Page 1 of 1
my O/S kernel project has been hacked with ransomware.
Posted: Mon Sep 10, 2018 10:16 pm
by ggodw000
Project was well maintained and was using VM as a boot target and now it has been hacked with
[email protected].
Other than this project, there is not much else worth saving. If can not save, I have to restart everything
(((
my Full post at security forum is here:
https://www.cnet.com/forums/discussions ... elpqq-com/
Re: my O/S kernel project has been hacked with ransomware.
Posted: Mon Sep 10, 2018 11:37 pm
by iansjack
Is this a plain-text, source-code distribution or is it binaries?
Re: my O/S kernel project has been hacked with ransomware.
Posted: Tue Sep 11, 2018 2:47 am
by Solar
Generally speaking, if you have a halfway-recent backup of your "productive" files (as you should), use that and just don't bother with "recovery". Your system was infected. You cannot trust it anymore.
Do a clean format of your hard drive(s). Reinstall your OS. Scan your backup thoroughly for malware, and recover "productive" files only. (I.e., recover source files, personal photos etc., but do set up third-party software from scratch.)
Re: my O/S kernel project has been hacked with ransomware.
Posted: Tue Sep 11, 2018 2:56 am
by Octocontrabass
https://www.nomoreransom.org/
If you're lucky, a decryption tool may already exist. Otherwise, you'll have to start over from scratch, with better backups this time.
Re: my O/S kernel project has been hacked with ransomware.
Posted: Tue Sep 11, 2018 5:17 pm
by ggodw000
Solar wrote:Generally speaking, if you have a halfway-recent backup of your "productive" files (as you should), use that and just don't bother with "recovery". Your system was infected. You cannot trust it anymore.
Do a clean format of your hard drive(s). Reinstall your OS. Scan your backup thoroughly for malware, and recover "productive" files only. (I.e., recover source files, personal photos etc., but do set up third-party software from scratch.)
i should have and laxed and now paid the price. I backed up onto bitlocker encrypted usb HDD 1TB everything in my NAS drive.
Once if i managed to recover the VMM HDDs on which everything I have, I am going to wipe that infected drive!
It may still be possible that something could have jumped to the firmware of the low-end HP server I have but I am going to assume it has not happened.
That is after I dc-d infected drive and re-installed fresh Win server onto another drive, so far nothing happened.
Re: my O/S kernel project has been hacked with ransomware.
Posted: Tue Sep 11, 2018 5:18 pm
by ggodw000
Octocontrabass wrote:https://www.nomoreransom.org/
If you're lucky, a decryption tool may already exist. Otherwise, you'll have to start over from scratch, with better backups this time.
This is a good one, thanks! First I think I will duplicate the hdd.
Few years back, I made DOS utility that actually duplicates the entire drive using INT 13h calls, fair amout of work but simple, but alas, lost the code.
Re: my O/S kernel project has been hacked with ransomware.
Posted: Tue Sep 11, 2018 10:01 pm
by ggodw000
regarding cloning, i recall now linux's dd utility should do the trick as it performs block by block copy.
dd if=/dev/sd<source> of=/dev/sd<target>
Re: my O/S kernel project has been hacked with ransomware.
Posted: Fri Sep 14, 2018 10:12 am
by ggodw000
duplication is done using linux dd. booted to both hdd and booting to exactly same image. now real work begins!
Re: my O/S kernel project has been hacked with ransomware.
Posted: Sun Sep 16, 2018 2:26 pm
by ggodw000
Good and bad new. But good one prevailed. Will start with bad news:
i fired up the infected PC and went to nomoreransom.org and they identified one of the file successfully with cryptoxxx. Two tools from uTrend and kasp. failed to work.
Good ones, decided to search for backup of hyperv file on my NAS drive and YES!! within second it shows that I saved all hyperv vhdd-s on that folder. I only to reconstruct VM now. I am going to write to
[email protected] to give 'em some wild goose chase. Perhaps negotiate down to 25c for decryption help and if not agree tell 'em F-off!!