New global ransomware attack hits East Europe and spreading

Page 3 of 10 FirstFirst 12345 ... LastLast

  1. Posts : 30,591
    Windows 10 (Pro and Insider Pro)
    Thread Starter
       #21

    lx07 said:
    Ah interesting, I missed that bit. These only work if you are running Admin account (or with Admin rights) though correct?
    Correct.
      My Computers


  2. Posts : 3,105
    W10 Pro + W10 Preview
       #22

    This was not ransomware....more than likely industrial espionage....why would the perpetrator leave an easily traceable calling address?
    This has already been shut down.....so financial gain was not the motive.
      My Computers


  3. Posts : 7,898
    Windows 11 Pro 64 bit
       #23

    AndreTen said:
    Thanks for warning Steve. One can usually trust the guys at Bleeping Computers. Will check it out. Kaspersky could react to changes in Windows dir...

    Edit: can't imagine what would trigger Kaspersky, except that it just reacts to creating files in C:\Windows..

    There are just 3 files, filled with some text (don't delete this.. is a vaccine ...) named perfc, perfc.dll and perfc.somtething else
    Does anyone know why that batch file inserts 3 perfc files whereas the manual fix just creates the file perfc (read only)? I've used a manual fix since Kaspersky Antivirus deletes perfc.dat created by the batch file.

    I just ran Notepad as Admin, saved the empty file as c:\windows\perfc, then made two further copies of perfc and renamed them perfc.dll and perfc.dat. Finally I set them to be read only. Kaspersky antivirus doesn't object when you do it this way.
      My Computers


  4. Posts : 30,591
    Windows 10 (Pro and Insider Pro)
    Thread Starter
       #24

    Steve C said:
    Does anyone know why that batch file inserts 3 perfc files whereas the manual fix just creates the file perfc (read only)? I've used the manual fix since Kaspersky Antivirus deletes perfc.dat created by the batch file.
    I have no idea... It was mentioned somewhere, that this vaccine isn't futureproof. Malware makers could easily change its behavior. Perhaps it's something in that direction...

    Once more: all major AV and antimalware suites are updated and are blocking it (including Windows defender)
      My Computers


  5. Posts : 56,825
    Multi-boot Windows 10/11 - RTM, RP, Beta, and Insider
       #25

    dencal said:
    This was not ransomware....more than likely industrial espionage....why would the perpetrator leave an easily traceable calling address?
    This has already been shut down.....so financial gain was not the motive.
    Muscle flexing and diversion.....what's the real target?
      My Computers


  6. Posts : 5,478
    2004
       #26

    Steve C said:
    Does anyone know why that batch file inserts 3 perfc files whereas the manual fix just creates the file perfc (read only)? I've used the manual fix since Kaspersky Antivirus deletes perfc.dat created by the batch file.
    If you look at the link in the batchfile twitter.com/0xAmit/status/879778335286452224 various people are arguing about whether perfc (no extension), perfc.dat or perfc.dll are required. I guess the writer of the file stuck them all in to be on the safe side.
      My Computer


  7. Posts : 3,105
    W10 Pro + W10 Preview
       #27

    f14tomcat said:
    Muscle flexing and diversion.....what's the real target?
    Either some curious kid in a back room seeing how clever he is.....or more worryingly a nation seeking superiority by paralysing vital industries, bringing countries to a standstill......most modern warfare is conducted using computerised technology, ie- aeroplanes, ships, missiles, orbiting space satellites etc.....all could be rendered completely ineffective......frightening isn't it.
      My Computers


  8. Posts : 7,898
    Windows 11 Pro 64 bit
       #28

    lx07 said:
    If you look at the link in the batchfile twitter.com/0xAmit/status/879778335286452224 various people are arguing about whether perfc (no extension), perfc.dat or perfc.dll are required. I guess the writer of the file stuck them all in to be on the safe side.
    Thanks - I just created the 3 files manually as Post 23.
      My Computers


  9. Posts : 91
    Windows 10
       #29

    Forgive me if this is a silly question, but how does the malware get into one's computer? Infected executable attachment, drive-by download, download via malicious link in an email..?
      My Computer


  10. Posts : 3,105
    W10 Pro + W10 Preview
       #30

    Smiley1 said:
    Forgive me if this is a silly question, but how does the malware get into one's computer? Infected executable attachment, drive-by download, download via malicious link in an email..?
    In this particular case it appears to have infiltrated a software update.
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:36.
Find Us




Windows 10 Forums