Jump to content

can you restore windows?

work it ᕙ༼ຈل͜ຈ༽ᕗ harder, make it (ง •̀_•́)ง better, do it ᕦ༼ຈل͜ຈ༽ᕤ faster, raise ur ヽ༼ຈل͜ຈ༽ノ donger

ᕙ༼ຈل͜ຈ༽ᕗ HARDER, BETTER, FASTER, DONGER! ᕙ༼ຈل͜ຈ༽ᕗ

 

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173381
Share on other sites

Link to post
Share on other sites

I prefer caution over data preservation

The infection isn't polymorphic or anything nor does it embed itself in any system files. It is usually 1 file under AppData or at the root of C:\.

No need to be cautious. It's not like its a worm or anything. It's a very simple infection really. It just works in such a way as to make it impossible to restore your data unless you have backups or run Vista/7 and can use the shadow copy service to restore previous versions of the files. System restore does not do this.

CPU: i7-3930K @ 4.8GHz MOBO: IV Gene RAM: 16GB Crucial Ballistix Tactical Tracer 1866MHz GPU: GTX 780 Ti CASE: Corsair 350D STORAGE: 2 x Samsung 840 Pro 256 GB, 2x WD Red 4TB
PSU
: EVGA SuperNova 650W DISPLAY: 1 x ASUS VG248QE, 3 x Dell U2414H COOLING: Corsair H100i INPUT: Corsair Vengeance K70, SteelSeries Sensei AUDIO: Sennheiser HD 280 Pro, ATH-M50s, Beredynamic DT770 Pro, Steelseries H Wireless

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173389
Share on other sites

Link to post
Share on other sites

The infection isn't polymorphic or anything nor does it embed itself in any system files. It is usually 1 file under AppData or at the root of C:\.

No need to be cautious. It's not like its a worm or anything. It's a very simple infection really. It just works in such a way as to make it impossible to restore your data unless you have backups or run Vista/7 and can use the shadow copy service to restore previous versions of the files. System restore does not do this.

I still prefer the "burn everything" method

-The Bellerophon- Obsidian 550D-i5-3570k@4.5Ghz -Asus Sabertooth Z77-16GB Corsair Dominator Platinum 1866Mhz-x2 EVGA GTX 760 Dual FTW 4GB-Creative Sound Blaster XF-i Titanium-OCZ Vertex Plus 120GB-Seagate Barracuda 2TB- https://linustechtips.com/main/topic/60154-the-not-really-a-build-log-build-log/ Twofold http://linustechtips.com/main/topic/121043-twofold-a-dual-itx-system/ How great is EVGA? http://linustechtips.com/main/topic/110662-evga-how-great-are-they/#entry1478299

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173408
Share on other sites

Link to post
Share on other sites

The infection isn't polymorphic or anything nor does it embed itself in any system files. It is usually 1 file under AppData or at the root of C:\.

No need to be cautious. It's not like its a worm or anything. It's a very simple infection really. It just works in such a way as to make it impossible to restore your data unless you have backups or run Vista/7 and can use the shadow copy service to restore previous versions of the files. System restore does not do this.

Yes but are the files still encypted

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173432
Share on other sites

Link to post
Share on other sites

You have to reinstall windows so get to it then follow these tips to avoid this in the future

 

 

1. Stop going to naughty places on your primary rig, build a crap thing with ubuntu for that.

 

2. Stop opening ever email you get.

 

3. Common sense is the best antivirus there is.

 

4. Clean up your desktop, seeing that many icons makes my head hurt.

 

 

(also grats, you just announced to the forum that you were watching some really kinky stuff)

I've never actually gotten a virus watching any really kinky (never gotten a virus from doing anything really kinky either). It's usually websites that offer copywrite infringing material that will give you viruses.

 

I wonder if the files are actually encrypted. It's possible it's just a scare tactic. Additionally, anything that requires a remote server is extremely risky because the police can track it back to you with reasonable ease.

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173526
Share on other sites

Link to post
Share on other sites

Got this at my work when somebody opened an EXE attachment and the entire share directory was encrypted. You CANNOT just remove it with a virus scanner since the files are still encrypted. You either restore from backup or pay them for the decryption key. If you remove the virus, you won't be able to decrypt the files and need to "re-infect" to use the decryption key. By then, the timer would probably have run out and you have to pay more. We just ended up restore from backup.

 

ps. yes, the files are actually encrypted using a 2048-bit RSA key, virtually impossible to crack.

 

 

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173539
Share on other sites

Link to post
Share on other sites

I've never actually gotten a virus watching any really kinky (never gotten a virus from doing anything really kinky either). It's usually websites that offer copywrite infringing material that will give you viruses.

 

I wonder if the files are actually encrypted. It's possible it's just a scare tactic. Additionally, anything that requires a remote server is extremely risky because the police can track it back to you with reasonable ease.

I doubt the police give any f**ks

-The Bellerophon- Obsidian 550D-i5-3570k@4.5Ghz -Asus Sabertooth Z77-16GB Corsair Dominator Platinum 1866Mhz-x2 EVGA GTX 760 Dual FTW 4GB-Creative Sound Blaster XF-i Titanium-OCZ Vertex Plus 120GB-Seagate Barracuda 2TB- https://linustechtips.com/main/topic/60154-the-not-really-a-build-log-build-log/ Twofold http://linustechtips.com/main/topic/121043-twofold-a-dual-itx-system/ How great is EVGA? http://linustechtips.com/main/topic/110662-evga-how-great-are-they/#entry1478299

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173543
Share on other sites

Link to post
Share on other sites

Got this at my work when somebody opened an EXE attachment and the entire share directory was encrypted. You CANNOT just remove it with a virus scanner since the files are still encrypted. You either restore from backup or pay them for the decryption key. If you remove the virus, you won't be able to decrypt the files and need to "re-infect" to use the decryption key. By then, the timer would probably have run out and you have to pay more. We just ended up restore from backup.

paying most likely won't solve anything, they will just leave your files locked. I know if it were me doing it that's what I would do.

-The Bellerophon- Obsidian 550D-i5-3570k@4.5Ghz -Asus Sabertooth Z77-16GB Corsair Dominator Platinum 1866Mhz-x2 EVGA GTX 760 Dual FTW 4GB-Creative Sound Blaster XF-i Titanium-OCZ Vertex Plus 120GB-Seagate Barracuda 2TB- https://linustechtips.com/main/topic/60154-the-not-really-a-build-log-build-log/ Twofold http://linustechtips.com/main/topic/121043-twofold-a-dual-itx-system/ How great is EVGA? http://linustechtips.com/main/topic/110662-evga-how-great-are-they/#entry1478299

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173549
Share on other sites

Link to post
Share on other sites

Got this at my work when somebody opened an EXE attachment and the entire share directory was encrypted. You CANNOT just remove it with a virus scanner since the files are still encrypted. You either restore from backup or pay them for the decryption key. If you remove the virus, you won't be able to decrypt the files and need to "re-infect" to use the decryption key. By then, the timer would probably have run out and you have to pay more. We just ended up restore from backup.

 

ps. yes, the files are actually encrypted using a 2048-bit RSA key, virtually impossible to crack.

Paying doesn't unlock your files anymore. They were unlocking them for a while. Now there are so many variants out there. Most just scam you out of funds.

And yes you can just remove it. Again, if you are on Vista/7 you can use shadow copy service to restore files if a backup is not an option.

CPU: i7-3930K @ 4.8GHz MOBO: IV Gene RAM: 16GB Crucial Ballistix Tactical Tracer 1866MHz GPU: GTX 780 Ti CASE: Corsair 350D STORAGE: 2 x Samsung 840 Pro 256 GB, 2x WD Red 4TB
PSU
: EVGA SuperNova 650W DISPLAY: 1 x ASUS VG248QE, 3 x Dell U2414H COOLING: Corsair H100i INPUT: Corsair Vengeance K70, SteelSeries Sensei AUDIO: Sennheiser HD 280 Pro, ATH-M50s, Beredynamic DT770 Pro, Steelseries H Wireless

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173840
Share on other sites

Link to post
Share on other sites

I still prefer the "burn everything" method

I prefer the "non scare tactics method" :P

CPU: i7-3930K @ 4.8GHz MOBO: IV Gene RAM: 16GB Crucial Ballistix Tactical Tracer 1866MHz GPU: GTX 780 Ti CASE: Corsair 350D STORAGE: 2 x Samsung 840 Pro 256 GB, 2x WD Red 4TB
PSU
: EVGA SuperNova 650W DISPLAY: 1 x ASUS VG248QE, 3 x Dell U2414H COOLING: Corsair H100i INPUT: Corsair Vengeance K70, SteelSeries Sensei AUDIO: Sennheiser HD 280 Pro, ATH-M50s, Beredynamic DT770 Pro, Steelseries H Wireless

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1173842
Share on other sites

Link to post
Share on other sites

Well, you're funked. Goodbye personal data.

