Please help -CryptoLocker ransomware virus on my computer

One more reason to stick to linux...

Edit : Wonder if the API will work if the drive is already encrypted probably not ?
 
Never had this ............. but be absolutely sure, I am not planning on getting it. :eek:

/ updates Avira, and sorts out backups
 
saw how the CBT locker gets on users computer;

a email with an update .zip is sent to you from fedex or UPS;

you thinking its legit, open it and bang goes your system, moral of the story dont open .zip attachments,
 
One of my customers got infected by one of the variants today. They opened some video / zip file from email, which came with an error message and opened some website.

They called me with some problem of software not working and the PC being extremely slow(was probably busy encrypting).

My first instincts are always to go back to a previous shadow copy. That saved them a lot of damage. Doing that I managed to get to a restore point before the PC was infected and it stopped the encryption process. Looks like only about 10% or less of their data is infected (basically everything in the first few folders sorted alphabetically) and they do a full backup every month of all their PC's so hopefully not to much damage. All other computers are fine.

Tomorrow going to restore via a third PC and a new memory stick.(I don't connect the backup drive to the affected PC, just in case the f**ker is still running/active on the affected PC. I don't wanna infect the backup disk)

Yup those cryptolockers/ransomware things are nasty.

Unfortunately the only save computer is a computer which never gets switched on.
 
Last edited:
Probably got it from Norton. Norton is known to be bloatware rubbish.

Well I guess your server is proper farked now.

Yep, lost basically fken everything.. the only way we think it came on our system, one of our new laptops only had Avast Free antivirus on it, thus not the most comprehensive protection and the individual clicked on spam email/attachment.. :cry:
 
One more reason to stick to linux...

Edit : Wonder if the API will work if the drive is already encrypted probably not ?

Currently our backups are sitting on a tower pc running Windows 7x64, thinking of switching to FreeNas , being linux file system what effect will viruses/trojans like this have on a system running linux?
 
Currently our backups are sitting on a tower pc running Windows 7x64, thinking of switching to FreeNas , being linux file system what effect will viruses/trojans like this have on a system running linux?

freenas is based on freebsd, not linux
 
Just note that Dropbox also gets infected. Luckily the rollback feature works.

Say what??? I am planning on sending all my photos to GDrive instead but since you say a cloud service can get farked... uhm... how?
 
Say what??? I am planning on sending all my photos to GDrive instead but since you say a cloud service can get farked... uhm... how?

No, it gets funnier! Not going to name names, but this person that got infected, infected his dropbox. Now this is fine and all that BUT because he was on a global dropbox, the files got synchronized into EVERYONE'S box! And this company is huge and everyone knows their name.
How embarrassing!

Oh, how does it do it? Simple, it attacks everything on your machine including shared drives and map drives.
 
How did it get onto your PC?
If I look at our Mimecast malware filters, most of the messages that contain the Cryptolocker malware (47/50) have the following subject lines:
Jennifer Lawrence's iCloud nude pix
NEW Celebrity Nudes Leaked
Vanessa Hudgens, Paige Duke, Kelly Brooke EXPOSED
Fappening - Second Cumming NEW NUDES!
etc, etc.

All have PDF, PPT, JPG attachments that are actually .EXE's
 
Most of these infections are being delivered using email attachments with a .js file within a zip file.

Check with your email provider as they should be scanning your inbound email for viruses.
 
If I look at our Mimecast malware filters, most of the messages that contain the Cryptolocker malware (47/50) have the following subject lines:
Jennifer Lawrence's iCloud nude pix
NEW Celebrity Nudes Leaked
Vanessa Hudgens, Paige Duke, Kelly Brooke EXPOSED
Fappening - Second Cumming NEW NUDES!
etc, etc.

All have PDF, PPT, JPG attachments that are actually .EXE's

LOL :D

Something interesting, the files it goes after are the following types:
3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx

They mostly seem to be targeting document type files. Just another reason to use Latex.

Frankly I am a bit insulted. The real value of my work lies in the source code and documentation that I have written in Latex.

To the potential ransomware writers, ignore this post
 
Fck me I got 90% of a clients data back!

How cryptolocker works is it creates a copy of the file it encrypts, and then deletes the original.
That is where we stand half (maybe less) a chance.

Windows doesn’t actually delete the data, just marks it as free space until it needs the space.
So when infected just pull the plug (shutdown may install updates or something), take the drive out and attach to another pc.
Then use an app that can recover deleted files, I used Easeus but there plenty of free tools that can do the same thing. Takes the whole day to scan the drive though.

The less space you have on the drive and closer to full capacity the less chance you’ll have I guess.
My client was just lucky – had only used 20% of the drive.
 
sitting on 3 nuked sites here, what do they all have in common?
- No lockdown
- Local admin
- bad backups

recoving the deleted files now.
 
Fck me I got 90% of a clients data back!

How cryptolocker works is it creates a copy of the file it encrypts, and then deletes the original.
That is where we stand half (maybe less) a chance.

Windows doesn’t actually delete the data, just marks it as free space until it needs the space.
So when infected just pull the plug (shutdown may install updates or something), take the drive out and attach to another pc.
Then use an app that can recover deleted files, I used Easeus but there plenty of free tools that can do the same thing. Takes the whole day to scan the drive though.

The less space you have on the drive and closer to full capacity the less chance you’ll have I guess.
My client was just lucky – had only used 20% of the drive.

Update:
2nd client also 90% success, third client I got zero, but I suspect they messed with the drive a bit, installing antivirus and antimalware software before I got to it..

Today I setup a test machine with about 5GB of data, mainly photos and docs.
Ran the java script (via an email I had captured) and let it encrypt everything.
Then I pulled the power plug and took out the drive.

From the deleted " lost files" in Easeus I got everything back with a loss of maybe 20meg.
Pretty much a success rate of 99%
 
Top
Sign up to the MyBroadband newsletter
X