Windows 10: New global ransomware attack hits East Europe and spreading

Discus and support New global ransomware attack hits East Europe and spreading in AntiVirus, Firewalls and System Security to solve the problem; I was checking out the Norse tracking map and Microsoft was sending out a lot of attacks to servers in Washington DC. It looks like DC is the main... Discussion in 'AntiVirus, Firewalls and System Security' started by AndreTen, Jun 26, 2017.

  1. bro67 Win User

    New global ransomware attack hits East Europe and spreading


    I was checking out the Norse tracking map and Microsoft was sending out a lot of attacks to servers in Washington DC. It looks like DC is the main target right now. Norse Attack Map
     
    bro67, Jun 27, 2017
    #16
  2. Steve C Win User

    Beware of using the batch file in that link. It creates some other files including perfc.dat which Kaspersky Total Security promptly deleted.
     
    Steve C, Jun 27, 2017
    #17
  3. AndreTen Win User
    Thanks for warning Steve. One can usually trust the guys at Bleeping Computers. Will check it out. Kaspersky could react to changes in Windows dir...

    Edit: can't imagine what would trigger Kaspersky, except that it just reacts to creating files in C:\Windows..

    There are just 3 files, filled with some text (don't delete this.. is a vaccine ...) named perfc, perfc.dll and perfc.somtething else
     
    AndreTen, Jun 27, 2017
    #18
  4. Kol12 Win User

    New global ransomware attack hits East Europe and spreading

    I'm curious, how are these hackers able to get hold of NSA exploits?
    @bro67 Can you tell me what Norse tracking map is?
     
    Kol12, Jun 27, 2017
    #19
  5. lx07 Win User
  6. AndreTen Win User
    Not really..
    System is patched for original Eternalblue (WannyCry), but not for other exploits.

    All major AV and Antimalware companies updated their software, so users are on the safe side by now. Industrial solutions are other story...
     
    AndreTen, Jun 27, 2017
    #21
  7. lx07 Win User
    Ah interesting, I missed that bit. These only work if you are running Admin account (or with Admin rights) though correct?
     
  8. AndreTen Win User

    New global ransomware attack hits East Europe and spreading

    Correct.
     
    AndreTen, Jun 27, 2017
    #23
  9. dencal Win User
    This was not ransomware....more than likely industrial espionage....why would the perpetrator leave an easily traceable calling address?
    This has already been shut down.....so financial gain was not the motive.
     
    dencal, Jun 27, 2017
    #24
  10. Steve C Win User
    Does anyone know why that batch file inserts 3 perfc files whereas the manual fix just creates the file perfc (read only)? I've used a manual fix since Kaspersky Antivirus deletes perfc.dat created by the batch file.

    I just ran Notepad as Admin, saved the empty file as c:\windows\perfc, then made two further copies of perfc and renamed them perfc.dll and perfc.dat. Finally I set them to be read only. Kaspersky antivirus doesn't object when you do it this way.
     
    Steve C, Jun 27, 2017
    #25
  11. AndreTen Win User
    I have no idea... It was mentioned somewhere, that this vaccine isn't futureproof. Malware makers could easily change its behavior. Perhaps it's something in that direction...

    Once more: all major AV and antimalware suites are updated and are blocking it (including Windows defender)
     
    AndreTen, Jun 27, 2017
    #26
  12. f14tomcat Win User
    Muscle flexing and diversion.....what's the real target?
     
    f14tomcat, Jun 27, 2017
    #27
  13. lx07 Win User

    New global ransomware attack hits East Europe and spreading

    If you look at the link in the batchfile twitter.com/0xAmit/status/879778335286452224 various people are arguing about whether perfc (no extension), perfc.dat or perfc.dll are required. I guess the writer of the file stuck them all in to be on the safe side.
     
  14. dencal Win User
    Either some curious kid in a back room seeing how clever he is.....or more worryingly a nation seeking superiority by paralysing vital industries, bringing countries to a standstill......most modern warfare is conducted using computerised technology, ie- aeroplanes, ships, missiles, orbiting space satellites etc.....all could be rendered completely ineffective......frightening isn't it.
     
    dencal, Jun 27, 2017
    #29
  15. Steve C Win User
    Thanks - I just created the 3 files manually as Post 23.
     
    Steve C, Jun 27, 2017
    #30
Thema:

New global ransomware attack hits East Europe and spreading

Loading...
  1. New global ransomware attack hits East Europe and spreading - Similar Threads - global ransomware attack

  2. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware attack on my pc. All my files such as photos, videos, apps, xlxs, pdf and every thing are encrypted. every file extension shown as *YGKZ format and could not open anything. ID appears to be an online ID encryption. how do i resolve this....
  3. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I downloaded one file which was containing viruses and now all my Data is encrypted with .omfl extension and i have very important files on my pc. how to recover all file https://answers.microsoft.com/en-us/windows/forum/all/ransomware-attack/305c4fbf-4a2e-4293-9c35-a3bf07f3602d
  4. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware has attacked my pc. I cant do anything.please help https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/f0b64b4b-ea69-4af7-bb37-4f5e4a9ce363
  5. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I have been attacked by ransomware. Is there any way to remove and decrypt the files? Or I have to completely format my hard drive? Seeking attention to Microsoft community. I have attached some screen shots. I am not sure about the ransom type yet. [IMG] [IMG]...
  6. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Hello guys, i have a problem and i need help. to cut the long story short, my computer is infected with a ransomware (with ''nelasod'' extension on all docx, xlx, ppt and videos files). This has made it difficult to open any of my document in my external hard drive. It seems...
  7. Ransomware Attack ( .TRO)

    in AntiVirus, Firewalls and System Security
    Ransomware Attack ( .TRO): Hi all, I have a few questions regarding the ransomware attack. Most of my files format were changed to (.tro), is there a way to decrypted the files back to their original format? if possible then can anyone share how to do it? Thanks in advance for your response....
  8. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: Hello Dear all hope that you all doing well. Somone just hacked my pc.my all files stored on hard drive is converted to PPTX.how can i fix it. https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/659f8e54-0800-4449-95f0-94604fae69f6
  9. New Ransomware attack

    in AntiVirus, Firewalls and System Security
    New Ransomware attack: Only 5 days out and Win10 being screwed with. This link was in an E-Mail today: New Windows 10 scam will encrypt your files for ransom | ZDNet 12608
  10. Bad Rabbit ransomware: A new variant of Petya is spreading

    in Windows 10 News
    Bad Rabbit ransomware: A new variant of Petya is spreading: Bad Rabbit, a ransomware infection thought to be a new variant of Petya, has apparently hit a number of organisations in Russia and Ukraine. In a tweet, Russian cybersecurity firm Group-IB said that at least three media organisations in the country have been hit by...