Close

Page 1 of 4 1234 LastLast
Results 1 to 20 of 61
  1. #1
    DF Probation MsDG's Avatar
    Join Date
    May 2002
    Location
    Birmingham
    Posts
    6,456
    Thanks
    93
    Thanked:        1,176
    Karma Level
    947

    Attention Cryptolocker Ransomware Warning

    I thought I should highlight this nasty little bugger to all, as it is doing the rounds at work (cyrptolocker)

    There is a new form of mailware/virus going around that has a unique spin to it. When infected your PC will show no signs of problems while its busy encrypting all of your personal files (Documents / pictures etc) on both your PC and any none UNC drives you have attached to it. Once complete, it then pops up the usual ransom message bollocks.

    The thing that makes this one different to the rest is that you can remove the virus... but you CANNOT decrypt your personal files. They are using strong encryption and no-one yet has cracked it.

    Unless you have backups of your file (on something that wasn't attached at the time of getting the virus) you have pretty much lost everything!

    http://en.wikipedia.org/wiki/CryptoLocker

    9 Thanks given to MsDG

    chesser (29th October 2013),  Doctor Who (26th October 2013),  Mobileman (26th October 2013),  Mr.James (26th October 2013),  Mule (26th October 2013),  muttleymacclad (26th October 2013),  QfanatiQ (28th October 2013),  WRATH OF BOD (28th October 2013),  Zoots (28th October 2013)  


  2. #2
    DF VIP Member hoponbaby's Avatar
    Join Date
    Nov 2000
    Posts
    996
    Thanks
    155
    Thanked:        218
    Karma Level
    335

    Default Re: Cyrptolocker Ransomware Warning

    Apparently they are upholding their end of the "deal" and releasing the decryption key if you pay within the designated time, in some cases people have no choice 😞 effective little scam by the bastards

  3. #3
    DF VIP Member Over Carl's Avatar
    Join Date
    Apr 2006
    Location
    London
    Posts
    13,125
    Thanks
    3,975
    Thanked:        1,690
    Karma Level
    1252

    Default Re: Cyrptolocker Ransomware Warning

    I've been told if you can find previous versions of the file (right click, properties, previous versions) this works. Also been told it just renames everything to loads of *.tmp files.

    Haven't seen it myself so can't say if that works.

  4. #4
    DF VIP Member
    ZX7R's Avatar
    Join Date
    May 2002
    Location
    Hertfordshire
    Posts
    3,976
    Thanks
    507
    Thanked:        799
    Karma Level
    578

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by MsDG View Post
    I thought I should highlight this nasty little bugger to all, as it is doing the rounds at work (cyrptolocker)

    There is a new form of mailware/virus going around that has a unique spin to it. When infected your PC will show no signs of problems while its busy encrypting all of your personal files (Documents / pictures etc) on both your PC and any none UNC drives you have attached to it. Once complete, it then pops up the usual ransom message bollocks.

    The thing that makes this one different to the rest is that you can remove the virus... but you CANNOT decrypt your personal files. They are using strong encryption and no-one yet has cracked it.

    Unless you have backups of your file (on something that wasn't attached at the time of getting the virus) you have pretty much lost everything!

    http://en.wikipedia.org/wiki/CryptoLocker
    Out of interest, what anti-virus solution is being used at your workplace?

  5. #5
    DF Probation MsDG's Avatar
    Join Date
    May 2002
    Location
    Birmingham
    Posts
    6,456
    Thanks
    93
    Thanked:        1,176
    Karma Level
    947

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by Over carl View Post
    I've been told if you can find previous versions of the file (right click, properties, previous versions) this works. Also been told it just renames everything to loads of *.tmp files.

    Haven't seen it myself so can't say if that works.
    The old Ransomware renamed files to tmp.... this new one actually encrypts files. Unless you have some backup of files (sometimes Windows restore works) you are really up shit creek

    Thanks to MsDG

    Over Carl (27th October 2013)  


  6. #6
    DF Probation MsDG's Avatar
    Join Date
    May 2002
    Location
    Birmingham
    Posts
    6,456
    Thanks
    93
    Thanked:        1,176
    Karma Level
    947

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by ZX7R View Post
    Out of interest, what anti-virus solution is being used at your workplace?
    Symantec Corporate. But to be fair to the AV, I think in all cases the payload is being delivered by the user either opening a dodgy zip from an email attachment or installing shite downloaded from the internet.

    You must remember that this ransomware is making someone big money, so they are putting effort in to disguise the signature in 0day wave attacks.

