Ransomware Question


  1. Posts : 156
    10
       #1

    Ransomware Question


    Someone I had a shared dropbox folder with was infected with ransomware. As of now, I do not beleive I am infected. i went ahead and left the shares. I scanned with malwarebytes, hitmanpro, and windows defender and it say my machine is clean. Is there anything else I should look for?
      My Computer


  2. 1PW
    Posts : 370
    W10
       #2

    Hello rinconmike

    The advice received at https://forums.malwarebytes.com/topi...45-ransomware/ is by far the best you will find. An experienced professional can soon render an accurate assessment after a thorough analysis of the system in question.

    HTH
      My Computers


  3. Posts : 7,607
    Windows 10 Home 20H2
       #3

    If a PC is infected with ransomware, it takes seconds to encrypt the files. The user possibly has no time to run a scan or do an analysis.
      My Computer


  4. Posts : 156
    10
    Thread Starter
       #4

    I will head over to malwarebytes forum. But if I my system was infected via dropbox files, would it be obvious?
      My Computer


  5. Posts : 7,607
    Windows 10 Home 20H2
       #5

    Do you think ransomware would delay encryption if it got into your system via DropBox?
      My Computer


  6. Posts : 156
    10
    Thread Starter
       #6

    I am not sure.
      My Computer


  7. Posts : 8,114
    windows 10
       #7

    Which ransomeware was it as it make a difference
      My Computer


  8. Posts : 156
    10
    Thread Starter
       #8

    I am not sure. A company I work with was hit. I am not on their network. They have dropbox on a server and internally map network drives for local users. Then for other users they share dropbox folders. I had 3 folders shared. After I found out the issue, I removed the share from my dropbox. I did not inspect the content of those folders. I have DB on three machines so three machines had those folders but all removed when I removed the share.

    The ransomware hit the printers and the printers printed out this file.

    Ransomware Note 2020-10-16a
    Ransomware Question-ransomware-note-2020-10-16a.jpg
    Last edited by rinconmike; 17 Oct 2020 at 10:17.
      My Computer


  9. Posts : 8,114
    windows 10
       #9

    That doesnt help some there is a decrypter for and some go to sleep and then wake in the future
      My Computer


  10. Posts : 1,807
    Windows 10 Pro 21H1 19043.1348
       #10

    rinconmike said:
    I am not sure. A company I work with was hit. I am not on their network. They have dropbox on a server and internally map network drives for local users. Then for other users they share dropbox folders. I had 3 folders shared. After I found out the issue, I removed the share from my dropbox. I did not inspect the content of those folders. I have DB on three machines so three machines had those folders but all removed when I removed the share.

    The ransomware hit the printers and the printers printed out this file.

    Ransomware Note 2020-10-16a.pdf

    This type of information is best shared using an image file.

    Ransomware Question-001-insert-image.jpg


    Ransomware Question-1017-ransomware-threat.jpg


    Not that it changes anything with how this threat is dealt with but I'm just always curious to know more about the origins.
    To satisfy my own curiosity and any others that might care...


    Ransomware Question-1017-tracert-egregor.top.jpg


    Ransomware Question-1017-whois-gw.eu.hosting.jpg

    This hosting site does not appear to be blacklisted meaning they may or may not be legit.
    Last edited by W10 Tweaker; 17 Oct 2020 at 10:39.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:28.
Find Us




Windows 10 Forums