Welcome to the Cumulus Support forum.

Latest Cumulus MX V4 release 4.4.2 (build 4085) - 12 March 2025

Latest Cumulus MX V3 release 3.28.6 (build 3283) - 21 March 2024

Legacy Cumulus 1 release 1.9.4 (build 1099) - 28 November 2014
(a patch is available for 1.9.4 build 1099 that extends the date range of drop-down menus to 2030)

Download the Software (Cumulus MX / Cumulus 1 and other related items) from the Wiki

If you are posting a new Topic about an error or if you need help PLEASE read this first viewtopic.php?p=164080#p164080

Netbook hit by virus again!! What to do to to stops this,,,

Talk about anything that doesn't fit elsewhere - PLEASE don't put Cumulus queries in here!
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Netbook hit by virus again!! What to do to to stops this,,,

Post by ace2 »

This is the second time this has happened. It's the virus that hold you to ransom until you pay a fee to unlock your files/pc.
Have to do a restore to solve this.
I have virus protection(windows defender) and malware premium and it still hits!!!
What else can i do, firewall is on, noted malware was disabled.
The little bugga changed some jpg, mp3 to exe as well as all my backups..
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by ace2 »

Plus lost 25Gb :o of jpeg backups as well, it infected my NAS drive :evil: , but only in the archive section where i store all my pictures....
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
User avatar
Super-T
Posts: 906
Joined: Tue 09 Sep 2008 3:37 am
Weather Station: wh-1081
Operating System: Weather Laptop - Windows 10 Pro
Location: Auckland, New Zealand
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by Super-T »

I had this with a customer once and it also got into his backup drive plugged into USB.
Can't say where the customer got his problem from but I did remove it for him. He lost heaps of old pictures.
It all comes down to how you backup. Daily I back up to local hard drive and monthly or more often I back up to the laptop that runs Cumulus and also to a spare hard drive I keep in the car.
So far that has worked for me.
You can tell customers how to do their backups but that doesn't mean they will.
uncle_bob
Posts: 505
Joined: Wed 17 Aug 2011 2:58 pm
Weather Station: WeatherDuino Pro2
Operating System: 2008
Location: Canberra

Re: Netbook hit by virus again!! What to do to to stops this

Post by uncle_bob »

ace2 wrote: What else can i do, firewall is on, noted malware was disabled.
Sound like you've got most things covered, but a couple of suggestions;
Make sure you have the UAC set to the highest level.
Don't use an account with admin privileges for day to day use. Only use an elevated user when necessary.
Interested in building your own Weather Station? Maybe check out the WeatherDuino Pro Project Here
Conder, Canberra Weather
Image
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by ace2 »

The data that was lost wasn't important, as it was just image backup for my cam, my main personal images are replicated on more that one device and cloud backed up as well.
Moved UAC to highest but concerned if I move to a standard login, I might not be able to run some scripts, especially the powershell ones.

Chris
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
uncle_bob
Posts: 505
Joined: Wed 17 Aug 2011 2:58 pm
Weather Station: WeatherDuino Pro2
Operating System: 2008
Location: Canberra

Re: Netbook hit by virus again!! What to do to to stops this

Post by uncle_bob »

It's always a trade off of security vs userability :)
You'd be able to run scripts as another user though.
Interested in building your own Weather Station? Maybe check out the WeatherDuino Pro Project Here
Conder, Canberra Weather
Image
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by ace2 »

uncle_bob wrote:It's always a trade off of security vs userability :)
You'd be able to run scripts as another user though.
Lucky enough I have in place a full backup of cumulus and scripts to a removable drive and then that gets backed up onto a network drive.
So if a full reimage is needed, its a small task. just annoying.
Small price to pay for userability......
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
User avatar
N0BGS
Posts: 205
Joined: Sat 10 Nov 2012 2:26 am
Weather Station: Davis Vantage Pro 2
Operating System: Win10vm,VMWare ESXi 7.0
Location: Hermon, Maine USA
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by N0BGS »

Chris:

Windows Defender in my experience defends against almost nothing. I use and recommend Sophos AV. I have it on over 700 machines where I work and we have very few problems with viruses or malware. I have used McAfee, Symantec, AVG, etc, in large network environments. Sophos is better.

