Hi, Thanks. I haven't got a look like I said, can you give me an idea of how you cleaned it, and any idea what this thing does? Also, any idea how they got it? Thanks. Dave. On 11/9/12, Darragh OHeiligh <Darragh.OHeiligh@oireachtas.ie> wrote:
these infections seem to be specific to the region. In the US, their FBI, in England, their the police, over here in Ireland their the gards.
I saw a computer infected with this varient on Monday. It kept getting to the BSOD and crapping out. This happened in Safe mode as well.
Took me ages to clean it up. Even then, it's only working for a while until the person decides if it's worth paying me to rebuild it.
Seems like it's nasty enough.
Regards
Darragh Ó Héiligh Fujitsu
Offices of the Houses of the Oireachtas, Fredrick Building, South Fredrick Street, Dublin2 Telephone: +353 (1) 618 3559 Email: darragh.oheiligh@oireachtas.ie Internet: http://www.oireachtas.ie
From: David Mehler <dave.mehler@gmail.com> To: blind-sysadmins <blind-sysadmins@lists.hodgsonfamily.org>, Date: 09/11/2012 12:35 Subject: [Blind-sysadmins] FBI ransomware? Sent by: "Blind-sysadmins" <blind-sysadmins-bounces@lists.hodgsonfamily.org>
Hello,
Has anyone had unfortunate cause to deal with a system infected by the FBI ransomware? If so, how did you eraticate that outbreak? I've just started preliminary reading on this and I've not seen the machine so I don't know how this infection hit it.
Any suggestions appreciated.
Thanks. Dave.
_______________________________________________ Blind-sysadmins mailing list Blind-sysadmins@lists.hodgsonfamily.org http://lists.hodgsonfamily.org/listinfo/blind-sysadmins
Oireachtas email policy and disclaimer. http://www.oireachtas.ie/parliament/about/oireachtasemailpolicyanddisclaimer... Beartas ríomhphoist an Oireachtais agus séanadh. http://www.oireachtas.ie/parliament/ga/eolas/beartasriomhphoistanoireachtais...
_______________________________________________ Blind-sysadmins mailing list Blind-sysadmins@lists.hodgsonfamily.org http://lists.hodgsonfamily.org/listinfo/blind-sysadmins