    The most effective way to block this little shit seems to be via creating a local / group policy to prevent EXE and ZIP files running in the temp areas of the users profile.

    http://www.bleepingcomputer.com/viru...re-information

  7. #7
    DF VIP Member Mr.James's Avatar
    Join Date
    Nov 2000
    Location
    town
    Posts
    4,264
    Thanks
    233
    Thanked:        408
    Karma Level
    576

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by MsDG View Post
    The most effective way to block this little shit seems to be via creating a local / group policy to prevent EXE and ZIP files running in the temp areas of the users profile.
    I've been doing this for a long time at work and it can be a right pain in the arse. People can only execute stuff from program files and windows folders but it causes so many issues I'm thinking of scrapping it, maybe not if this could be a concequence. It's surprising how many legitimately installed apps copy stuff to a temp folder and run it from there. I must battle with software restriction polices once or twice a month.



    ________________
    Sent via Tapatalk

    2 Thanks given to Mr.James

    Over Carl (27th October 2013),  Zoots (26th October 2013)  


  8. #8
    DF VIP Member Mr.James's Avatar
    Join Date
    Nov 2000
    Location
    town
    Posts
    4,264
    Thanks
    233
    Thanked:        408
    Karma Level
    576

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by MsDG View Post
    and any none UNC drives you have attached to it.
    Just out of curiosity, does it do mapped network drives? That could be a right pain!


    ________________
    Sent via Tapatalk

  9. #9
    DF Probation MsDG's Avatar
    Join Date
    May 2002
    Location
    Birmingham
    Posts
    6,456
    Thanks
    93
    Thanked:        1,176
    Karma Level
    947

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by Mr.James View Post
    Just out of curiosity, does it do mapped network drives? That could be a right pain!


    ________________
    Sent via Tapatalk
    I am not sure. We use mapped UNC drives... so far we have not had any issues on the network drives.

    Thanks to MsDG

    Mr.James (26th October 2013)  


  10. #10
    DF VIP Member Mr.James's Avatar
    Join Date
    Nov 2000
    Location
    town
    Posts
    4,264
    Thanks
    233
    Thanked:        408
    Karma Level
    576

    Default Re: Cyrptolocker Ransomware Warning

    That's not too bad then... All our 'my docs' folders are redirected onto UNC and the rest on mapped drives. Only thing people would lose are desktop folders favourites etc.

    Email archives could be a pain though.


    ________________
    Sent via Tapatalk

  11. #11
    DF VIP Member keyser666's Avatar
    Join Date
    Sep 2013
    Location
    United Kingdom
    Posts
    275
    Thanks
    92
    Thanked:        152
    Karma Level
    157

    Default Re: Cyrptolocker Ransomware Warning

    Well Outlook strips out attachments at client level that are .exe .bat .zip etc. They are actually there but the default reg key is not to show them, so users wont be seeing them anyway. Cant remember with Notes or Groupwise as I have not supported them for some years

  12. #12
    DF VIP Member akimba's Avatar
    Join Date
    Jun 2006
    Location
    UK
    Posts
    2,846
    Thanks
    1,034
    Thanked:        783
    Karma Level
    369

    Default Re: Cyrptolocker Ransomware Warning

    theres so much 3rd party encryption software is out there now it wasn't going to be long until it was used for ill gotten gains :-(

  13. #13
    DF VIP Member QfanatiQ's Avatar
    Join Date
    Jan 2004
    Location
    Berkshire
    Posts
    3,944
    Thanks
    241
    Thanked:        131
    Karma Level
    437

    Default Re: Cyrptolocker Ransomware Warning

    Thanks for this. I got hit several times on the old Ransomware. I must back up and will do tonight. This is a good reason to save files on a separate HD as well.

    I take it Win7 does not have a block against this?

    What is the money being asked for value wise?

    Cheers.....Q

  14. #14
    DF VIP Member DJ OD's Avatar
    Join Date
    Jul 2001
    Location
    On da decks.
    Posts
    10,114
    Thanks
    1,008
    Thanked:        2,254
    Karma Level
    1105

    Default Re: Cyrptolocker Ransomware Warning

    Cunning little trick TBH.

    Thing is, regardless of how good your A/V security is, you can never stop idiots doing stupid shit. In the work place nothing should be stored locally anyway. If local machines get infected, a quick reboot with a machine image fixes all in a few minutes.

    Fkin shite for home users! Hardly anyone backs up stuff properly.

    I've got my music backed up in about 5 locations! Need to do a new one though...


    DJ OD

  15. #15
    DF Probation MsDG's Avatar
    Join Date
    May 2002
    Location
    Birmingham
    Posts
    6,456
    Thanks
    93
    Thanked:        1,176
    Karma Level
    947

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by QfanatiQ View Post
    Thanks for this. I got hit several times on the old Ransomware. I must back up and will do tonight. This is a good reason to save files on a separate HD as well.

    I take it Win7 does not have a block against this?

    What is the money being asked for value wise?

    Cheers.....Q
    Windows will block if it is an outside attack, but if the user initiates it (i.e. manually installing it) then you are entirely down to your AV recognising it and blocking it.