If you want something free from Microsoft go with Security Essentials. http://windows.microsoft.com/en-us/wind ... s-download

Not great, but much better than Defender

By "Malware premium" do you mean Malwarebytes, or something else?

--Kurt
System administrator/Network Tech, blah, blah ,blah ;)
Blitzortung Station 1809
TNETWeather

Re: Netbook hit by virus again!! What to do to to stops this

Post by TNETWeather »

ace2 wrote:This is the second time this has happened. It's the virus that hold you to ransom until you pay a fee to unlock your files/pc.
Have to do a restore to solve this.
I have virus protection(windows defender) and malware premium and it still hits!!!
What else can i do, firewall is on, noted malware was disabled.
The little bugga changed some jpg, mp3 to exe as well as all my backups..
Your signature indicates you are using WordPress. Sure it is up to date along with all the plugins? BTW hiding your WP version doesn't protect you from attacks. You hopefully are not using admin as the administrator login and have taken other security steps.

You need to look hard at what other websites you use on a regular basis as well and make sure your email habits are good.

Also when you say you are restoring... I would start from scratch. Ransomware hides very well. There is no point in attempting to "clean" a machine with it except wiping it and starting from scratch.

Not sure what malware premium is. Malwarebytes Subscribed??
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by ace2 »

Its malewarebytes premium and sorry, it is windows security essentials, not defender, wouldn't touch sophos after it took down Flinders uni where I was working last year.
I would normally use forefront, but just chucked essentials on instead.
I use wordpress, but has nothing to do with this setup or my site in general.
The netbook doesn't get used for anything else like surfing or anything, its behind my bar and is only accessible via RD.

System restore from recovery mode, payload of the ransomware virus was minimal with only system shells overwritten and infection of some jpegs, it was actually a crap version, the executable was seen in plain view running.
Once restored, I ran a full threat scan with essentials, malwarebytes and spybot with zero detections.
So the system looks to be clean with nothing left behind.
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
User avatar
N0BGS
Posts: 205
Joined: Sat 10 Nov 2012 2:26 am
Weather Station: Davis Vantage Pro 2
Operating System: Win10vm,VMWare ESXi 7.0
Location: Hermon, Maine USA
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by N0BGS »

Sophos took down Flinders University? That's a story I'd like to hear more about.

--K
Blitzortung Station 1809
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by ace2 »

Yep, I worked on the IT helpdesk, sophos release a update that caused sophos to suspect its own definition and updating mechanism as a virus and quarantine it.
It didn't bring down the 3500 machines we supported, but cause some hassles.
So they ditched it in favour of forefront last year...
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
User avatar
ace2
Posts: 679
Joined: Tue 14 Jan 2014 12:38 pm
Weather Station: maxkon ws-1081pc
Operating System: windows 7 & 8
Location: Adelaide, south Australia, Australia
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by ace2 »

TNETWeather wrote:This was released 10 days ago...

http://www.fbi.gov/news/stories/2015/ja ... n-the-rise
Nasty little buggers!!
What I find strange is with my netbook, it's not used for web surfing or emails and is only accessible via Remote desktop. Yet has been hit twice by this type of malware.
**formatted last time**
Suggests its been targeted......
CHRIS
Image
web site
http://www.ace2weather.com
Follow me on Twitter
http://tinyurl.com/kwlr9re
YouTube channel
http://tinyurl.com/lehwpgp
Facebook page
http://tinyurl.com/k3sap4s
Tiny URL links used
User avatar
N0BGS
Posts: 205
Joined: Sat 10 Nov 2012 2:26 am
Weather Station: Davis Vantage Pro 2
Operating System: Win10vm,VMWare ESXi 7.0
Location: Hermon, Maine USA
Contact:

Re: Netbook hit by virus again!! What to do to to stops this

Post by N0BGS »

ace2 wrote:Yep, I worked on the IT helpdesk, sophos release a update that caused sophos to suspect its own definition and updating mechanism as a virus and quarantine it.
It didn't bring down the 3500 machines we supported, but cause some hassles.
So they ditched it in favour of forefront last year...
Oh right. I remember that also because it happened at my organization, too. Caused quite a sensation for a few hours as I recall.
To their credit, Sophos had a fix out within hours and were very forthright about the error. I'd like to think that was a one-off.
So, yeah, that was a pain. Still like the product, though.

Thanks,

--Kurt
Blitzortung Station 1809
Post Reply