Recent Topics
Toyota 2TR-FE 2.7 questions
by Doublehaul. 12/12/18 12:32 AM
Anybody used Eurolub?
by FordCapriDriver. 12/12/18 12:18 AM
Micro-Green Cut Open
by David1. 12/11/18 11:45 PM
Witch way does this valve work?
by Dylan1303. 12/11/18 11:42 PM
Santa came early..
by leoblack9. 12/11/18 11:22 PM
dropped a zip tie in my prius trans
by eljefino. 12/11/18 09:54 PM
2 Cello's - Some talented fellows right here.
by StevieC. 12/11/18 09:49 PM
Something different for sure - Punjabi Celtic
by StevieC. 12/11/18 09:40 PM
Honda eu200i hiccuping @ low idle - fixed
by Jmoney7269. 12/11/18 09:34 PM
Your dealer is here - Humor
by StevieC. 12/11/18 08:46 PM
1994 Honda Civic LX Main Relay-solder
by Gito. 12/11/18 08:43 PM
Winter/Summer Fuel Economy
by RayCJ. 12/11/18 08:33 PM
0w20 oils - NOACK
by superangrypenguin. 12/11/18 08:19 PM
Liqui Moly Special Tec AA 5w20 API SN
by Johnny248. 12/11/18 08:15 PM
Buy a brand new 1966-1977 Ford Bronco
by StevieC. 12/11/18 07:50 PM
2012 Accord,QSUD 5W20,WIX 57356 filter,3K miles
by aquariuscsm. 12/11/18 07:05 PM
Check out this awsome work!
by Chris142. 12/11/18 06:47 PM
200,000 miles
by Marco620. 12/11/18 06:29 PM
Newest Members
tcoffin014, Schm1d, EagleC, Dinka, MechanicGuy
66654 Registered Users
Who's Online Now
27 registered members (ArrestMeRedZ, A_A_G, Billbert, Char Baby, 1WildPig, 2 invisible), 914 guests, and 35 spiders.
Key: Admin, Global Mod, Mod
Forum Statistics
Forums67
Topics294,961
Posts4,924,845
Members66,654
Most Online2,553
Oct 27th, 2018
Donate to BITOG
Previous Thread
Next Thread
Print Thread
Hop To
Petya GoldenEye Ransomware Tips #4444125
06/28/17 04:02 PM
06/28/17 04:02 PM
Joined: May 2009
Posts: 2,304
WA (USA)
Y_K Offline OP
Y_K  Offline OP
Joined: May 2009
Posts: 2,304
WA (USA)

Last edited by wwillson; 06/28/17 06:53 PM. Reason: subject clarification
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444220
06/28/17 06:15 PM
06/28/17 06:15 PM
Joined: Apr 2016
Posts: 781
Specific Ocean
Kibitoshin Offline
Kibitoshin  Offline
Joined: Apr 2016
Posts: 781
Specific Ocean
All I can say is keep your OS updated, don't open attachments from unknown senders and stay away from bad parts of the internet (sites, DL's, etc.)
Also having strong network security helps too.


Shin Gekiretsu Shin'ou'hou
01 Toyota Tundra 2WD V8 4.7L
02 Chevy Silverado C1500 V8 5.3L
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444499
06/29/17 02:07 AM
06/29/17 02:07 AM
Joined: May 2009
Posts: 2,304
WA (USA)
Y_K Offline OP
Y_K  Offline OP
Joined: May 2009
Posts: 2,304
WA (USA)
Informational post from ESET

MBR is also a big factor in this game


"This forum talking about 4wd systems is like when other forums talk about oil."
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444862
06/29/17 10:44 AM
06/29/17 10:44 AM
Joined: Mar 2016
Posts: 484
burlington ,ontario, canada
ndfergy Offline
ndfergy  Offline
Joined: Mar 2016
Posts: 484
burlington ,ontario, canada
Thanks for the tip on the ports 445 tcp & udp; I've gone ahead and blocked them on all my computers.

As far as smbv1 I've had that disabled since W8. Contrary to your link and from what I've read Vista and W7 requires you to manually disable smbv1. To do this open Powershell as an administrator then paste/enter/restart the following:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 0 -Force

If discovered you require this protocol with legacy devices to re-enable repeat with below:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 1 -Force

Last edited by ndfergy; 06/29/17 10:49 AM. Reason: spelling

2015 Toyota Yaris 5spd Manual
Summer: Mobil Super 1000 10w30
Winter: Mobil Super 1000 5w30
OEM Filter
Re: Petya GoldenEye Ransomware Tips [Re: ndfergy] #4445586
06/30/17 12:02 AM
06/30/17 12:02 AM
Joined: May 2009
Posts: 2,304
WA (USA)
Y_K Offline OP
Y_K  Offline OP
Joined: May 2009
Posts: 2,304
WA (USA)
Thank you. And from the latest dispatches it looks like the hackers cannot decrypt even if you pay the ransom. One way trip.


"This forum talking about 4wd systems is like when other forums talk about oil."
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4445643
06/30/17 05:13 AM
06/30/17 05:13 AM
Joined: Dec 2009
Posts: 26,192
Regina, Saskatchewan, Canada
Garak Online content
Garak  Online Content
Joined: Dec 2009
Posts: 26,192
Regina, Saskatchewan, Canada
I had read something about their email being shut down, so that's handy. wink


Plain, simple Garak.

2008 Infiniti G37 - Shell ROTELLA T6 Multi-Vehicle 5w-30, NAPA Gold 7356
1984 F-150 4.9L - Quaker State GB 10w-30, Wix 51515
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4445817
06/30/17 08:51 AM
06/30/17 08:51 AM
Joined: May 2015
Posts: 2,009
America
Alfred_B Offline
Alfred_B  Offline
Joined: May 2015
Posts: 2,009
America
Yeah, the ransom itself was a very small amount. But the victim had to send the transaction ID and the ransomware attack ID to an email address hosted in Germany. The Germans disabled the email so the victims are SOL.

I'm sure the attacker will come up with an alternate solution, it's not a good customer service to leave paying victims unhappy. Not good for business.

Re: Petya GoldenEye Ransomware Tips [Re: Alfred_B] #4445934
06/30/17 11:24 AM
06/30/17 11:24 AM
Joined: Nov 2008
Posts: 9,277
Phoenix
dishdude Offline
dishdude  Offline
Joined: Nov 2008
Posts: 9,277
Phoenix
Originally Posted By: Alfred_B

I'm sure the attacker will come up with an alternate solution, it's not a good customer service to leave paying victims unhappy. Not good for business.


Now that's funny!


2018 Challenger SRT 392 PUP 0w-40 Wix 57899XP
2018 GTI

BOB IS THE OIL GUY® Powered by UBB.threads™