Calgarypuck Forums - The Unofficial Calgary Flames Fan Community
Old 11-07-2013, 04:37 PM   #21
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Kind of a related note, but if I was running IT in a lawyers office without a working backup to recover from Cryptolocker (or any other of the dozens of things that can happen to data), I would expect to be looking to a job really quickly.

That's completely irresponsible.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
The Following 7 Users Say Thank You to Rathji For This Useful Post:
Old 11-07-2013, 04:40 PM   #22
cKy
First Line Centre
 
Join Date: Jan 2008
Location: Okotoks
Exp:
Default

I agree. It doesnt matter how big or small that firm is, any type of sequential backup should be mandatory.
__________________

cKy is offline   Reply With Quote
Old 11-07-2013, 05:10 PM   #23
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Quote:
Originally Posted by Rathji View Post
Kind of a related note, but if I was running IT in a lawyers office without a working backup to recover from Cryptolocker (or any other of the dozens of things that can happen to data), I would expect to be looking to a job really quickly.

That's completely irresponsible.
But, but, IT is an expense that doesn't add to the bottom line of the company!
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
The Following 5 Users Say Thank You to photon For This Useful Post:
Old 11-08-2013, 07:16 AM   #24
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Quote:
Originally Posted by photon View Post
But, but, IT is an expense that doesn't add to the bottom line of the company!
Every business owner is entitled to their potentially company destroying budget decisions.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
The Following 2 Users Say Thank You to Rathji For This Useful Post:
Old 11-08-2013, 09:02 AM   #25
Inglewood Jack
#1 Goaltender
 
Inglewood Jack's Avatar
 
Join Date: Jan 2012
Exp:
Default

the fact that more than one person here has already been ransomed freaks me out a little. is this thing able to slip by your standard run of the mill antivirus software? or were the infections mentioned here cases where there was none or outdated AV?
Inglewood Jack is online now   Reply With Quote
Old 11-08-2013, 10:13 AM   #26
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Quote:
Originally Posted by Inglewood Jack View Post
the fact that more than one person here has already been ransomed freaks me out a little. is this thing able to slip by your standard run of the mill antivirus software? or were the infections mentioned here cases where there was none or outdated AV?
It really doesn't make much difference. The virus is in active development, and as a result will be adjusting to defense or removal methods. For example, early versions allowed for you to restore from previous versions, but the new versions don't.


You can't rely on AV to protect you from this. You need a cold backup.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
The Following User Says Thank You to Rathji For This Useful Post:
Old 11-08-2013, 10:28 AM   #27
MolsonInBothHands
First Line Centre
 
Join Date: Aug 2002
Exp:
Default

Quote:
Originally Posted by Rathji View Post
Kind of a related note, but if I was running IT in a lawyers office without a working backup to recover from Cryptolocker (or any other of the dozens of things that can happen to data), I would expect to be looking to a job really quickly.

That's completely irresponsible.
They were using a cloud backup service. It got to it.
__________________
"Cammy just threw them in my locker & told me to hold on to them." - Giordano on the pencils from Iggy's stall.
MolsonInBothHands is offline   Reply With Quote
Old 11-08-2013, 10:31 AM   #28
Mccree
#1 Goaltender
 
Join Date: Sep 2003
Location: Calgary
Exp:
Default

Is this an executable type virus or does come the pdf's and other type of files?
__________________

Mccree is offline   Reply With Quote
Old 11-08-2013, 11:31 AM   #29
Ace
First Line Centre
 
Ace's Avatar
 
Join Date: Oct 2002
Exp:
Default

Quote:
Originally Posted by MolsonInBothHands View Post
They were using a cloud backup service. It got to it.
Even if they had a static back up the evil genius thing here is that it's going to be cheaper for the company to just pay the ransom, rather than restore from back-up.
__________________
Ace is offline   Reply With Quote
Old 11-08-2013, 11:45 AM   #30
Stealth22
Powerplay Quarterback
 
Join Date: Nov 2010
Exp:
Default

Quote:
Originally Posted by Ace View Post
Even if they had a static back up the evil genius thing here is that it's going to be cheaper for the company to just pay the ransom, rather than restore from back-up.
Exactly.

For most companies, $300 is a drop in the bucket, especially compared to 2 or 3 days worth of hours for the entire IT team to restore from a backup, and then make sure that everything is up and running properly.
Stealth22 is offline   Reply With Quote
Old 11-08-2013, 04:36 PM   #31
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Turns out the new version has an extended pay period in case you didn't make the 3 day cutoff.

Its a bit more expensive, at 10 bitcoins... which is over $3000 by today's pricing.

As for the company in question: The online backup had no versioning or iterative backup? Ouch.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
Old 11-08-2013, 05:44 PM   #32
blankall
Ate 100 Treadmills
 
blankall's Avatar
 
Join Date: Mar 2006
Exp:
Default

Quote:
Originally Posted by Mccree View Post
Is this an executable type virus or does come the pdf's and other type of files?
I most definitely did not run an exe file. It came on another file and my guess was triggered by my AV when it went to delete it.
blankall is offline   Reply With Quote
The Following User Says Thank You to blankall For This Useful Post:
Old 02-12-2015, 12:29 AM   #33
blankall
Ate 100 Treadmills
 
blankall's Avatar
 
Join Date: Mar 2006
Exp:
Default

A heads up. There is a cure for this now:

https://www.decryptcryptolocker.com/

Managed to get all of my files back! About a year later..but woohoo!
blankall is offline   Reply With Quote
The Following 5 Users Say Thank You to blankall For This Useful Post:
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 08:47 AM.

Calgary Flames
2024-25




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021 | See Our Privacy Policy