    Money = up to $300

  16. #16
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default Re: Cyrptolocker Ransomware Warning

    Was thinking about this.

    If you remove the Infection and all traces of it, how do you then find who to contact to get the decryption key from?

    Is it a unique key for each decryption or a common public key ?

    If its unique then how do the 'infectors' know it's their variant that has caused the encryption and therefore provide the right key (assuming there are variants in the wild?)

    Do you have to provide a hash to obtain the correct de-crypt key?

    Mml


    Sent from my iPhone using Tapatalk
    "When a naked man is chasing a woman through an alley with a butchers knife and a hard-on, I figure he isn't out collecting for the Red Cross." - 'Dirty' Harry

  17. #17
    DF Probation MsDG's Avatar
    Join Date
    May 2002
    Location
    Birmingham
    Posts
    6,456
    Thanks
    93
    Thanked:        1,176
    Karma Level
    947

    Default Re: Cyrptolocker Ransomware Warning

    Obviously if you killl the virus you cannot then pay and get the files decrypted.

    From the forums I have read, no-one has yet reversed engineered the virus, so no-one knows much about the encryption.

    "The necessary decryption key is never left lying around on host machines. CryptoLocker phones home to a command-and-control server to obtain a public RSA key before it begins the task of silently encrypting files on compromised machines. The same command server also hosts the private key."

  18. #18
    DF VIP Member QfanatiQ's Avatar
    Join Date
    Jan 2004
    Location
    Berkshire
    Posts
    3,944
    Thanks
    241
    Thanked:        131
    Karma Level
    437

    Default Re: Cyrptolocker Ransomware Warning

    Quote Originally Posted by MsDG View Post
    Windows will block if it is an outside attack, but if the user initiates it (i.e. manually installing it) then you are entirely down to your AV recognising it and blocking it.

    Money = up to $300
    Are we talking Ransomware generally or this new one?

    I never instigated it, first time is explainable, but my other two hits, no idea and very frustrating.

    Never the less, this is good to know and deal with.

    Q

  19. #19
    DF VIP Member Over Carl's Avatar
    Join Date
    Apr 2006
    Location
    London
    Posts
    13,125
    Thanks
    3,975
    Thanked:        1,690
    Karma Level
    1252

    Default Re: Cyrptolocker Ransomware Warning

    Just started my first day doing commercial IT Support in a while and had fun with a client that had this virus. Only one machine was infected, but this nuked pretty much everything on the UNC shares on the server that were setup as mapped drives (mapped via ip address rather than hostname if that makes a difference)

    Quote Originally Posted by muttleymacclad View Post
    Was thinking about this.

    If you remove the Infection and all traces of it, how do you then find who to contact to get the decryption key from?
    If you get infected you will have a countdown, it says after this the files will not be recoverable even if you pay. As you mentioned if you uninstall/clean it you then won't be able to pay if you wished, but they helpfully provide a link you can use to re-infect the pc to allow you to pay them to sort it.

    Quote Originally Posted by MsDG View Post
    Money = up to $300
    The two options I saw were either 2 bitcoin or you had to load money on some prepayment card that only is a valid option in the US.

  20. #20
    DF Super Moderator
    evilsatan's Avatar
    Join Date
    Jul 2004
    Location
    Essex
    Posts
    20,080
    Thanks
    1,105
    Thanked:        3,242
    Karma Level
    1542

    Default Re: Cyrptolocker Ransomware Warning

    Cloud backups with versioning ftw then and offline backups for the data that's too large. Might have to disconnect my mapped drives for the time being too as the data on there is too large to backup (but is also replaceable, just inconvenient to lose).

    Looks like I will be buying MBAM Pro just in case, it claims to prevent infection:
    http://blog.malwarebytes.org/intelli...-need-to-know/

    Lifetime Pro license less than half price:
    http://www.digital-forums.com/showth...9-30?p=3721643
    Last edited by evilsatan; 29th October 2013 at 08:14 PM.


Page 1 of 4 1234 LastLast

Similar Threads

  1. Ford Airbag Warning Lights
    By mjf5 in forum Cars & Motorbikes
    Replies: 2
    Last Post: 17th November 2002, 11:29 AM
  2. Virus Warning
    By sligoman in forum Digital Satellite TV
    Replies: 7
    Last Post: 6th October 2002, 02:50 PM
  3. WARNING DONT USE DIVINO(THEY FUCKED ME ;()
    By vegasplaye in forum Old Skool Gaming & Retro
    Replies: 2
    Last Post: 24th September 2002, 11:50 AM
  4. Replies: 5
    Last Post: 7th September 2002, 12:48 PM
  5. Warning to athletes looking 2 put on weight
    By Porthos in forum Health & Fitness
    Replies: 0
    Last Post: 29th August 2002, 06:03 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •