Recent Topics
Crown Victoria HVAC repair
by emmett442. 09/24/18 08:44 AM
2007 Toyota Camry LE Alternator
by maverickfhs. 09/24/18 08:28 AM
AutoSense drying not drying
by Ifixyawata. 09/24/18 08:23 AM
Time for a new Generator... Wisdom desired!
by webfors. 09/24/18 06:36 AM
flat roof weight bearing support
by henni. 09/24/18 06:29 AM
ADD A MARBLE - Make Life Easier
by MasterSolenoid. 09/24/18 06:17 AM
Mobile 1 ESP @ Dowler Karn St. Thomas Ont
by RogerBacon. 09/24/18 05:40 AM
Mobile 1 ESP @ Dowler Karn St. Thomas Ont.
by RogerBacon. 09/24/18 05:37 AM
Direct Injection Valve Cleaning Maintenance
by RayCJ. 09/24/18 05:20 AM
Chattanooga tn ,cycling
by CourierDriver. 09/24/18 04:42 AM
Sunrise, Sunset
by csandste. 09/24/18 02:39 AM
Adding fuel filter- Generator built with no filter
by rubberchicken. 09/23/18 09:57 PM
Clutch Engaging too low
by Spetz. 09/23/18 09:41 PM
SMA - Krown previously, Fluid Film Application
by StevieC. 09/23/18 09:21 PM
First Paint Correction
by RayCJ. 09/23/18 08:33 PM
2011 Dodge Caliber
by dogememe. 09/23/18 07:48 PM
Mixing transmission fluids - partial change
by spk2000. 09/23/18 07:31 PM
Newest Members
Lilshady, SevenDu, sigpro, RayCJ, yellow97tt6spd
66055 Registered Users
Who's Online Now
71 registered members (92saturnsl2, 4WD, ARCOgraphite, 1JCB, 65convertible, 2010Civic, 12 invisible), 1,554 guests, and 33 spiders.
Key: Admin, Global Mod, Mod
Forum Statistics
Forums67
Topics290,931
Posts4,852,655
Members66,055
Most Online3,590
Jan 24th, 2017
Donate to BITOG
Previous Thread
Next Thread
Print Thread
Hop To
Petya GoldenEye Ransomware Tips #4444125
06/28/17 05:02 PM
06/28/17 05:02 PM
Joined: May 2009
Posts: 2,236
WA (USA)
Y_K Offline OP
Y_K  Offline OP
Joined: May 2009
Posts: 2,236
WA (USA)

Last edited by wwillson; 06/28/17 07:53 PM. Reason: subject clarification
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444220
06/28/17 07:15 PM
06/28/17 07:15 PM
Joined: Apr 2016
Posts: 753
Specific Ocean
Kibitoshin Offline
Kibitoshin  Offline
Joined: Apr 2016
Posts: 753
Specific Ocean
All I can say is keep your OS updated, don't open attachments from unknown senders and stay away from bad parts of the internet (sites, DL's, etc.)
Also having strong network security helps too.


Shin Gekiretsu Shin'ou'hou
01 Toyota Tundra 2WD V8 4.7L - 170k mi
02 Chevy Silverado C1500 V8 5.3L 154k mi
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444499
06/29/17 03:07 AM
06/29/17 03:07 AM
Joined: May 2009
Posts: 2,236
WA (USA)
Y_K Offline OP
Y_K  Offline OP
Joined: May 2009
Posts: 2,236
WA (USA)
Informational post from ESET

MBR is also a big factor in this game


"This forum talking about 4wd systems is like when other forums talk about oil." © 2018 FlyPenFly
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4444862
06/29/17 11:44 AM
06/29/17 11:44 AM
Joined: Mar 2016
Posts: 466
burlington ,ontario, canada
ndfergy Offline
ndfergy  Offline
Joined: Mar 2016
Posts: 466
burlington ,ontario, canada
Thanks for the tip on the ports 445 tcp & udp; I've gone ahead and blocked them on all my computers.

As far as smbv1 I've had that disabled since W8. Contrary to your link and from what I've read Vista and W7 requires you to manually disable smbv1. To do this open Powershell as an administrator then paste/enter/restart the following:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 0 -Force

If discovered you require this protocol with legacy devices to re-enable repeat with below:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 1 -Force

Last edited by ndfergy; 06/29/17 11:49 AM. Reason: spelling

2015 Toyota Yaris 5spd Manual
Summer: Mobil Super 1000 10w30
Winter: Mobil Super 1000 5w30
OEM Filter
Re: Petya GoldenEye Ransomware Tips [Re: ndfergy] #4445586
06/30/17 01:02 AM
06/30/17 01:02 AM
Joined: May 2009
Posts: 2,236
WA (USA)
Y_K Offline OP
Y_K  Offline OP
Joined: May 2009
Posts: 2,236
WA (USA)
Thank you. And from the latest dispatches it looks like the hackers cannot decrypt even if you pay the ransom. One way trip.


"This forum talking about 4wd systems is like when other forums talk about oil." © 2018 FlyPenFly
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4445643
06/30/17 06:13 AM
06/30/17 06:13 AM
Joined: Dec 2009
Posts: 25,400
Regina, Saskatchewan, Canada
Garak Offline
Garak  Offline
Joined: Dec 2009
Posts: 25,400
Regina, Saskatchewan, Canada
I had read something about their email being shut down, so that's handy. wink


Plain, simple Garak.

2008 Infiniti G37 - Shell ROTELLA T6 Multi-Vehicle 5w-30, NAPA Gold 7356
1984 F-150 4.9L - Quaker State GB 10w-30, Wix 51515
Re: Petya GoldenEye Ransomware Tips [Re: Y_K] #4445817
06/30/17 09:51 AM
06/30/17 09:51 AM
Joined: May 2015
Posts: 1,992
America
Alfred_B Offline
Alfred_B  Offline
Joined: May 2015
Posts: 1,992
America
Yeah, the ransom itself was a very small amount. But the victim had to send the transaction ID and the ransomware attack ID to an email address hosted in Germany. The Germans disabled the email so the victims are SOL.

I'm sure the attacker will come up with an alternate solution, it's not a good customer service to leave paying victims unhappy. Not good for business.

Re: Petya GoldenEye Ransomware Tips [Re: Alfred_B] #4445934
06/30/17 12:24 PM
06/30/17 12:24 PM
Joined: Nov 2008
Posts: 9,046
Phoenix
dishdude Offline
dishdude  Offline
Joined: Nov 2008
Posts: 9,046
Phoenix
Originally Posted By: Alfred_B

I'm sure the attacker will come up with an alternate solution, it's not a good customer service to leave paying victims unhappy. Not good for business.


Now that's funny!


2018 Challenger SRT

BOB IS THE OIL GUY® Powered by UBB.threads™