Ransomware - Wannacry/wcry and everything else ...
Ransomware in general is something none of us wish to deal with. The latest Wannacry problem is worse. This is not because of what it is but rather of the extent to which it has affected our users. There have been a plethora of great suggestions all over this site. I would add to those with the following suggestions:
• Completely check your system for viruses with a reputable virus checker
• Check any suspected files and or links at virustotal.com
• Make sure you have a tested versioning backup system
• Do a complete scan of your system
o Make sure all your programs and your operating system is up to date (even old Windows OS’s now
have updates, like windows XP – check the Microsoft website and do a windows update)
o If you are unable to do updates on your own machine due to company policy, make sure that your IT
department is doing the updates.
• Do not, click on an attachment in your email, even if it is from someone you know – call them up and check
that they sent it – they’ll understand.
Whenever I touch a system I do a “ransomware check” which involves the following:
• Create a blank text file called myapp.txt in the root drive (c:\) and rename it to myapp.exe
• Run FoolishIT’s Cryptoprevent
• Install an anti-ransomware tool such as BD Antiransomware, MBAM Antiransomware, Kaspersky
Antiransomware for business, etc.
• Run SpyBHORemover and SpyDLLRemover from securityxploded.com
• Run a full scan
• Disable Autorun and Autoplay
The rest of what I do involves anti virus procedures. It is important to do all of this at the very least to protect your systems. I highly recommend using tools/software such as Cylance, SentinelOne, MBAM, Kaspersky, etc.
This could affect YOU if you have ESXi installed on SD cards !!!!!
e.g. DELL EMC have just issued a statement stating the use of SD Mirrored cards (IDSM) is NOT recommended for ESXi 7.x and later, despite that they sold the technology !!! and some DELL EMC R740 shipped with OEM pre-installed ESXi 7.x. using IDSM - Mirrored SD cards!
and now they do not recommend it!
NOTE: If you had ordered VMware ESXi with your Dell EMC PowerEdge server, it is preinstalled on your server. The ESXi installer media is required for reinstallation. The Boot Optimized Storage Solution (BOSS) card is the preferred non-HDD or SSD device for VMware ESXi 7.0 installation. The Dell Internal Dual SD Module (IDSDM) install is no longer recommended due to write endurance issues with the SD flash media. For more information, see the Storage Requirements for ESXi 7.0 Installation or Upgrade section on the VMware ESXi Installation and Setup Guide or see VMware Knowledge Base article 2145210.