Plumbing Company Becomes Encryptionware Victim

Posted on
Bulldogtech onguard remote backup

We received a call this week from a long time customer, a plumbing company that relies on SAP software to conduct their business; stating they could not access their server drive. Theyre business was stopped in it’s tracks.

Encryptionware garbled (encrypted) all the data including their SQL databases. We instructed them to immediately power down the system while we logged in to each workstation and ran a full virus scan. We found one of the receptionists initially was infected via an email attachment (via AOL), which executed code that scanned for accessible drives and encrypted any data found.

This customers business was stopped! Their service techs did not have access to their stops, accounting data was lost and the local attached backup drive was found to also be encrypted.

What could have been a major disaster, was mitigated by Bulldogs OnGuard Remote Backup. After our technicians reloaded the main server, ONGuard was able to recover all data files & SQL databases within 20 hours from the previous nights backup.

After less than a day, our customer was back in business thanks to OnGuard backup.

As a result, we discussed with the customer to migrate away from AOL email and move to our secure exchange servers as well as use our OnGuard Defender package to help mitigate future attacks.

This was a Win-Win for all!

If your data secure? Learn more about our OnGuard Remote Backup and protect your company today!

Call Us: 718-921-6159

sales@bulldogtechinc.com

Several Medical Offices Affected By AllScripts Hack

Posted on
Bulldogtech onguard remote backup
Malware strikes again! We recieved numerous calls this week from several healthcare providers who use allscripts. We sent our technicians out to do a site inspection and found every single machine infected with encryptionware. Luckily for the Doctor, the operating system was not heavily damaged, and we were able to successfully clean the boot volume of any infections. Their data unfortunately was encrypted requiring a full data restoration of their patient data, office documents, and EMR databases via Onguard Remote Backup. We initiated the restore process and within 12hrs all data was present, and all applications functional. Another OnGuard Success Store Is your data protected? Call us: 718-921-6159 sales@bulldogtechinc.com

Bulldog Tech Restores Encrypted Server

Posted on
Bulldogtech onguard remote backup

OnGuard Remote Backup saves another long time customer! One morning we received a call from a fabrication company, unable to access their billing system, driven by SAP software. We found they were hit with the Ransom.CryptXXX (WannaCry) attack, causing complete encryption of all data, and critical operating system files.

We acted quickly to get them running again. First we picked up the server, reloaded the operating system and began a full system restore using OnGuard Remote Backup. We reviewed there security policy, and disabled remote access using insecure remote desktop. 

OnGuard emote Backup saved their data and put them back in business as if nothing happened!

OnGuard Remote Backup is typically installed to the main server, set to back up the network shared volume, or volumes, which typically contain any business related documents, scans, databases, etc. OnGuard runs on a nightly schedule, first scanning for any changed files, then sending the date to our secure remote storage vault.

OnGuard has been wildly successful in instances where all volumes are destroyed from an Encryptionware type exploit. With no indication these types of threats will subside, having and testing a backup solution regularly is the only way to avert disaster.

Are you protected?

Call Us: 718-921-6159

Sales@Bulldogtechinc.com

If your Windows De-Activated, Bring it in

Posted on

Friendly Reminder, The Real Microsoft Will Never Call You

Posted on

Microsoft cracks down on tech support scams, 16 call centers raided
Read Article at Sophos

More than 100 Indian police swarmed 16 tech support scam call centers in Gurgaon and Noida last week, arresting 39 people for allegedly impersonating legitimate support reps for companies including Microsoft, Apple, Google, Dell and HP.

The day after the raids, which were carried out on Tuesday and Wednesday, Microsoft said that it has received over 7,000 victim reports from customers in more than 15 countries who’ve been ripped off by the call centers.

This is the second of two recent, big raids on Indian tech support scammers. In October, after Microsoft filed complaints about customers falling for pop-up messages that lied about their systems being infected with malware, Indian police raided 10 illegal call centers and arrested 24 alleged scammers.

In that second raid, law enforcement seized a wealth of evidence, including the call scripts, live chats, voice call recordings and customer records used to run the scams.

Read More