PSA - Again about backups
- rjohnson
- Duck South Addict
- Posts: 4895
- Joined: Mon Jan 17, 2005 11:28 am
- Location: Brandon, MS
- Contact:
PSA - Again about backups
http://www.pcworld.com/article/2600543/ ... files.html
If any of you heard of the CryptoLocker ransomware there is one that one upped it called CryptoWall. It has been out since late last year but only recently really making its presence known. Once a PC is infected it will start encrypting PDF, XLS, DOC, and other common files on the PC then move on to mapped network drives and even Dropbox. It will put the files above in each folder it encrypts. It is piggybacked on other downloads from the web on infected sites and through email attachments that users just can't restrain from opening. So again if you're not backing your stuff up you either pony up the ransom or lose the files. Average ransom is $500. I'm putting this out there because I'm helping someone recover from this infection right now. Fortunately we have multiple levels of backups for them and they are only losing about 30 minutes worth of work today. So be careful what you download, keep your AV up to date, and backup your stuff!!!!
If any of you heard of the CryptoLocker ransomware there is one that one upped it called CryptoWall. It has been out since late last year but only recently really making its presence known. Once a PC is infected it will start encrypting PDF, XLS, DOC, and other common files on the PC then move on to mapped network drives and even Dropbox. It will put the files above in each folder it encrypts. It is piggybacked on other downloads from the web on infected sites and through email attachments that users just can't restrain from opening. So again if you're not backing your stuff up you either pony up the ransom or lose the files. Average ransom is $500. I'm putting this out there because I'm helping someone recover from this infection right now. Fortunately we have multiple levels of backups for them and they are only losing about 30 minutes worth of work today. So be careful what you download, keep your AV up to date, and backup your stuff!!!!
http://www.lithicIT.com My biz
-
- Duck South Addict
- Posts: 8273
- Joined: Tue Jan 25, 2005 8:35 pm
- Location: Sylacauga Alabama via Louisville MISSISSIPPI
Re: PSA - Again about backups
Something very similar happened to a lady in our corp office, it got her computer then got on the network drive hacked all of our stuff, HR, accounting, etc... Ransom was $850 and once paid everything was returned but it took 3 weeks of no internet/email to get fixed and back up. Pain in the ass for all the sales team and resort staff, sure am glad I just grow grass lol
Life is to short to only fish on weekends
- lilwhitelie
- Duck South Addict
- Posts: 2092
- Joined: Sat Feb 12, 2005 8:21 pm
- Location: brandon, ms
Re: PSA - Again about backups
My lord was I wrong on this topic!!! I see PSA and think its a dang prostate information topic. And the backups part was really scary.
HRCH JB'S LIL WHITE LIE
Re: PSA - Again about backups
lilwhitelie wrote:My lord was I wrong on this topic!!! I see PSA and think its a dang prostate information topic. And the backups part was really scary.
I was thinking Palmetto State Armory and backup meaning buy more guns and ammo...
Re: PSA - Again about backups
This junk hit us yesterday. It infected about 16,000 network files. The majority of those files were backed up each night, with the exception of a "temp" cifs share of 10gig which will be a complete loss. The poor Symantec sales guy that just called me wanting to sell something got ambushed. Bad timing on his part.
Looking for 2 duck calls from Dominic Serio of Greenwood (ones for Novacaine)
"Most Chesapeakes, unless in agreement that it is his idea, will continually question the validity of what he is being asked to do" - Butch Goodwin
"Most Chesapeakes, unless in agreement that it is his idea, will continually question the validity of what he is being asked to do" - Butch Goodwin
- rjohnson
- Duck South Addict
- Posts: 4895
- Joined: Mon Jan 17, 2005 11:28 am
- Location: Brandon, MS
- Contact:
Re: PSA - Again about backups
No antivirus will work if the user opens the attachment and runs it. Can't take human error out of the equation unfortunately. Poor Symantec sales guy.teul2 wrote:This junk hit us yesterday. It infected about 16,000 network files. The majority of those files were backed up each night, with the exception of a "temp" cifs share of 10gig which will be a complete loss. The poor Symantec sales guy that just called me wanting to sell something got ambushed. Bad timing on his part.
http://www.lithicIT.com My biz
Re: PSA - Again about backups
The user says she did not download anything nor open any attachments. She was researching her kids science project and got hit. They are calling this one a 'Drive-by-download' attack and Symantec Endpoint Protection missed it. But hey are also telling me we needed an "add-on" to our current product to stop this. The infection only got her profile on the computer and network drives she had access / permission to. This is my number one reason for not giving users admin rights to their computers and restricting file access rights to only job essential needs. If they can't install software, they can't spread viruses as easily.rjohnson wrote:No antivirus will work if the user opens the attachment and runs it. Can't take human error out of the equation unfortunately. Poor Symantec sales guy.
Looking for 2 duck calls from Dominic Serio of Greenwood (ones for Novacaine)
"Most Chesapeakes, unless in agreement that it is his idea, will continually question the validity of what he is being asked to do" - Butch Goodwin
"Most Chesapeakes, unless in agreement that it is his idea, will continually question the validity of what he is being asked to do" - Butch Goodwin
Re: PSA - Again about backups
Assuming a client based web/url traffic firewall? We utilize one as an accompaniment to our client AV. It blocks rouge or malicious content/websites before it has a chance to infiltrate the client.teul2 wrote:The user says she did not download anything nor open any attachments. She was researching her kids science project and got hit. They are calling this one a 'Drive-by-download' attack and Symantec Endpoint Protection missed it. But hey are also telling me we needed an "add-on" to our current product to stop this. The infection only got her profile on the computer and network drives she had access / permission to. This is my number one reason for not giving users admin rights to their computers and restricting file access rights to only job essential needs. If they can't install software, they can't spread viruses as easily.rjohnson wrote:No antivirus will work if the user opens the attachment and runs it. Can't take human error out of the equation unfortunately. Poor Symantec sales guy.
(╯°□°)╯︵ ┻━┻
Re: PSA - Again about backups
me to program mgr when he got a 'vm from microsoft' via email: "did you click on anything?"
him: "no i did not....well, the first time i did, but only the once."
DOH! or rather DUH!
him: "no i did not....well, the first time i did, but only the once."
DOH! or rather DUH!
Experience is a freakin' awesome teacher...
- rjohnson
- Duck South Addict
- Posts: 4895
- Joined: Mon Jan 17, 2005 11:28 am
- Location: Brandon, MS
- Contact:
Re: PSA - Again about backups
Same here in now two different instances. Neither received a malicious attachment nor installed any new software. AV appears to have missed it in both locations. Plan to check some clients' firewalls this afternoon that have content filtering enabled to see if it is being blocked successfully with that. Sneaky little devil this one is.teul2 wrote:The user says she did not download anything nor open any attachments. She was researching her kids science project and got hit. They are calling this one a 'Drive-by-download' attack and Symantec Endpoint Protection missed it. But hey are also telling me we needed an "add-on" to our current product to stop this. The infection only got her profile on the computer and network drives she had access / permission to. This is my number one reason for not giving users admin rights to their computers and restricting file access rights to only job essential needs. If they can't install software, they can't spread viruses as easily.rjohnson wrote:No antivirus will work if the user opens the attachment and runs it. Can't take human error out of the equation unfortunately. Poor Symantec sales guy.
http://www.lithicIT.com My biz
Re: PSA - Again about backups
Yes edub, we have a Barracuda webfilter.
Been on the phone with Symantec and they are telling me that we need the "web gateway module" to prevent this infection. Which happens to not be standard on our version of SEP. Have to step up to the SPS Enterprise version.
Been on the phone with Symantec and they are telling me that we need the "web gateway module" to prevent this infection. Which happens to not be standard on our version of SEP. Have to step up to the SPS Enterprise version.
Looking for 2 duck calls from Dominic Serio of Greenwood (ones for Novacaine)
"Most Chesapeakes, unless in agreement that it is his idea, will continually question the validity of what he is being asked to do" - Butch Goodwin
"Most Chesapeakes, unless in agreement that it is his idea, will continually question the validity of what he is being asked to do" - Butch Goodwin
Re: PSA - Again about backups
Due diligence means you have to buy & implement the safeguards. But I really don't think you can't beat this stuff, all you can do is increase your resilience. System Center Configuration Manager for re-imaging + nightly backup of clients' My Documents folders to network attached storage.
Re: PSA - Again about backups
you left out user rights restrictionsJDgator wrote:Due diligence means you have to buy & implement the safeguards. But I really don't think you can't beat this stuff, all you can do is increase your resilience. System Center Configuration Manager for re-imaging + nightly backup of clients' My Documents folders to network attached storage.

(╯°□°)╯︵ ┻━┻
Re: PSA - Again about backups
edub20 wrote:you left out user rights restrictionsJDgator wrote:Due diligence means you have to buy & implement the safeguards. But I really don't think you can't beat this stuff, all you can do is increase your resilience. System Center Configuration Manager for re-imaging + nightly backup of clients' My Documents folders to network attached storage.
Computer Nazi!!!
Who is online
Users browsing this forum: Amazon [Bot] and 3 guests