BLKPURE Virus? Malware? Help

ShoTTaS

{ BANANA }
Pro User
VIP
Local time
8:29 PM
Messages
362
Location
Philippines
Hi

A user in my company had opened an attachment from an unknown sender. it was on a .zip file.
after he opened the file. almost all his files was replace a .blkpure extension,,, is this somewhat kind of virus?

kindly advice please.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
I am sure you have run a Scan with your Antivirus Software and checked with Malwarebytes ? ...

The next Step would be to upload the File in question to Virus Total ....
 

My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
Yeah, i already have done scanning it with Trend Micro Officescan and Malwarebytes.
i will upload a file that was affected by this virus/malware or what is it called.

question: am i going to upload it here? is it okay?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
Follow-up question, how am i going to retrieve the files that was affected? i already have done system restore but no luck. by the way the OS of the computer is Windows XP sp3.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
update: i have found out that this attack is from a ransomware,

does anyone knows how to stop this? another computer was infected today, still from an email attachment
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
Where are the Requested Files ? ....
 

My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
Follow-up question, how am i going to retrieve the files that was affected? i already have done system restore but no luck. by the way the OS of the computer is Windows XP sp3.

Windows XP should not be used on the internet.

update: i have found out that this attack is from a ransomware,

does anyone knows how to stop this? another computer was infected today, still from an email attachment

Tell users to stop opening email attachments.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
Hello HAVOC,

why does XP not be used on the internet? we have a bunch of computers still running in windows xP here.

Maxie,

i will upload the logs today, i was busy troubleshooting yesterday.

thanks
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
ShoTTaS,

The file extension .blkpure you presented is rather unique. Have done some searching, but, no luck so far.

If VirusTotal does not provide info on it...
https://www.virustotal.com/

There are other scanners you can use to see if any of them provide information, such as:

Jotti's malware scan

ThreatExpert - Online File Scanner

VirSCAN.org - Free Multi-Engine Online Virus Scanner v1.02, Supports 39 AntiVirus Engines!

Comodo Instant Malware Analysis


Also, what leads you to believe it is ransomware?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
cottonball,, that was just the extension they use for the encryption of the files. we have found out that we are facing a cryptowall .. we dont have any more option, rather than reformat the computer, and put windows 7 on it since shadowcopy is not supported on Win XP's.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
i believe it is a ransomware because on other blogsites and forums, i see those Cryptowall applications screenshot, same as what i see on our computers here.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
The reason XP is not recommend for internet use you have found out.

XP does not meet todays needed security requirements.

Cottonball is very good at beating up on infections so I will get out of the way.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Will you be able to provide the Malwarebytes report requested earlier?

I wasn't able to get the logs of malwarebytes.
I Cant get my hands on the infected computers anymore, it was being quarantined out of sight. Infected users where given new computers for their daily reports.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
I will get back on you, if i will be allowed to touch those computers again.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 32bit
CPU
Dual Core
Antivirus
Trend Micro
If you can, you may want to suggest the use of CryptoPrevent to whoever is fixing the machines: https://www.foolishit.com/vb6-projects/cryptoprevent/

If the company you work for has taken charge of whatever actions are necessary to clean the affected machines, that is good.

Assistance at this type of forum is really not intended for a computer used in a business. Many of us are amateurs, have different knowledge levels, and it is not possible to anticipate any alterations or configurations made to business machines, or how they will interact with the tools we commonly used in the removal of malware.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Back
Top