Showing posts with label Crypto Locker. Show all posts
Showing posts with label Crypto Locker. Show all posts

Monday, April 4, 2016

Cryptowall / Cryptolocker virus update.

We want to alert you to a very urgent threat to the data on your network called Cryptowall / Cryptolocker.

You should immediately advise your staff to
not open ANY files that are sent to you through e-mail. This new virus/trojan arrives as an e-mail that contains a zip, doc, xls, or pdf file that pretends to be an invoice, purchase order, bill, complaint, UPS or USPS shipment or other business communication. If you receive such a message, you should verify with the sender that they did in fact send this message prior to opening the attachment.

This threat is specifically designed to defeat firewalls, anti-virus and anti-malware software. There is presently no known way to block these threats. If you open such an attachment, you won't even know you have been infected until you attempt to access data on your network. Once infected, your critical data is inaccessible and current recovery steps are time consuming and expensive. We cannot stress the severity of this threat enough.

We are actively monitoring this situation and working with our security partners to implement updates as soon as they are available. In the meantime, we recommend that you and your team adopt a very conservative posture toward this threat by not opening any e-mail attachments you have not personally verified. We expect this threat to remain active for the foreseeable future.

If you have any questions or concerns related to this, please do not hesitate to contact our office. 

IES, Inc.
781-816-9437
www.iesAdvisors.com

Wednesday, June 11, 2014

Critical alert regarding a new variation of the Crypto-Locker Trojan.

There is a new variation of the Crypto-Locker Trojan currently attacking computer networks in the US. This is rampant right now so your extra vigilance and care is extremely important.

Do NOT click on any email attachments, faxes, PDF files or any other attachments unless you are 100% positive that it’s from someone you know well AND you are expecting the attachment. Many local companies have already been affected and their networks taken down by this Trojan. These emails are made to look like they are coming from banks, shipping companies and many other vendors we all use on a daily basis.

There is currently no antivirus or anti-malware that can protect you from this nor can it remove and fix the problem afterwards. The only resolution is to format and re-install the affected systems and servers and in many cases, unless you have an offsite backup solution, your critical data is encrypted and unable to be restored. We have found that even paying the ransom will not get your data back as the criminals do not respond even after you’ve send the money.

This is a network Trojan as well so if your local system gets infected it will attack and encrypt any and all files on shared drives – essentially putting your local data beyond your reach and un-useable.

If you make a mistake and click on the attachments which take you to a link outside your office you will be informed that your data has been encrypted and to send a payment to ….. If you see this popup, please immediately turn off your computer, unplug it from the wall and remove the network cable that connects you to your network, the server and the internet. This might help with protecting some of the data on your network shares.

We will keep you informed and updated as this Trojan continues to make it way throughout the US.

In the meantime, if you have any questions or concerns related to this, please do not hesitate to contact our office at contactus@iesadvisors.com or 781-816-9437.

Sunday, October 13, 2013

IMPORTANT NOTICE TO ALL COMPUTER USERS: New Crypto Locker Ransomware infecting computers & locking down files.


We are seeing a new version of Crypto Locker Ransomware infecting computers and encrypting files so that you cannot access them. A message comes up as shown in the above link demanding $300 to be paid in order to get the files back.

If you encounter this virus on a work or home machine, turn it off immediately. Do not click on anything to close it. These criminals attempt to panic you into clicking on the "close" buttons which are really an "Ok, infect my computer" button. It is extremely important that you simply turn off the power to the computer immediately and contact your IT support person.

We recommend enabling strict filters on any and all firewalls in both your home and office, which may block some valid HTTPS sites such as banking sites but it's safer than letting this new trojan/virus into your computer systems. The infection is also "network aware" which means that if an infected user has access to a shared folder on a server or another workstation, that user will cause all shared files to become encrypted and unrecoverable as well.

The trojan infection is coming from infected web sites. The links may come in via email or on social media sites. So be very cautious about ANY web links. As we always recommend the sender should clearly identify themselves, you should know the sender and the purpose of the link(s) sent. In any case - it's still best to ignore them and DO NOT click on any links you receive without first calling and verifying that the sender and the link is legitimate.

Please be safe in your email and Internet browsing. If you need assistance securing your computers or find your computers to be infected, feel free to contact us to discuss your options.

IES, Inc.
781-816-9437
iesAdvisors.com