Danas me zove kolega sa posla i kaze da ne moze da se uloguje na laptop sa svojom sifrom.
U pitanju je laptop windows 7 i imao je login sifru i omogucen RDP ali na drugom portu.
U ruteru je taj port bio forwardovan na njegovu lokalnu ip adresu laptopa.
Resetovao sam sifru za login iz cmd i ulogovao se ali me je docekala fina poruka na dekstopu o ransomwaru.

Naravno svi fajlovi su kriptovani na obe particije.
Instalirao sam Mbam i rezultat skeniranja ne obecava,koliko ja vidim ovo je neka prilicno sveza verzija gamadi i tesko da se moze sta uraditi oko spasavanja fajlova ali eto bilo bi dobro da neko potvrdi strucniji od mene.
Pregledao sam mailove na serveru i nisam video nista cudno i mislim da je ovo pokupljeno sa nekog sajta,u logu se spominje firefox problematicna ekstenzija.
Nadam se da se ne siri preko mreze posto na poslu imamo jos nekoliko racunara na istoj mrezi.
Sta raditi dalje?
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 4/8/20
Scan Time: 1:47 PM
Log File: c95128aa-798e-11ea-b6ae-68b599f83d86.json
-Software Information-
Version: 4.1.0.56
Components Version: 1.0.867
Update Package Version: 1.0.21792
License: Free
-System Information-
OS: Windows 7
CPU: x64
File System: NTFS
User: ******-PC\Admin
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 269227
Threats Detected: 6
Threats Quarantined: 6
Time Elapsed: 2 min, 6 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 2
PUP.Optional.ForcedInstalledExtensionFF, C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C3QGLR0C.DEFAULT-1536308651104\BROWSER-EXTENSION-DATA\{56A1E8D2-3CED-4919-ACA5-DDD58E0F31EF}, Quarantined, 1799, 580170, 1.0.21792, , ame,
PUP.Optional.BrowserProtection, C:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\C3QGLR0C.DEFAULT-1536308651104\BROWSER-EXTENSION-DATA\{AA4ABAC2-1FFA-12AA-BBDD-9305CB2C1254}, Quarantined, 1824, 630897, 1.0.21792, , ame,
File: 4
Ransom.Crysis, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\INFO.HTA, Quarantined, 5641, 791609, 1.0.21792, , ame,
PUP.Optional.ForcedInstalledExtensionFF, C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\c3qglr0c.default-1536308651104\browser-extension-data\{56a1e8d2-3ced-4919-aca5-ddd58e0f31ef}\storage.js.id-6CA0D3F4.[[email protected]].ncov, Quarantined, 1799, 580170, , , ,
Ransom.Crysis, C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\INFO.HTA, Quarantined, 5641, 791609, 1.0.21792, , ame,
PUP.Optional.BrowserProtection, C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\c3qglr0c.default-1536308651104\browser-extension-data\{aa4abac2-1ffa-12aa-bbdd-9305cb2c1254}\storage.js.migrated.id-6CA0D3F4.[[email protected]].ncov, Quarantined, 1824, 630897, , , ,
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)