Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
ransomware in Irish
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 30 - Collapse all  -  Translate all to Translated (View all originals)   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
calcrea  
View profile  
 More options Sep 27 2012, 7:55 am
From: calcrea <calc...@gmail.com>
Date: Thu, 27 Sep 2012 04:55:37 -0700 (PDT)
Local: Thurs, Sep 27 2012 7:55 am
Subject: ransomware in Irish

Hey guys, got phoned this morning by the old man, his laptop has been taken over by a virus that just displays an official looking Irish language page. basically it demands €100 to unlock the comp. Tried to remove it but cmd prompts and safe mode won't start so Im stumped. Anyone been hit by this or know how to remove it? Thanks :-)


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Domhnall Walsh  
View profile  
 More options Sep 27 2012, 7:57 am
From: Domhnall Walsh <domhn...@091labs.com>
Date: Thu, 27 Sep 2012 12:57:18 +0100
Local: Thurs, Sep 27 2012 7:57 am
Subject: Re: [091labs-public] ransomware in Irish

Without seeing it, no. Get it to me, I'll sort it.
On 27 Sep 2012 12:55, "calcrea" <calc...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Martin ODonnell  
View profile  
 More options Sep 27 2012, 8:02 am
From: Martin ODonnell <marti...@gmail.com>
Date: Thu, 27 Sep 2012 13:02:35 +0100
Local: Thurs, Sep 27 2012 8:02 am
Subject: Re: [091labs-public] ransomware in Irish
my first thought would've been safe mode then system restore, but if
you cant get into safe mode it wont be straight forward to sort it
out. feel free to leave the laptop in the Labs, let me know when its
there and i'll pop up and collect and sort it for ya if you like. i'm
sure i'll get it fixed if i have my hands on it, but i dont know what
advice to give you to have a go at it yourself if it wont go into safe
mode for you


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Domhnall Walsh  
View profile  
 More options Sep 27 2012, 8:11 am
From: Domhnall Walsh <domhn...@091labs.com>
Date: Thu, 27 Sep 2012 13:11:31 +0100
Local: Thurs, Sep 27 2012 8:11 am
Subject: Re: [091labs-public] ransomware in Irish

Hmm. Depending on how long it's been since your last restore point, using
system restore to "fix" such problems is a bit like giving yourself a
lobotomy to forget something you don't like. Okay, that's a little
dramatic, but you get what I mean. Anyway, there are plenty of viruses and
things that are more than aware of System Restore and infect your restore
points as well to be sure.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
calcrea  
View profile  
 More options Sep 27 2012, 8:13 am
From: calcrea <calc...@gmail.com>
Date: Thu, 27 Sep 2012 05:13:32 -0700 (PDT)
Local: Thurs, Sep 27 2012 8:13 am
Subject: Re: ransomware in Irish

Thanks guys, I'll be bringing it with me to the labs. Gotta go meet katie
there now actually lol.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Richard Conroy  
View profile  
 More options Sep 27 2012, 8:21 am
From: Richard Conroy <richard.con...@gmail.com>
Date: Thu, 27 Sep 2012 13:21:22 +0100
Local: Thurs, Sep 27 2012 8:21 am
Subject: Re: [091labs-public] Re: ransomware in Irish

Does anyone boot from an OS on a USB stick or external drive?

I know you can setup ubuntu to boot from a stick, I am wondering though if
this is a good general approach to take with security - especially if you
can load software from the USB stick that can clean up windows.

Possibly spawn a windows image from virtualbox?

On Thu, Sep 27, 2012 at 1:13 PM, calcrea <calc...@gmail.com> wrote:
> Thanks guys, I'll be bringing it with me to the labs. Gotta go meet katie
> there now actually lol.

> On Thursday, September 27, 2012 12:55:37 PM UTC+1, calcrea wrote:

>> Hey guys, got phoned this morning by the old man, his laptop has been
>> taken over by a virus that just displays an official looking Irish language
>> page. basically it demands €100 to unlock the comp. Tried to remove it but
>> cmd prompts and safe mode won't start so Im stumped. Anyone been hit by
>> this or know how to remove it? Thanks :-)

--
http://richardconroy.blogspot.com | http://twitter.com/RichardConroy

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Domhnall Walsh  
View profile  
 More options Sep 27 2012, 8:25 am
From: Domhnall Walsh <domhn...@091labs.com>
Date: Thu, 27 Sep 2012 13:25:30 +0100
Local: Thurs, Sep 27 2012 8:25 am
Subject: Re: [091labs-public] Re: ransomware in Irish

Viruses are starting to be aware of VMs, that policy could be unwise. Also,
most USB sticks don't have hardware write protect switches, which could
scupper you, particularly with a compromised BIOS.
On 27 Sep 2012 13:21, "Richard Conroy" <richard.con...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Barry Coughlan  
View profile  
 More options Sep 27 2012, 8:29 am
From: Barry Coughlan <b.coughl...@gmail.com>
Date: Thu, 27 Sep 2012 13:29:27 +0100
Local: Thurs, Sep 27 2012 8:29 am
Subject: Re: [091labs-public] ransomware in Irish

If you have a windows disc you can get it to "repair" the OS, which
overwrites any OS files which might have been modified. At least you could
with XP, presume the feature is still there in 7.

On Thu, Sep 27, 2012 at 1:11 PM, Domhnall Walsh <domhn...@091labs.com>wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alanna Kelly  
View profile  
 More options Sep 27 2012, 8:31 am
From: Alanna Kelly <amethyst...@gmail.com>
Date: Thu, 27 Sep 2012 13:31:01 +0100
Local: Thurs, Sep 27 2012 8:31 am
Subject: Re: [091labs-public] ransomware in Irish

Is this the one claiming to be from the guards?
On Sep 27, 2012 1:29 PM, "Barry Coughlan" <b.coughl...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Domhnall Walsh  
View profile  
 More options Sep 27 2012, 8:32 am
From: Domhnall Walsh <domhn...@091labs.com>
Date: Thu, 27 Sep 2012 13:32:39 +0100
Local: Thurs, Sep 27 2012 8:32 am
Subject: Re: [091labs-public] ransomware in Irish

7, like Vista, is a little different, I seem to remember. Something about
copying an image of a working install off the installer disk rather than a
file-by-file installer in the classical sense like XP.

Could be wrong on that though.
On 27 Sep 2012 13:29, "Barry Coughlan" <b.coughl...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Grealish  
View profile  
 More options Sep 27 2012, 9:08 am
From: Mark Grealish <m...@bhalash.com>
Date: Thu, 27 Sep 2012 14:08:22 +0100
Local: Thurs, Sep 27 2012 9:08 am
Subject: Re: [091labs-public] ransomware in Irish

msconfig -> Startup Programs -> Disable all.

Reboot in safe mode and run a virus scan. Also look in msconfig for details
of where the virus resides and delete the .exe there.

It's worked for me on numerous occasions for muggles' computers.

On Thu, Sep 27, 2012 at 1:32 PM, Domhnall Walsh <domhn...@091labs.com>wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
gerryk  
View profile  
 More options Sep 27 2012, 9:11 am
From: gerryk <ger...@gmail.com>
Date: Thu, 27 Sep 2012 14:11:02 +0100
Local: Thurs, Sep 27 2012 9:11 am
Subject: Re: [091labs-public] ransomware in Irish

Some of these extortion-ware things will encrypt files too, so getting the
thing off is irrelevant unless you have the decryption key too.
On Sep 27, 2012 2:08 PM, "Mark Grealish" <m...@bhalash.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Grealish  
View profile  
 More options Sep 27 2012, 9:15 am
From: Mark Grealish <m...@bhalash.com>
Date: Thu, 27 Sep 2012 14:15:05 +0100
Local: Thurs, Sep 27 2012 9:15 am
Subject: Re: [091labs-public] ransomware in Irish

Something something Reamde.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Grealish  
View profile  
 More options Sep 27 2012, 9:17 am
From: Mark Grealish <m...@bhalash.com>
Date: Thu, 27 Sep 2012 14:16:44 +0100
Local: Thurs, Sep 27 2012 9:16 am
Subject: Re: [091labs-public] ransomware in Irish

I thankfully haven't run into any ransomware that encrypts files - yet!

Is it also worth educating your father on Those Kinds Of Websites?


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Duncan Thomas  
View profile  
 More options Sep 27 2012, 9:30 am
From: Duncan Thomas <duncan.tho...@gmail.com>
Date: Thu, 27 Sep 2012 14:30:39 +0100
Local: Thurs, Sep 27 2012 9:30 am
Subject: Re: [091labs-public] ransomware in Irish
If you're really paranoid, there's an ide (pata & sata) usb write
blocking forensic copier in my pile of stuff in the corner...

On 27 September 2012 14:16, Mark Grealish <m...@bhalash.com> wrote:

--
Duncan Thomas

 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mark Grealish  
View profile  
 More options Sep 27 2012, 2:16 pm
From: Mark Grealish <m...@bhalash.com>
Date: Thu, 27 Sep 2012 19:16:27 +0100
Local: Thurs, Sep 27 2012 2:16 pm
Subject: Re: [091labs-public] ransomware in Irish

I totally want to play with that. :[

On Thu, Sep 27, 2012 at 2:30 PM, Duncan Thomas <duncan.tho...@gmail.com>wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Matthew Kolder  
View profile   Translate to Translated (View Original)
 More options Sep 27 2012, 2:51 pm
From: Matthew Kolder <matt...@091labs.com>
Date: Thu, 27 Sep 2012 19:51:45 +0100
Local: Thurs, Sep 27 2012 2:51 pm
Subject: Re: [091labs-public] ransomware in Irish

Fixed :)
On Sep 27, 2012 7:17 PM, "Mark Grealish" <m...@bhalash.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
calcrea  
View profile  
 More options Sep 27 2012, 3:00 pm
From: calcrea <calc...@gmail.com>
Date: Thu, 27 Sep 2012 12:00:56 -0700 (PDT)
Local: Thurs, Sep 27 2012 3:00 pm
Subject: Re: [091labs-public] ransomware in Irish

Not fixed! It came back straight away! :-(


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
calcrea  
View profile  
 More options Sep 27 2012, 3:22 pm
From: calcrea <calc...@gmail.com>
Date: Thu, 27 Sep 2012 12:22:45 -0700 (PDT)
Local: Thurs, Sep 27 2012 3:22 pm
Subject: Re: [091labs-public] ransomware in Irish

Donal? Could you let me know when you're around? Please


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alanna Kelly  
View profile  
 More options Sep 27 2012, 3:26 pm
From: Alanna Kelly <amethyst...@gmail.com>
Date: Thu, 27 Sep 2012 20:26:50 +0100
Local: Thurs, Sep 27 2012 3:26 pm
Subject: Re: [091labs-public] ransomware in Irish

Everyone thinks it's fixed until the RTQA...
On Sep 27, 2012 8:00 PM, "calcrea" <calc...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Domhnall Walsh  
View profile  
 More options Sep 27 2012, 3:31 pm
From: Domhnall Walsh <domhn...@091labs.com>
Date: Thu, 27 Sep 2012 20:31:36 +0100
Local: Thurs, Sep 27 2012 3:31 pm
Subject: Re: [091labs-public] ransomware in Irish

Around 10ish?
On 27 Sep 2012 20:22, "calcrea" <calc...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
calcrea  
View profile  
 More options Sep 27 2012, 3:36 pm
From: calcrea <calc...@gmail.com>
Date: Thu, 27 Sep 2012 12:36:37 -0700 (PDT)
Local: Thurs, Sep 27 2012 3:36 pm
Subject: Re: [091labs-public] ransomware in Irish

Im here all night. thanks mate :-)


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Duncan Thomas  
View profile  
 More options Sep 27 2012, 2:19 pm
From: Duncan Thomas <duncan.tho...@gmail.com>
Date: Thu, 27 Sep 2012 19:19:03 +0100
Local: Thurs, Sep 27 2012 2:19 pm
Subject: Re: [091labs-public] ransomware in Irish

It'll be there when you re next about
On Sep 27, 2012 7:16 PM, "Mark Grealish" <m...@bhalash.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Domhnall Walsh  
View profile  
 More options Sep 28 2012, 11:23 am
From: Domhnall Walsh <domhn...@091labs.com>
Date: Fri, 28 Sep 2012 16:23:05 +0100
Local: Fri, Sep 28 2012 11:23 am
Subject: Re: [091labs-public] ransomware in Irish

I _think_ I have this sorted...
On 28 Sep 2012 16:19, "Duncan Thomas" <duncan.tho...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mac Eoin, Paul  
View profile  
 More options Sep 28 2012, 11:30 am
From: "Mac Eoin, Paul" <paul.mace...@gmail.com>
Date: Fri, 28 Sep 2012 16:29:56 +0100
Local: Fri, Sep 28 2012 11:29 am
Subject: Re: [091labs-public] ransomware in Irish

What did you do? This is the kind of thing my grandad would get on his
computer and probably happily pay up.

Is there any simple way to prevent against these kind of attacks?

On 28 September 2012 16:23, Domhnall Walsh <domhn...@091labs.com> wrote:

--
Paul Mac Eoin

Irish Mobile (Three): (+353) 87 126 37 58
Skype: paul.mac.eoin

paul.mace...@gmail.com <pmaceo...@mail.gatech.edu>


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Messages 1 - 25 of 30   Newer >
« Back to Discussions « Newer topic     Older topic »