• A Great friend to the HardForum with a great kid that he is trying to get a scholorship to continue his schooling. Please give hime a vote! Only 24 hours left! Thanks.
    If you have an VOTE FOR KEENAN!

Ransomware

Starguard

Limp Gawd
Joined
Jul 28, 2003
Messages
332
Has anyone here ever been infected with this before? If so, how did you remove it.
 
If it didn't encrypt the drive, it's likely running from a location under c:\Program Data\ or c:\users\username\AppData\Local\Temp

Boot to a USB key or some kind of recovery environment, navigate to those locations and delete the offending executable, boot the computer, see if the ransomware shows up, if not, use something like Malwarebytes to clean up the rest.
 
More than a year ago my computer was infected by this kind of virus. Luckily I had a recently backup drive which I used to restore my files. Had to wipe out both my drives to fully get rid of the virus and reinstall Windows. Not ever paying these fuckers a cent just to restore my files, doing that will only encourage them to develop more malware like this.
 
There used to be a workaround using shadow copies of important data, but I believe the latest incarnation of the Cryptolocker Malware has taken care of that loophole.

Pay the fuckers or rely on your backups that you hopefully didn't have connected to your Windows PC at the time.

Hence the reason why I run Linux, they tried to make a Cryptolocker, but it was a massive fail.
 
Removing the virus is typically simple, it's the encryption that's the issue. Rather than worry about how to remove it, you should be figuring out how to reduce the chance of getting it.
 
Removing the virus is typically simple, it's the encryption that's the issue. Rather than worry about how to remove it, you should be figuring out how to reduce the chance of getting it.
Precisely! Removing the malware will actually complicate matters if you end up wanting to pay the criminals to decrypt because you would have to find the variant of the virus, reinfect and make sure the versioning and encryption "database" is in the registry. This was possible with 2013/14's Cryptolocker but the new prominent scourge is Cryptowall and there is no telling whether it will encrypt the files already encrypted by the initial infection.
 
Windows is ransomware. You install it, then it nags for activation and porks itself if you don't do it :D
 
An acquaintance of mine got hit with it 2 years ago. It pretended it was teh police taking your stuff downtown.

The guy didn't shutdown his machine right away, so the malware had plenty of time to encrypt his documents. I was unable to crack it despite my best efforts.
It even wipes free space, so something as trivial as using Recuva might not work. As was mentioned, shadow copy folders were a way out if you got to them quick enough from a known good system.

I advised him to chalk it up as a lesson learned and not contact the dude. He's military so his pride took the better of him and he did not attempt contact.

Two kinds of people in the world - those who make regular offsite backups and those who will.

edit: brute forcing got me as far as decrypting a few parts of a few files but it was like 0.5%.
 
An acquaintance of mine got hit with it 2 years ago. It pretended it was teh police taking your stuff downtown.

The guy didn't shutdown his machine right away, so the malware had plenty of time to encrypt his documents. I was unable to crack it despite my best efforts.
It even wipes free space, so something as trivial as using Recuva might not work. As was mentioned, shadow copy folders were a way out if you got to them quick enough from a known good system.

I advised him to chalk it up as a lesson learned and not contact the dude. He's military so his pride took the better of him and he did not attempt contact.

Two kinds of people in the world - those who make regular offsite backups and those who will.

edit: brute forcing got me as far as decrypting a few parts of a few files but it was like 0.5%.

I bet your friend takes backups of his stuff nowadays... :)
 
I bet your friend takes backups of his stuff nowadays... :)

Yeah, he began randomly dumping relevant stuff to a thumbdrive. Sometimes.

But that was XP time, so that backfired when autorun.inf viruses became the new black.

So I told him to create more backups in more places :D
 
I had a popup that hijacked my browser and said to send them money to decrypt my HDD. I run with a limited user account and it didn't actually do anything except making me use task manager to force close Firefox. But I did install the free version of this after it happened.

CryptoPrevent Malware Prevention
 
Back
Top