Stung by Spora Ransomware - Bastard!

If you care about it, back it up. if its important back it up twice.
on the cloud, on a external HDD or other pc or even print it out.
Print it out :rolleyes: That sounds more like doomsday scenario.
 
That's a bummer, happened with my friend and he had to reinstall everything. I felt sorry for him because I couldn't fix the problem. I hope you don't lose much of your data and kept a backup of it. From now on remember not to download and run anything which you don't trust fully. :)
 
Print it out :rolleyes: That sounds more like doomsday scenario.
sounds like it, but print doesnt degrade over time like like digitally stored media does.
if its for long term, get a hard copy of it.
 
Serious question:
If you pay them the fee, do they actually allow access to your files again?
Most of the time not. I read an article when these ransomwares were fairly new and i think a percentage was mentioned too i can't seem to recall now, but most of the time you won't get your files back even if you pay.

Cyber-insurance is blooming: https://nakedsecurity.sophos.com/2017/01/09/fear-factor-pushing-up-cyber-insurance-premiums/

The best course of action to prevent situations like this is not with AVs and with making your system bulletproof (which won't hurt for sure), but with making regular backups of your files, what you keep offline and/or in the cloud somewhere. When you're getting hit with shit like this, at worst you need to reinstall the OS, but you won't lose any important data. It's advisable to do regular backups anyway, hdds can go poof and data can get corrupted beyond saving.

I started to do weekly backups a few months ago.
 
I read that the Spora ransomware had a "try before you buy" feature. As in it lets you upload 1 or 2 files and decrypts them for you. This shows they have the keys and are able to decrypt your files IF you pay. Crafty as fuck that is!

A good tip for anyone wanting to limit exposure to ransomware is to change your windows file associations

spora and most of the others are generally coming in a zip containing a .js file. If you run the js file it fetches the exe that starts encrypting. Quick fix for this is make sure they open in something safe like notepad.

set all .JS files to open with notepad.exe as default
set all .VBS files to open with notepad as well
Capture.JPG

There are others but these seem to be used most. I have also seen stuff using powershell to hook stuff but theres no easy way to disable powershell fully in windows which is just plain stupid.
 
System restore doesn't remove the viruses. I mean, it's not like system restore would create a complete backup of your whole files, and then replace those with the current ones(like a reinstallation). In fact, I consider it pointless.

Can you make a screenshot of your task manager's processes? Maybe I'll be able to find something sketchy.

Right click on your taskbar -> start task manager -> processes -> Show processes from all users.
 
booted into safe mode and removed all traces of it manually from start up etc, and with a little help from malwarebytes.

My pdf, word files are still encrypted though. I'll just have to wait until trend micro or whoever update their decryption software for this new ransomeware, if they ever do.

That's messed up.

How did you wind up fixing it?
 
the data is etched in by the laser creating tiny marks and that is not rewritable, but its also too small and complicated for use too read so computers do it for us and that's why they call it 'digital' storage media.
in principal its no different than me marking a stone slab with a chisel.

and to be clear i was thinking of more traditional digital media such as SSDs and HDDs which store data magnetically or using semiconductors.

pretty cool stuff that though, and if it were to become a standardized way to archive info for long term, i'd like to use it.
 
@Hawkster By encrypted, are the pdfs modified in their source code? For e.g if you try on another pc, are they still encrypted or it's just on that machine?
 
I actually havent tried that yet because i was worried it would pass on the virus somehow to the other pc

@Hawkster By encrypted, are the pdfs modified in their source code? For e.g if you try on another pc, are they still encrypted, it's just on that machine?
 
Hi op sorry to hear that.Its best to run seo tools on a virtual machine because some of those websites that scrapebox scrapes are hacked websites.Check the windows files for any unusual files most windows system files are digitally signed by microsoft.Also check the autostart registry keys the malware uses to run when windows starts.Also unusual services and drivers
 
@Hawkster It says it's corrupted. But no infection occurred.

If you want, I can make a test with a smaller file maybe? 10-15mb max?

Nonetheless, this thing with ransomware looks great, and it seems that there are people willing to spend money.

How I believe it actually acts: it modifies the PATH for the .pdf/.doc format. So, instead of using adobe reader/microsoft office to open, it will actually open the virus. Simple, yet effective.

However, it may go deeper and inject some code in the .pdf/docx files, not sure yet.

I'd really give it a try if I wouldn't be so petrified by "ethics", but tell me what exactly is pure white hat?
 
Last edited:
Back
Top