYWORDS: computers; computing; cryptolocker; internet; malware; ransomware
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-85 next last

1 posted on 07/19/2015 6:34:06 AM PDT by fwdude
[ Post Reply | Private Reply | View Replies]

To: fwdude

I have always heard that you don’t get a key. You just lose your money.


2 posted on 07/19/2015 6:35:38 AM PDT by Flash Bazbeaux
[ Post Reply | Private Reply | To 1 | View Replies]

To: Flash Bazbeaux

I’ve heard the opposite, that most people do get back their data.


3 posted on 07/19/2015 6:36:53 AM PDT by fwdude (The last time the GOP ran an "extremist," Reagan won 44 states.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Flash Bazbeaux

I would think if you pay, they will always come back to do it again.


4 posted on 07/19/2015 6:37:17 AM PDT by bcr100
[ Post Reply | Private Reply | To 2 | View Replies]

To: fwdude

The obvious of paying the “ransom” only encourages them and I doubt that the “key” will remove the malware permanently, and that they will keep coming to the well for more $


5 posted on 07/19/2015 6:37:34 AM PDT by Ouderkirk (To the left, everything must evidence that this or that strand of leftist theory is true)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude
NO!
Dump WINDOWS, and get a different Operating System !
6 posted on 07/19/2015 6:38:15 AM PDT by Yosemitest (It's Simple ! Fight, ... or Die !)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude

Had a similar problem with an overseas branch. Never heard of the outcome.

I’m about to the point of running linux live such as Ubuntu for internet stuff and using windoze on line as little as possible.

Other than routine browsing, email, and FTP there is nothing else.


7 posted on 07/19/2015 6:39:34 AM PDT by wally_bert (There are no winners in a game of losers. I'm Tommy Joyce, welcome to the Oriental Lounge.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude
Pay the money, then take your backups off-net every time you backup.

Expensive lesson, but now you've learned it.

8 posted on 07/19/2015 6:39:54 AM PDT by Lazamataz ("In a very short period of time, these will be the good old days." -- unknown Freeper, 2015)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude
I have heard that paying the ransom goes form bad to worse as you give up your banking or credit card information. I am struggling with Marc's cyber page pirating Waterfox. I am using programs form Download.com and have removed Trojans and other virus files but not the pirate page. I expect things to get worse as the government gives our information to China.
9 posted on 07/19/2015 6:40:43 AM PDT by mountainlion (Live well for those that did not make it back.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude

“Hitman” worked for the DOJ page-locker. I don’t know about this one.


10 posted on 07/19/2015 6:42:15 AM PDT by Bernard (The Road To Hell is not paved with good results.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ouderkirk

Totally agree. Give a wolf a taste and he’ll be back for more - Kerim Bey.


11 posted on 07/19/2015 6:42:51 AM PDT by wally_bert (There are no winners in a game of losers. I'm Tommy Joyce, welcome to the Oriental Lounge.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Ouderkirk
Oh, it definitely does not remove the ransomware.

1) Take the machine off the intranet IMMEDIATELY.

2) Pay the money, I have never heard of someone not getting a key.

3) Unlock the data you want. Take the data off onto a USB, and on a computer you do not care about, insert the USB and run about 100,000 virus and rootkit scans.

4) Factory re-image the infected computer.

5) Factory-reset all the peripherals around it (I was once infected with a rootkit that flashed the firmware in a router, to reinfect my computer even after I factory-reimaged).

6) From that point on, all backups go on to one of several devices, and each device is taken offline after the backup.

12 posted on 07/19/2015 6:43:56 AM PDT by Lazamataz ("In a very short period of time, these will be the good old days." -- unknown Freeper, 2015)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Yosemitest

Okay, I need a solution to the CURRENT problem. Leave your hatred for Windows at the door for now.


13 posted on 07/19/2015 6:44:27 AM PDT by fwdude (The last time the GOP ran an "extremist," Reagan won 44 states.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: fwdude

Massachusetts police department pays $500 CryptoLocker ransom

http://www.networkworld.com/article/2906983/security0/massachusetts-police-department-pays-500-cryptolocker-ransom.html


14 posted on 07/19/2015 6:45:10 AM PDT by Tamzee (Man is not free unless government is limited. ~~~ Ronald Reagan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mountainlion

The transaction is done with bitcoins, so there is no exposure to your bank account.


15 posted on 07/19/2015 6:45:49 AM PDT by fwdude (The last time the GOP ran an "extremist," Reagan won 44 states.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: mountainlion; fwdude
I have heard that paying the ransom goes form bad to worse as you give up your banking or credit card information.

That's why God invented one-time-use debit cards!

Load the card, spend 6 bux on the fee, and boom. Done.

16 posted on 07/19/2015 6:46:22 AM PDT by Lazamataz ("In a very short period of time, these will be the good old days." -- unknown Freeper, 2015)
[ Post Reply | Private Reply | To 9 | View Replies]

To: fwdude
Pay the money, then take your backups off-net every time you backup. Expensive lesson, but now you've learned it.

+1

17 posted on 07/19/2015 6:50:15 AM PDT by keat
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude

You have to determine whether reconstructing the data would cost less than paying the ransome and possibly getting nothing in return.

==

Horse-barn door.

Why were backups on the same server(s) as the data files?

Why were servers not backed up/imaged?

==

How did the perps get the malware planted onto the system?

==

Even with my home computers, I have 4 or 5 backups on USB disks for data that is important.

==


18 posted on 07/19/2015 6:50:27 AM PDT by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude

The time you have spent on this problem could have made you basically proficient at another OS and more immune to this attack in the future.

The victims complacency is a powerful weapon to the hackers.


19 posted on 07/19/2015 6:59:53 AM PDT by Delta 21 (Patiently waiting for the jack booted kick at my door.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: fwdude
Think what you like, but the UNSECURE WINDOWS Operating System allowed the their access to your computer.
Don;' keep putting money into a bad system.
Most times you can simply do a "Power OFF" reboot of your computer, and when the internet comes up, immediately shut that window down before it has time to load.
Then start your internet from your home page.
Good luck with your THEFT RIDDEN SYSTEM.
WINDOWS is built to RIP YOU OFF, and keep you buying more programs to "FIX" a broken system !
20 posted on 07/19/2015 7:01:40 AM PDT by Yosemitest (It's Simple ! Fight, ... or Die !)
[ Post Reply | Private Reply | To 13 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-85 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson