Windows 10: New global ransomware attack hits East Europe and spreading

Discus and support New global ransomware attack hits East Europe and spreading in AntiVirus, Firewalls and System Security to solve the problem; Another massive attack is going on at the moment. It started in Ukraine and Russia and is already all over Europe and US too. Bitdefender Labs... Discussion in 'AntiVirus, Firewalls and System Security' started by AndreTen, Jun 26, 2017.

  1. AndreTen Win User

    New global ransomware attack hits East Europe and spreading


    Another massive attack is going on at the moment. It started in Ukraine and Russia and is already all over Europe and US too.

    Read more on bitdefender.com | massive-goldeneye-ransomware-campaign-slams-worldwide-users/

    Independent is reporting about Patya (Kaspersky identification of the same..)

    A lot of news around. thehackernews.com | 2017/06/petya-ransomware-attack
    :)
     
    AndreTen, Jun 26, 2017
    #1

  2. RANSOMWARE ATACK

    If you are referring to the recent WannaCry Ransomware Global attack....

    WannaCry spreads by exploit in a weakness found in Microsoft Windows which was formerly exploited by the US National Security Agency (NSA) and targets unpatched systems. A group known as The Shadow Brokers claimed to have dumped hacking tools stolen from
    NSA.


    Microsoft Customer Guidance for WannaCrypt attacks

    How to Protect yourself from the WannaCry or Wana Decryptor Ransomware

    How to protect yourself from WannaCry ransomware

    Microsoft releases WannaCrypt protection for out-of-support products...Windows XP, Windows 8, & Windows Server 2003

    Quote from
    Microsoft Customer Guidance for WannaCrypt attacks


    "...we are taking the highly unusual step of providing a security update for all customers to protect Windows platforms that are in custom support only, including Windows XP, Windows 8, and Windows Server 2003. Customers running Windows 10 were not targeted
    by the attack today.


    If you are referring to something else, then more information will be needed.
     
    quietman7 - MVP, Jun 26, 2017
    #2
  3. quietman7 - MVP, Jun 26, 2017
    #3
  4. Tony K Win User

    New global ransomware attack hits East Europe and spreading

    Thanks for reporting this here, Andre.

    What a crime. Will it ever end?!!
     
    Tony K, Jun 26, 2017
    #4
  5. AndreTen Win User
    This is business oriented attack and spreads very similar like WannaCry did, but exploits additional vulnerabilities. Disabling SMBv1 is smart move.

    thehackernews.com | windows-10-redstone3-smb
     
    AndreTen, Jun 26, 2017
    #5
  6. Tony K Win User
    In addition to that from Ed Bott, who posted this article back in mid May. I'm sure others did as well.

    More here: Windows 10 tip: Stop using the horribly insecure SMBv1 protocol | ZDNet
     
    Tony K, Jun 26, 2017
    #6
  7. pparks1 Win User
    Firewall servers and require access via jumpboxes.
     
    pparks1, Jun 26, 2017
    #7
  8. New global ransomware attack hits East Europe and spreading

    Control Panel/Programs and Features/Turn Windows features on or off.
     
    MikeMecanic, Jun 26, 2017
    #8
  9. Luckily, this little beauty has got the kill switch.
    New global ransomware attack hits East Europe and spreading [​IMG]
    *chuckle
    Source: Amit Serper (@0xAmit) | Twitter


    If you add "PsExec.exe" to disallowed apps, you can stop it from spreading from your computer.
    Code: reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "DisallowRun" /t REG_DWORD /d "1" /f reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun" /v "1" /t REG_SZ /d "PsExec.exe" /f[/quote]

    If you see the message bellow, pull off the cable and DO NOT turn on the computer.

    You can still save data from HDD. Source: Hacker Fantastic on Twitter:
     
    TairikuOkami, Jun 26, 2017
    #9
  10. AndreTen Win User
    If you see the message bellow, pull off the cable and DO NOT turn on the computer.

    You can still save data from HDD. Source: Hacker Fantastic on Twitter: [/quote] Thanks for posting this TairikuOkami. Could help a lot of users
     
    AndreTen, Jun 26, 2017
    #10
  11. Important notice: Paying the ransom will not help you get your data back. *Sad

    Email Provider Shuts Down Petya Inbox Preventing Victims From Recovering Files
     
    TairikuOkami, Jun 26, 2017
    #11
  12. f14tomcat Win User

    New global ransomware attack hits East Europe and spreading

    Whew!!!!!

    Zero-hour protection

    Malwarebytes detected this ransomware in the zero hour, meaning those that have Malwarebytes Premium or our standalone anti-ransomware technology have been protected from the instant this attack began. Both Malwarebytes business users and consumers users are protected if they are using the latest version of the above products.
     
    f14tomcat, Jun 27, 2017
    #13
  13. AndreTen Win User
    AndreTen, Jun 27, 2017
    #14
  14. MikeMecanic, Jun 27, 2017
    #15
Thema:

New global ransomware attack hits East Europe and spreading

Loading...
  1. New global ransomware attack hits East Europe and spreading - Similar Threads - global ransomware attack

  2. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware attack on my pc. All my files such as photos, videos, apps, xlxs, pdf and every thing are encrypted. every file extension shown as *YGKZ format and could not open anything. ID appears to be an online ID encryption. how do i resolve this....
  3. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I downloaded one file which was containing viruses and now all my Data is encrypted with .omfl extension and i have very important files on my pc. how to recover all file https://answers.microsoft.com/en-us/windows/forum/all/ransomware-attack/305c4fbf-4a2e-4293-9c35-a3bf07f3602d
  4. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware has attacked my pc. I cant do anything.please help https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/f0b64b4b-ea69-4af7-bb37-4f5e4a9ce363
  5. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I have been attacked by ransomware. Is there any way to remove and decrypt the files? Or I have to completely format my hard drive? Seeking attention to Microsoft community. I have attached some screen shots. I am not sure about the ransom type yet. [IMG] [IMG]...
  6. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Hello guys, i have a problem and i need help. to cut the long story short, my computer is infected with a ransomware (with ''nelasod'' extension on all docx, xlx, ppt and videos files). This has made it difficult to open any of my document in my external hard drive. It seems...
  7. Ransomware Attack ( .TRO)

    in AntiVirus, Firewalls and System Security
    Ransomware Attack ( .TRO): Hi all, I have a few questions regarding the ransomware attack. Most of my files format were changed to (.tro), is there a way to decrypted the files back to their original format? if possible then can anyone share how to do it? Thanks in advance for your response....
  8. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: Hello Dear all hope that you all doing well. Somone just hacked my pc.my all files stored on hard drive is converted to PPTX.how can i fix it. https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/659f8e54-0800-4449-95f0-94604fae69f6
  9. New Ransomware attack

    in AntiVirus, Firewalls and System Security
    New Ransomware attack: Only 5 days out and Win10 being screwed with. This link was in an E-Mail today: New Windows 10 scam will encrypt your files for ransom | ZDNet 12608
  10. Bad Rabbit ransomware: A new variant of Petya is spreading

    in Windows 10 News
    Bad Rabbit ransomware: A new variant of Petya is spreading: Bad Rabbit, a ransomware infection thought to be a new variant of Petya, has apparently hit a number of organisations in Russia and Ukraine. In a tweet, Russian cybersecurity firm Group-IB said that at least three media organisations in the country have been hit by...