Cryptolocker ransomed my pc!

Started by Yskonyn, March 08, 2014, 11:41:17 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Yskonyn

Well that was unexpected...
I booted my PC and upon entering the Windows desktop I was greeted with a background image accompanied by a pop-up window telling me that all my files were now encrypted and if I wanted to get them back I had 24 hrs to send 300 dollars in bitcoins to a certain server in exchange for an unlocking key.
If the timer runs out without payment recieved or any tampering with the software is detected, the unlock key would be deleted from their server and my files are lost forever.

Files encrypted include documents and photo's, so without a back-up all your Personal stuff is gone. Luckily I have all my stuff on a different computer, so a clean followed by a format C was not such a big deal, but this form of malware can be rather disastrous!

There is no way to decrypt your files though, just to get rid of the infection itself. So without a proper back-up you are screwed.
Be warned!

I probably got it because the missus clicked an add or opened an email she was not supposed to.
"Pilots do not get paid for what they do daily, but they get paid for what they are capable of doing.
However, if pilots would need to do daily what they are capable of doing, nobody would dare to fly anymore."

Grim.Reaper


Nefaro


FarAway Sooner

Yowza!  Did you have up-to-date antivirus software running on  your PC when it happened?  That really sucks...

Martok

Quote from: Grim.Reaper on March 08, 2014, 11:43:07 AM
Wow....that really stinks.
Quote from: Nefaro on March 08, 2014, 11:44:07 AM
Yikes.
+1 to what they said. 

Sorry to hear that, Yskonyn.  I'm glad nothing truly important/critical was lost, but it's still a shitty deal. 

"Like we need an excuse to drink to anything..." - Banzai_Cat
"I like to think of it not as an excuse but more like Pavlovian Response." - Sir Slash

"At our ages, they all look like jailbait." - mirth

"If we had lines here that would have crossed all of them. For the 1,077,986th time." - Gusington

"Government is so expensive that it should at least be entertaining." - airboy

"As long as there's bacon, everything will be all right." - Toonces

Rayfer

Quote from: FarAway Sooner on March 08, 2014, 12:49:20 PM
Yowza!  Did you have up-to-date antivirus software running on  your PC when it happened?  That really sucks...

Yes, I would think/hope a good anti-virus software would prevent this. Am I naive to think this?

Mr. Bigglesworth

Move to tech talk.

What AV were you using?
"Once more unto the breach, dear friends, once more; "
- Shakespeare's Henry V, Act III, 1598

donkey_roxor

Yikes indeed.

This is why I don't ever use computers or the Internet.



Yskonyn

Thanks guys,

Yes I was running ESET NOD 32 version 7. A good anti-virus software, but this particular thing was a Malware. Something a virus scanner doesn't usually protect you from.
From what I gather on the web, Malwarebytes Anti-Malware is about the only mainstream program that can get rid of the infection.
But nothing can de-crypt the files that were affected. So unless you can restore a backup, you're screwed.

As for preventing;
Awareness is the best defense; if you get a weird email, check, double check and look at details in there. There are always weird things in those mails that eventhough they seem to come from a legit sender like Paypal, certain parts of the mail do not add up; addresses, familiar (from your addressbook) contacts referenced, weird looking URLs in embedded links. Stuff like that.

There is a tool to lock certain windows parts from being  accessed and therefore supposed to prevent Cryptolock from being able to get installed. But those tools are pretty shady themselves...
"Pilots do not get paid for what they do daily, but they get paid for what they are capable of doing.
However, if pilots would need to do daily what they are capable of doing, nobody would dare to fly anymore."

Mr. Bigglesworth

"Once more unto the breach, dear friends, once more; "
- Shakespeare's Henry V, Act III, 1598

Greybriar

Today.com has an article about CryptoLocker and so does Wikipedia.

If worse comes to worse, couldn't you just format your hard drive and get rid of it (and everything else!)?
Regardless of how good a PC game may be it will always have its detractors and no matter how bad a PC game may be it will always have its fans.

eyebiter

.
#11
.

Greybriar

I wasn't aware that CryptoLocker affected the System BIOS. If it does it's nasty indeed.
Regardless of how good a PC game may be it will always have its detractors and no matter how bad a PC game may be it will always have its fans.

W8taminute

That's just plain evil.  This kind of thing should be an international offense with a harsh punishment.  Really there is big business to be made in tracking and capturing these kinds of malicious software criminals. 

This is the same act as if someone physically entered your house while you and your family were away and then proceeded to change the locks and board the windows.  You could only re-enter your house provided that you payed some extortion over to the thief.  I'm kind of outraged by this.

Anyway sorry to hear this happened to you Yskonyn and I hope that you did not lose anything important even though you had a backup.
"You and I are of a kind. In a different reality, I could have called you friend."

Romulan Commander to Kirk

Con

well stories like these make me go setup my backup

I have Norton 360 its a pain sometimes but I am glad to see that it is rated highly and I am using their backup software now

Thanks for the warning

Con