Main Rig: CPU: AMD Ryzen 7 5700X3D | RAM: 32GB (2x16GB) KLEVV CRAS XR RGB DDR4-3600 | Motherboard: Gigabyte B550I AORUS PRO AX | Storage: 500GB Crucial P3 Plus, 4TB Silicon Power UD90 | GPU: AsRock Radeon RX 9070 XT Steel Legend | Cooling: ThermalTake Floe 280mm w/ be quiet! Pure Wings 3 | Case: Sliger SM580 (Black) | PSU: Corsair SF850

Main Server: CPU: AMD Ryzen 9 5950X | RAM: 64GB (2x32GB) Corsair Vengeance LPX DDR4-3200 | Motherboard: ASUS Crosshair VII Hero WiFi | Storage: 512GB SKHynix NVMe | GPUs: NVIDIA TITAN Xp 2-way SLI | Cooling: Thermalright Frozen Prism 360mm | Case: Corsair 5000D Airflow (White) | PSU: Seasonic Focus GM850

File and Media Server (AOOSTAR WTR Pro): CPU: AMD Ryzen 7 5825U | RAM: 32GB (2x16GB) Silicon Power DDR4-3200 SODIMMs | Storage: 1TB Samsung 970 EVO Plus, 2x14TB Western Digital Ultrastar DC HC530

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1175159
Share on other sites

Link to post
Share on other sites

I've never actually gotten a virus watching any really kinky (never gotten a virus from doing anything really kinky either). It's usually websites that offer copywrite infringing material that will give you viruses.

 

I wonder if the files are actually encrypted. It's possible it's just a scare tactic. Additionally, anything that requires a remote server is extremely risky because the police can track it back to you with reasonable ease.

do tell what kind of kinkiness you were watching ;)

Case: NZXT Phantom PSU: EVGA G2 650w Motherboard: Asus Z97-Pro (Wifi-AC) CPU: 4690K @4.2ghz/1.2V Cooler: Noctua NH-D15 Ram: Kingston HyperX FURY 16GB 1866mhz GPU: Gigabyte G1 GTX970 Storage: (2x) WD Caviar Blue 1TB, Crucial MX100 256GB SSD, Samsung 840 SSD Wifi: TP Link WDN4800

 

Donkeys are love, Donkeys are life.                    "No answer means no problem!" - Luke 2015

 

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1175368
Share on other sites

Link to post
Share on other sites

This thread reminded me to do a backup. Luckily I only have a couple .blend files that I actually care about, so I just stuck those on a flash drive. Don't care about anything else.

 Motherboard: MSI Z97S Krait Edition █ CPU: Intel i7-4790K █ GPU: Nvidia Geforce GTX 780Ti █ RAM: 8GB AVEXIR DDR3 1600  █ Storage: 120GB Kingston HyperX SSD + 1TB Seagate Barracuda HDD 


█ Monitor: 21.5" 1080p 60Hz  PSU: 700w █ Case: Fractal Define R4 █       ...LTT Dark Theme master race.


Project MiniConsole


Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1176244
Share on other sites

Link to post
Share on other sites

Well when you're basically stealing peoples' money, they do.

Which is why the scammers only accept prepaids like GreenDot, harder to trace than a CC.

CPU: i7-3930K @ 4.8GHz MOBO: IV Gene RAM: 16GB Crucial Ballistix Tactical Tracer 1866MHz GPU: GTX 780 Ti CASE: Corsair 350D STORAGE: 2 x Samsung 840 Pro 256 GB, 2x WD Red 4TB
PSU
: EVGA SuperNova 650W DISPLAY: 1 x ASUS VG248QE, 3 x Dell U2414H COOLING: Corsair H100i INPUT: Corsair Vengeance K70, SteelSeries Sensei AUDIO: Sennheiser HD 280 Pro, ATH-M50s, Beredynamic DT770 Pro, Steelseries H Wireless

Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1197376
Share on other sites

Link to post
Share on other sites

I watch some real kinky stuff and never get a virus, although my Antivirus does block some sites.

 

I use Avast! free.

 

I have to cure my needs somehow, and it is only natural.

 

By the way, dat a sexy virus ;)

Le Bastardo+ 

i7 4770k + OCUK Fathom HW labs Black Ice 240 rad + Mayhem's Gigachew orange + 16GB Avexir Core Orange 2133 + Gigachew GA-Z87X-OC + 2x Gigachew WF 780Ti SLi + SoundBlaster Z + 1TB Crucial M550 + 2TB Seagate Barracude 7200rpm + LG BDR/DVDR + Superflower Leadex 1KW Platinum + NZXT Switch 810 Gun Metal + Dell U2713H + Logitech G602 + Ducky DK-9008 Shine 3 MX Brown

Red Alert

FX 8320 AMD = Noctua NHU12P = 8GB Avexir Blitz 2000 = ASUS M5A99X EVO R2.0 = Sapphire Radeon R9 290 TRI-X = 1TB Hitachi Deskstar & 500GB Hitachi Deskstar = Samsung DVDR/CDR = SuperFlower Golden Green HX 550W 80 Plus Gold = Xigmatek Utguard = AOC 22" LED 1920x1080 = Logitech G110 = SteelSeries Sensei RAW
Link to comment
https://linustechtips.com/topic/86409-cypt-lock/page/2/#findComment-1197438
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×