## Osiris Ransomware

The war between wetware and hardware.
### Osiris Ransomware

Got it

oh, fuck
### Re: Osiris Ransomware

Easy.

Reformat and restore from backups.

### Re: Osiris Ransomware

How did you get it?
### Re: Osiris Ransomware

Malware Bytes claims to be able to remove the malicious software, but will not decrypt your affected personal files.

https://malwaretips.com/blogs/remove-osiris-virus/

The only solution is preventative, I'm sorry to say--having a backup of the files it would try to get at.

### Re: Osiris Ransomware

What Doctor X said. Also disconnect your backup drive from your system after the backup is complete. I use an external 2TB drive which I only plug in when I want to run a backup.

Which I need to do tonight.

Anyway, you may be able to use the Kaspersky utility to decrypt your files after you've cleaned out the ransomware itself.

https://www.bugsfighter.com/remove-osir ... ris-files/

There are some other decryption utilities out there as well:

Kaspersky, TrendMicro, Avast, and others have free utilities and instructions.

On Winders, I have an Administrator account with all the awesome powers and a standard account without awesome powers. I can only install software if I log on to the Administrator account.

A lot of malware is installed via phony "updates". Caveat clcky.

My work laptop is configured such that if it is lost or stolen, IT can "brick" it remotely. Might be good for parts but that's about it.
### Re: Osiris Ransomware

Indeed, my Ex-HD are "offline" by nature--not connected to the computer.

Your first link promises some hope that gnome's does not --that Kaspersky has an option if you have a copy of a file "somewhere" that is not affected its programs can use to figure out the encryption.

--J.D.
### Re: Osiris Ransomware

Just curious. How does the malefactor get paid?

Bitcoin?
### Re: Osiris Ransomware

Anaxagoras wrote:How did you get it?
ed lives dangerously…

### Re: Osiris Ransomware

Abdul Alhazred wrote:Just curious. How does the malefactor get paid?

Bitcoin?
That's the usual demand.
### Re: Osiris Ransomware

<sigh>iles.

I got an email. From FedEx. We do a fair amount of business with FX so getting an email is no biggie. Subject was "undeliverable package" or words to that effect. New one on me but FX changes things every now and then, so no biggie. Seems that the return label was an attachment. Boy, I had problems figuring that one out, couldn't open it. My wife wanted to get a copy of the thing since she handles client service and returns and stuff like that. I nicely sent her a copy.

Shortly thereafter I noted that many many dropbox files were being updated. My my wife was busy. Yes indeed. Then I looked into my drop box. Holy shit. 7000 files with the Osiris extension. That and one HTML file per folder that told you how to log into some web address using the Tor browser. They made no bones about it, it was extortion pure and simple.

I energetically told my wife to pull the plug on her machine. Long story shot the fucking thing started with her local dropbox which then dutifully corrupted the cloud copies then dutifully updated the stuff on my machine. 100% of our business files.

<sigh> That was 1:30 EST. See, I figured that with dropbox I had backups. And they have copies of deleted files. NOT. For some reason the deleted files weren't there. However, my laptop, which has dropbox, died last night. Soooooooo all of the business stuff and my personal stuff is back... wife's machine is a mess though I think that it is mostly photos (!). Also Quickbooks appears to be corrupted. Probably other stuff.

I will read thru the good advice and undoubted mockery in the above posts later or tomorrow. Thanks for all the info.

I do think that I would shoot the perpetrator.
### Re: Osiris Ransomware

↑ We commiserate with you, ed, rest assured.

But as this is one of the rare places where you can laugh of everything…

### Re: Osiris Ransomware

It is sorta funny.

I see Doc X standing above the fray explaining how you should have backups of everything.

Jesus, with dropbox I didn't think that I needed backups.
### Re: Osiris Ransomware

If your wife was in the kitchen making you a sandwich none of this would happen

### Re: Osiris Ransomware

Pyrrho wrote:Anyway, you may be able to use the Kaspersky utility to decrypt your files after you've cleaned out the ransomware itself.

https://www.bugsfighter.com/remove-osir ... ris-files/
Seems like a place to start and start NOW.

--J.D.
### Re: Osiris Ransomware

Kaspersky has some other utilities

https://noransom.kaspersky.com/

Someone has a list of several others but I can't find it now. You might find expert advice on one of the antivirus companies forums.

The FedEx email attack is very common. The criminals make these things look very legitimate.

You are the victim of a crime.
### Re: Osiris Ransomware

Though I will say this since one of my "catcher" accounts gets these.

The header tells a story, even if forged. You cannot forge it all.

Why is FedEx trying to contact you from outside of the US or from a server that has nothing to do with FedEx or from an address that is not fucking FedEx?!!

Businesses also do not send compressed files.

I know, I know, it is pissing on a grave, but graves exist to remind us all that we are not special.

--J.D.
### Re: Osiris Ransomware

That really sucks Ed.

Maybe this situation calls for hiring a professional?
### Re: Osiris Ransomware

Was the attachment an executable? I'm trying to find out from your experience what the actual trigger event was. Help me look out for that sort of thing myself.
