Fazza Posted July 5, 2017 Posted July 5, 2017 During a routine laptop repair I found a .png file in the c:\users folder depicting a Ransom Note. Here's a screenshot of the file: The date of creation is March 2016 - I thought these only got put on the computer at the end of encryption? There are no signs of anything being encrypted so maybe Microsoft Endpoint Protection on this Windows 7 laptop caught it in time? Either way the HDD has been whipped out and replaced with a new and it will be formatted/wiped before using it again.
RJohnson91 Posted July 5, 2017 Posted July 5, 2017 Could it have been that they have saved the picture from the internet, for example, if I saved your attachment for later use? Alternatively, it could be your local anti-virus caught it after it had injected it's files but not encrypted anything, very much how Sophos InterceptX works with wannacry. If you're wiping the HDD anyway, I wouldn't worry. Ryan
bald_pig Posted July 5, 2017 Posted July 5, 2017 I'd speak to the owner of the laptop before doing anything.
tmoon-mint Posted July 5, 2017 Posted July 5, 2017 You could run the image through a reverse image search and see what results come up?
Fazza Posted July 5, 2017 Author Posted July 5, 2017 Could it have been that they have saved the picture from the internet, for example, if I saved your attachment for later use? Alternatively, it could be your local anti-virus caught it after it had injected it's files but not encrypted anything, very much how Sophos InterceptX works with wannacry. Unlikely I would think that they would have saved a ransomware image in the C:\Users folder. Hopefully Microsoft FEP caught it as Ive done a full scan of the HDD on USB and it found nothing. I'd speak to the owner of the laptop before doing anything. I'm not going to do that as most people cant remember what they did on their computer and what web sites or emails they opened 1 day ago let alone 1yr ago! You could run the image through a reverse image search and see what results come up? Good idea! Just done it and it comes up as TeslaCrypt.
Tesla Posted July 5, 2017 Posted July 5, 2017 Good idea! Just done it and it comes up as TeslaCrypt. I ain't dun' nuffin' 3
JJonas Posted July 5, 2017 Posted July 5, 2017 https://www.bleepingcomputer.com/news/security/teslacrypt-shuts-down-and-releases-master-decryption-key/
simonw Posted July 5, 2017 Posted July 5, 2017 I ain't dun' nuffin' Oooh!, double negative! Means you have. Naughty Tesla, bad Tesla! 3
Fazza Posted July 5, 2017 Author Posted July 5, 2017 https://www.bleepingcomputer.com/news/security/teslacrypt-shuts-down-and-releases-master-decryption-key/ I'f I'm reading that right we've had a narrow escape! Sounds like the laptop was infected but because they had in effect turned their servers off it didn't get an encryption key to enable to encrypt the laptop.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now