Jump to content

Really Nasty Virus 'CryptoLocker' Heads Up

bchampion96

Hi guys,

 

Dunno if you've heard about this one, but just keep you common sense sharp and don't do dodgy stuff because even big name antiviruses can't stop it. The only way of getting rid of it is a hard drive wipe, so get back ups going.

 

cryptolocker.png

 

http://www.switchfast.com/switchfast-blog/2013/10/2/virus-alert-cryptolocker-ransomware.aspx

Feel free to message me if you want to chat!

Link to comment
Share on other sites

Link to post
Share on other sites

I always play it cautiously when online anyway, I never ever go on a website that I think is dodgy. As you stated, common sense.

CPU: Intel Core i5 2550K @ 4GHz | Cooler: Gelid Tranquillo Rev. 2 | Mobo: Gigabyte GA-Z68AP-D3

GPU: XFX 1GB HD6850 OC'd | SSD: OCZ Agility 3 60GB | HDD: Samsung 500GB | PSU: Corsair HX520W | Case: Zalman Z11+

 
Link to comment
Share on other sites

Link to post
Share on other sites

Tis the best antivirus 

Indeed so. What types of files is this virus on, do you know? Installers? Webpages?

CPU: Intel Core i5 2550K @ 4GHz | Cooler: Gelid Tranquillo Rev. 2 | Mobo: Gigabyte GA-Z68AP-D3

GPU: XFX 1GB HD6850 OC'd | SSD: OCZ Agility 3 60GB | HDD: Samsung 500GB | PSU: Corsair HX520W | Case: Zalman Z11+

 
Link to comment
Share on other sites

Link to post
Share on other sites

I had a simillar virus to this that locked down the computer, and I removed it by jsut disconnecting myself from the internet and then used windows restore (i Think(could be revert or something simillar)) to go back four 4 hour to when i didnt have this virus. I did this on windows 7

sorry for bad English, my computer wants to correct everything to swedish

 

Link to comment
Share on other sites

Link to post
Share on other sites

Indeed so. What types of files is this virus on, do you know? Installers? Webpages?

 

Mostly email transmitted, it seems.

Feel free to message me if you want to chat!

Link to comment
Share on other sites

Link to post
Share on other sites

Mostly email transmitted, it seems.

That's okay then, I don't really e-mail that much :P

CPU: Intel Core i5 2550K @ 4GHz | Cooler: Gelid Tranquillo Rev. 2 | Mobo: Gigabyte GA-Z68AP-D3

GPU: XFX 1GB HD6850 OC'd | SSD: OCZ Agility 3 60GB | HDD: Samsung 500GB | PSU: Corsair HX520W | Case: Zalman Z11+

 
Link to comment
Share on other sites

Link to post
Share on other sites

I asked Avast UK and they said they have got it in their virus database already

I don't think it will be long before most AV's have it in their databases; wonder if Anti-MalwareBytes can find it. Highly recommend it, my friends used it and got rid of virus/malware on their computers.

CPU: Intel Core i5 2550K @ 4GHz | Cooler: Gelid Tranquillo Rev. 2 | Mobo: Gigabyte GA-Z68AP-D3

GPU: XFX 1GB HD6850 OC'd | SSD: OCZ Agility 3 60GB | HDD: Samsung 500GB | PSU: Corsair HX520W | Case: Zalman Z11+

 
Link to comment
Share on other sites

Link to post
Share on other sites

Btw this is a stupid noob questions but ive never got a virus via email before, how do you get a virus from emails. do you just click the email and get a virus or is it when you click on an attachment.

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

I have super anti-spyware, Malwarebtyes and bitdefender anti-virus on my PC, so this is going to have to be quite stealthy.

Link to comment
Share on other sites

Link to post
Share on other sites

Btw this is a stupid noob questions but ive never got a virus via email before, how do you get a virus from emails. do you just click the email and get a virus or is it when you click on an attachment.

You can open attachments which contain them. If I recall, I think you can get them via opening the e-mail itself. But never open an e-mail that looks dodgy to you, again it's all common sense; just delete it and forget about it!

CPU: Intel Core i5 2550K @ 4GHz | Cooler: Gelid Tranquillo Rev. 2 | Mobo: Gigabyte GA-Z68AP-D3

GPU: XFX 1GB HD6850 OC'd | SSD: OCZ Agility 3 60GB | HDD: Samsung 500GB | PSU: Corsair HX520W | Case: Zalman Z11+

 
Link to comment
Share on other sites

Link to post
Share on other sites

Don't have HTML activated by default and never open an email or an attachment if you don't know exactly what it is and who sent it.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

Btw this is a stupid noob questions but ive never got a virus via email before, how do you get a virus from emails. do you just click the email and get a virus or is it when you click on an attachment.

