'the computer ...
 

MegaSack DRAW - 6pm Christmas Eve - LIVE on our YouTube Channel

[Closed] 'the computer "actually started to shake"'

26 Posts
19 Users
0 Reactions
86 Views
Posts: 251
Full Member
Topic starter
 

Hell of a virus...

[url= http://www.bbc.co.uk/news/uk-england-devon-38857488 ]http://www.bbc.co.uk/news/uk-england-devon-38857488[/url]

Let's hope they get some advice on off site backups as well as anti-virus.

They'll finish scanning it all and the town hall will burn down...


 
Posted : 03/02/2017 4:39 pm
Posts: 77691
Free Member
 

There's so much wrong there it's hard to know where to begin.


 
Posted : 03/02/2017 4:44 pm
Posts: 251
Full Member
Topic starter
 

I thought you'd like it 🙂


 
Posted : 03/02/2017 4:45 pm
Posts: 6208
Full Member
 

I'd begin by needing a licence to operate a computer


 
Posted : 03/02/2017 4:45 pm
Posts: 23296
Free Member
 


There's so much wrong there it's hard to know where to begin.

Tiverton in general or just this story?


 
Posted : 03/02/2017 4:45 pm
Posts: 0
Free Member
 

"The council is [i]now [/i]looking into computer security measures."
erm...


 
Posted : 03/02/2017 5:00 pm
Posts: 77691
Free Member
 

Quite.

Backups.
User education.
Backups.
Spam filtering.
Backups.
Anti-virus.
Backups.
If the computer "actually started to shake" I'm a 4' paraplegic Latvian postman.
Have I mentioned backups yet?


 
Posted : 03/02/2017 5:07 pm
Posts: 28550
Free Member
 

Tiverton IT support department have now found their recovery disk.

[img] [/img]


 
Posted : 03/02/2017 5:09 pm
Posts: 0
Free Member
 

[quote=Cougar ]There's so much wrong there it's hard to know where to begin.

Yeah, I was about to start, but then realised what they're doing right would be a shorter list. Here it is:


 
Posted : 03/02/2017 5:09 pm
 poly
Posts: 8748
Free Member
 

So do we think its total incompetence, or has someone got some [s]clinton[/s] emails to get rid of?


 
Posted : 03/02/2017 5:13 pm
Posts: 77691
Free Member
 

Oh, and,

You can block this sort of attack fairly trivially by removing execute rights from temporary directories.


 
Posted : 03/02/2017 5:14 pm
Posts: 0
Free Member
 

Aye, I'd be thinking some one's trying to hide something there.


 
Posted : 03/02/2017 5:16 pm
Posts: 621
Free Member
 

If the computer "actually started to shake" I'm a 4' paraplegic Latvian postman.

Quite. Only thing I can think is that the the encryption process caused the CPU fans or DVD drive to spin up causing a fairly loud noise. ❓ Bit of a leap to it shaking though 😆


 
Posted : 03/02/2017 5:17 pm
Posts: 45692
Free Member
 

I bet they still have an IT chap who gets paid a nice fat salary...


 
Posted : 03/02/2017 7:14 pm
Posts: 17852
Full Member
 

Sounds like demonic possession rather than a virus.


 
Posted : 03/02/2017 7:16 pm
Posts: 6722
Full Member
 

5.25" floppy discs, green screens, dot matrix printers... whats not to like?
Govt IT at the cutting edge of a blunt thing.


 
Posted : 03/02/2017 7:32 pm
Posts: 0
Free Member
 

The computer started shaking ? Well at keast that confirms the staff quality.

Also he said deleting all the data files was the worst thing he'd seen in 15 years at the council. Personally I doubt it.


 
Posted : 03/02/2017 9:00 pm
Posts: 33530
Full Member
 

Just stupidity here, it is in Devon, after all...
Actually, that's a wee bit harsh, I love Devon, but even hospitals have been hit by these ransomware viruses, it's basically total lack of awareness about not opening anything that smells fishy, and having up-to-date security, something a bit more sophisticated than Norton...

5.25" floppy discs

You may laugh, but I worked for a while in an on-site studio at a major cardboard packaging manufacturers, and they moved files around on floppies!
This was around twelve years ago.


 
Posted : 03/02/2017 9:02 pm
Posts: 45692
Free Member
 

it's basically total lack of awareness about not opening anything that smells fishy

Or stupidity.
I had weekly issues with our old (72 yr old...) secretary who could not understand that all the emails in our info@ email address were not always from nice people who were trying to help. We did have up to date, cloud-hosted systems that were really robust, but her ability to *always* click on *all* attachments on *all* emails (multiple times, just in case) tested the security to it's limits... I would weekly sit with her and go through the emails - pointing out iffy spelling, dodgy graphics, odd email addresses, spoof URLs etc, and showed how to right click and 'scan for virus' etc - still she blithely multi-clicked away or even tried to save to desktop if it wouldn't open...

🙄


 
Posted : 03/02/2017 9:48 pm
 DezB
Posts: 54367
Free Member
 

Sounds like an episode of Mr Robot


 
Posted : 03/02/2017 9:57 pm
Posts: 23296
Free Member
 

[quote=matt_outandabout ]
I had weekly issues with our old (72 yr old...) secretary who could not understand that all the emails in our info@ email address were not always from nice people who were trying to help. We did have up to date, cloud-hosted systems that were really robust, but her ability to *always* click on *all* attachments on *all* emails (multiple times, just in case) tested the security to it's limits... I would weekly sit with her and go through the emails - pointing out iffy spelling, dodgy graphics, odd email addresses, spoof URLs etc, and showed how to right click and 'scan for virus' etc - still she blithely multi-clicked away or even tried to save to desktop if it wouldn't open...

for similar reasons, particular email recipients at our place have all attachments stripped off their emails automatically. its just easier that way...


 
Posted : 03/02/2017 10:00 pm
Posts: 17
Free Member
 

Let's face it here nobody is actually shocked are they!

My recent it help included sorting out some bodies wireless mouse (mostly opening the hatch on the back to pull the receiver out) amazingly just taking it out the box and putting it next to the laptop didn't connect it.

On the flip side a mate did a coding weekend comp thing, every team had a hosted server to use, the sponsor who was doing the hosting specialised on online hosting just cloned the boxes giving all the teams the same security details so anyone could get in to all the servers.


 
Posted : 04/02/2017 2:16 am
Posts: 23296
Free Member
 

Well if you don't change the default password...


 
Posted : 04/02/2017 7:44 am
Posts: 6722
Full Member
 

[quoteWell if you don't change the default password

Thats it,
Devon County Council secure log in details

Admin
Password


 
Posted : 04/02/2017 8:59 am
Posts: 3073
Full Member
 

Tiverton council urgently requires a windows ME recovery disk.


 
Posted : 04/02/2017 9:13 am
Posts: 5747
Full Member
 

[quote=Cougar ]Oh, and,
You can block this sort of attack fairly trivially by removing execute rights from temporary directories.

This sounds like a very sensible thing to implement. Does it work on a windows PC and if so is it reasonably easy to set up? Have tried a quick Google but nothing obvious came up (plenty of info on how to reinstate them but not how to remove them 🙂 )


 
Posted : 04/02/2017 9:24 am
Posts: 77691
Free Member
 

https://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information#manual

or

https://www.foolishit.com/cryptoprevent-malware-prevention/

In a corporate environment you can do much the same as the first link via Group Policy.


 
Posted : 04/02/2017 9:36 am