Page 1 of 2

PSA - Again about backups

Posted: Mon Sep 22, 2014 5:53 pm
by rjohnson
http://www.pcworld.com/article/2600543/cryptowall-held-over-halfamillion-computers-hostage-encrypted-5-billion-files.html

cryptowall_files.jpg
cryptowall_files.jpg (5.56 KiB) Viewed 1119 times


If any of you heard of the CryptoLocker ransomware there is one that one upped it called CryptoWall. It has been out since late last year but only recently really making its presence known. Once a PC is infected it will start encrypting PDF, XLS, DOC, and other common files on the PC then move on to mapped network drives and even Dropbox. It will put the files above in each folder it encrypts. It is piggybacked on other downloads from the web on infected sites and through email attachments that users just can't restrain from opening. So again if you're not backing your stuff up you either pony up the ransom or lose the files. Average ransom is $500. I'm putting this out there because I'm helping someone recover from this infection right now. Fortunately we have multiple levels of backups for them and they are only losing about 30 minutes worth of work today. So be careful what you download, keep your AV up to date, and backup your stuff!!!!

Re: PSA - Again about backups

Posted: Mon Sep 22, 2014 7:32 pm
by duckkiller
Something very similar happened to a lady in our corp office, it got her computer then got on the network drive hacked all of our stuff, HR, accounting, etc... Ransom was $850 and once paid everything was returned but it took 3 weeks of no internet/email to get fixed and back up. Pain in the ass for all the sales team and resort staff, sure am glad I just grow grass lol

Re: PSA - Again about backups

Posted: Mon Sep 22, 2014 8:48 pm
by lilwhitelie
My lord was I wrong on this topic!!! I see PSA and think its a dang prostate information topic. And the backups part was really scary.

Re: PSA - Again about backups

Posted: Tue Sep 23, 2014 6:16 am
by kb7722

Re: PSA - Again about backups

Posted: Tue Sep 23, 2014 6:34 am
by edub20


Can't ever have too many backups...

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 8:23 am
by teul2
This junk hit us yesterday. It infected about 16,000 network files. The majority of those files were backed up each night, with the exception of a "temp" cifs share of 10gig which will be a complete loss. The poor Symantec sales guy that just called me wanting to sell something got ambushed. Bad timing on his part.

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 9:13 am
by rjohnson

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 9:43 am
by teul2

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 10:48 am
by edub20

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 10:54 am
by donia
me to program mgr when he got a 'vm from microsoft' via email: "did you click on anything?"
him: "no i did not....well, the first time i did, but only the once."
DOH! or rather DUH!

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 12:00 pm
by rjohnson

Re: PSA - Again about backups

Posted: Wed Sep 24, 2014 12:54 pm
by teul2
Yes edub, we have a Barracuda webfilter.

Been on the phone with Symantec and they are telling me that we need the "web gateway module" to prevent this infection. Which happens to not be standard on our version of SEP. Have to step up to the SPS Enterprise version.

Re: PSA - Again about backups

Posted: Thu Sep 25, 2014 7:00 pm
by JDgator
Due diligence means you have to buy & implement the safeguards. But I really don't think you can't beat this stuff, all you can do is increase your resilience. System Center Configuration Manager for re-imaging + nightly backup of clients' My Documents folders to network attached storage.

Re: PSA - Again about backups

Posted: Fri Sep 26, 2014 7:16 am
by edub20

Re: PSA - Again about backups

Posted: Fri Sep 26, 2014 7:57 am
by kb7722