 

It happens when people open: image.jpg.exe, and don't have an anti-virus. Or they do, they it's a trial when they bought the computer, and it's expired.

Link to comment
Share on other sites

Link to post
Share on other sites

AntiVirus' can't do anything to this. Sure they can remove the virus itself, but it can't decrypt the files.

 

As said by OP the only way to deal with after you have it is to do a restore to before you had it.

 

And please for the love of god if you get this, don't pay the ransom.

| NZXT Phantom | i5-2500k @4Ghz | H60 | EVGA GTX 680 Sig2 | 8GB Corsair Vengeance | 

Link to comment
Share on other sites

Link to post
Share on other sites

Someone is really messed up to do this.

 

 

anyway, I dont really have anything on my PC that cant be restored in a day.

 

Steam games, Free programs (fraps, Paint.NET, Notepad++), account based games (Minecraft, 2142, Planetside 2)

 

Documents & images are my only concern, but I have 10 GB of cloud storage, so I should start uploading that.

Link to comment
Share on other sites

Link to post
Share on other sites

If you have Windows 8, and a second internal or external HDD, you can use File History.

I have mine doing backups every 10min, and I can go back in time. If I format and re-install Windows, turning on File History feature will re3deect everything and resume backup operation where it left of.

Link to comment
Share on other sites

Link to post
Share on other sites

I don't need to worry about a virus but my favorite one is the one that replaces your wallpaper with a background saying the government needs to get paid 50k or whatever because you have child porn or something illegal on your pc that or it calls you a terrorist.

Link to comment
Share on other sites

Link to post
Share on other sites

Good luck on breaking that encryption RSA 2048 is one hell of an encryption algorithm to use. The RSA 2048 keys are 2^32 stronger then  1024 bit  keys.

 

2^32 = 4,294,967,296 or almost 4.3 billion, therefore breaking a  2048-bit SSL certificate would take about 4.3 billion times longer. So using a standard desktop level processor you can expect the runtime to take 4,294,967,296 x 1.5 million years to break a  2048-bit SSL certificate.

 

Or in "smaller" terms a little over 6.4 quadrillion years.

 

Makes that $300 dollars look like a bargain. If you got this virus its over, there is no way to crack it. If you do a little research on Cryptography you will find that typically encryption is only broken when average level computing power is able to surmount it. 

Link to comment
Share on other sites

Link to post
Share on other sites

if the website looks fishy, don't click it.

 

if the picture looks fishy, don't click it

 

 

on the interwebs, fish are bad. do not go near dem and you will be ok :D

Stuff:  i7 7700k @ (dat nibba succ) | ASRock Z170M OC Formula | G.Skill TridentZ 3600 c16 | EKWB 1080 @ 2100 mhz  |  Acer X34 Predator | R4 | EVGA 1000 P2 | 1080mm Radiator Custom Loop | HD800 + Audio-GD NFB-11 | 850 Evo 1TB | 840 Pro 256GB | 3TB WD Blue | 2TB Barracuda

Hwbot: http://hwbot.org/user/lays/ 

FireStrike 980 ti @ 1800 Mhz http://hwbot.org/submission/3183338 http://www.3dmark.com/3dm/11574089

Link to comment
Share on other sites

Link to post
Share on other sites

kaspersky has some tools available to decrypt the files on the drive as well if you find that they are still locked after removal.

4770k @4.4 / 16GB @2400 / Plextor MP5X 128GB / MSI Mpower Z87 / MSI GTX 1070 Armor OC / AX860 / XSPC RX240 & EX240 / Koolance 380i / CM 690 II / Qnix 1440p @96Hz / Benq XL2420G

Current Status: Mourning the loss of my 780 ti 

Link to comment
Share on other sites

Link to post
Share on other sites

So what are they going to do now? How did he go about getting it?

They paid $300. What could they do really? The server had hundreds of PDF files and each of them had a256 bit encryption

Finally my Santa hat doesn't look out of place

Link to comment
Share on other sites

Link to post
Share on other sites

They paid $300. What could they do really? The server had hundreds of PDF files and each of them had a256 bit encryption

 

Yea, it's call having an hourly backup. Any server should have this. PLUS, have daily backup on seperate drive or be old school cassets.

Also, why the authorities was not informed? Why the virus got installed on the server in the first place? Who accessed the server (I mean someone had to install it)? Why would someone use the server as his or hers own computer, let alone be admin? Was it made on purpose? Was the server running on legacy Windows?

 

Basic IT guys.. basic IT. I don't think you even need a degree to even know this.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×