Recent Topics
Oil for 2015 Ford Explorer
by oilnut12. 03/23/19 12:48 AM
Blains farm and fleet citgo syn
by BTLew81. 03/22/19 10:48 PM
2003 Duramax 208, XXX miles Rotella T4
by TurboJW. 03/22/19 08:11 PM
Turn signals on the freeway?
by das_peikko. 03/22/19 08:05 PM
Running Boards Restored
by kstanf150. 03/22/19 07:38 PM
QSUD at Canadian Tire
by Snagglefoot. 03/22/19 07:29 PM
Camry vs Accord vs ???
by Joe1. 03/22/19 07:26 PM
Fire up
by Matagonka. 03/22/19 07:16 PM
Mobil-1 AFE Discounted at Sam's Club
by ekpolk. 03/22/19 06:20 PM
Test drove a Tesla Model 3
by y_p_w. 03/22/19 05:54 PM
Did i make a mistake? Hilux 3.0 d4dhello
by Anton93. 03/22/19 05:52 PM
WM Valvoline Full Syn Modern Eng Clearance
by Spartanfool. 03/22/19 04:22 PM
Need Moly basic training
by Bill_W. 03/22/19 04:03 PM
P0420 code goes away in warmer weather
by 2010Civic. 03/22/19 03:54 PM
Customer declined new belt
by Chris142. 03/22/19 03:13 PM
How to deep clean back of wheels?
by qdeezie. 03/22/19 02:51 PM
RK oil sale T4 15w40
by 1978elcamino. 03/22/19 01:57 PM
Hello and goodbye to my old job
by Motorking. 03/22/19 01:52 PM
Newest Members
duradick, Harold1031, Skendread, NGK, Thomas1
67589 Registered Users
Who's Online Now
26 registered members (4WD, bmod305, Bjornviken, anndel, billt460, 4 invisible), 495 guests, and 56 spiders.
Key: Admin, Global Mod, Mod
Forum Statistics
Forums67
Topics286,265
Posts4,905,499
Members67,589
Most Online2,967
Mar 10th, 2019
Donate to BITOG
Hop To
Petya GoldenEye Ransomware Tips #4444125
06/28/17 05:02 PM
06/28/17 05:02 PM
Joined: May 2009
Posts: 2,397
WA (USA)
Y_K Offline OP
Y_K  Offline OP

Joined: May 2009
Posts: 2,397
WA (USA)

Last edited by wwillson; 06/28/17 07:53 PM. Reason: subject clarification
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444220
06/28/17 07:15 PM
06/28/17 07:15 PM
Joined: Apr 2016
Posts: 815
Specific Ocean
Kibitoshin Offline
Kibitoshin  Offline

Joined: Apr 2016
Posts: 815
Specific Ocean
All I can say is keep your OS updated, don't open attachments from unknown senders and stay away from bad parts of the internet (sites, DL's, etc.)
Also having strong network security helps too.


Shin Gekiretsu Shin'ou'hou
01 Toyota Tundra 2WD V8 4.7L
02 Chevy Silverado C1500 V8 5.3L
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444499
06/29/17 03:07 AM
06/29/17 03:07 AM
Joined: May 2009
Posts: 2,397
WA (USA)
Y_K Offline OP
Y_K  Offline OP

Joined: May 2009
Posts: 2,397
WA (USA)
Informational post from ESET

MBR is also a big factor in this game

Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444862
06/29/17 11:44 AM
06/29/17 11:44 AM
Joined: Mar 2016
Posts: 492
burlington ,ontario, canada
ndfergy Offline
ndfergy  Offline

Joined: Mar 2016
Posts: 492
burlington ,ontario, canada
Thanks for the tip on the ports 445 tcp & udp; I've gone ahead and blocked them on all my computers.

As far as smbv1 I've had that disabled since W8. Contrary to your link and from what I've read Vista and W7 requires you to manually disable smbv1. To do this open Powershell as an administrator then paste/enter/restart the following:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 0 -Force

If discovered you require this protocol with legacy devices to re-enable repeat with below:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 1 -Force

Last edited by ndfergy; 06/29/17 11:49 AM. Reason: spelling

2015 Toyota Yaris 5spd Manual
Summer: Mobil Super 1000 10w30
Winter: Mobil Super 1000 5w30
OEM Filter
Re: Petya GoldenEye Ransomware Tips [Re: ndfergy] #4445586
06/30/17 01:02 AM
06/30/17 01:02 AM
Joined: May 2009
Posts: 2,397
WA (USA)
Y_K Offline OP
Y_K  Offline OP

Joined: May 2009
Posts: 2,397
WA (USA)
Thank you. And from the latest dispatches it looks like the hackers cannot decrypt even if you pay the ransom. One way trip.

Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4445643
06/30/17 06:13 AM
06/30/17 06:13 AM
Joined: Dec 2009
Posts: 26,893
Regina, Saskatchewan, Canada
Garak Online content
Garak  Online Content

Joined: Dec 2009
Posts: 26,893
Regina, Saskatchewan, Canada
I had read something about their email being shut down, so that's handy. wink


Plain, simple Garak.

2008 Infiniti G37 - Shell ROTELLA T6 Multi-Vehicle 5w-30, Wix 57356
1984 F-150 4.9L - Quaker State GB 10w-30, Wix 51515
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4445817
06/30/17 09:51 AM
06/30/17 09:51 AM
Joined: May 2015
Posts: 2,151
America
Alfred_B Offline
Alfred_B  Offline

Joined: May 2015
Posts: 2,151
America
Yeah, the ransom itself was a very small amount. But the victim had to send the transaction ID and the ransomware attack ID to an email address hosted in Germany. The Germans disabled the email so the victims are SOL.

I'm sure the attacker will come up with an alternate solution, it's not a good customer service to leave paying victims unhappy. Not good for business.

Re: Petya GoldenEye Ransomware Tips [Re: Alfred_B] #4445934
06/30/17 12:24 PM
06/30/17 12:24 PM
Joined: Nov 2008
Posts: 9,601
Phoenix
dishdude Online content
dishdude  Online Content

Joined: Nov 2008
Posts: 9,601
Phoenix
Originally Posted By: Alfred_B

I'm sure the attacker will come up with an alternate solution, it's not a good customer service to leave paying victims unhappy. Not good for business.


Now that's funny!


2018 Challenger SRT 392 PUP 0w-40 Wix 57899XP
2018 GTI
Previous Thread
Index
Next Thread

BOB IS THE OIL GUY® Powered by UBB.threads™