I think that I may have crypt locker

Onceler

Golden Member
Feb 28, 2008
1,264
0
71
up popped up on my screen that if I don't pay thousands of dollars and that I have thirty days to pay or my files will be deleted.
Anyone know whats going on and if it is possible to recover without paying. Hoe can I tell if I am infected or not. As far as I can tell the d: drive files are playing just fine. I don't know about any of the others.
Thank you.
 
Last edited:

Onceler

Golden Member
Feb 28, 2008
1,264
0
71
I just thought about it and if my files were encryted I would not be able to open and play them. Am I right in assuming this?
 

Iron Woode

Elite Member
Super Moderator
Oct 10, 1999
30,938
12,440
136
Jump on and download, install, and run Combofix!!!

http://www.bleepingcomputer.com/download/combofix/

Heavily infected systems can take several hours for Combofix to delete everything. It may seem as though nothing is going on, but leave it running until it finishes. I had one system that took almost 24 hours.
or he may have to boot off a liveCD of either Ultimate Boot Disc or Hiren's Boot Disc or even a Kapersky Rescue Disc (http://support.kaspersky.com/4162).
 

code65536

Golden Member
Mar 7, 2006
1,006
0
76
Jump on and download, install, and run Combofix!!!

http://www.bleepingcomputer.com/download/combofix/

Heavily infected systems can take several hours for Combofix to delete everything. It may seem as though nothing is going on, but leave it running until it finishes. I had one system that took almost 24 hours.

If he really does have CryptoLocker, then forcibly removing it would mean that he can no longer pay the ransom and would also mean that he loses all of the data that had been encrypted.

On the other hand, if this is a cheap scareware program that's trying to get him to cough up money by pretending to by CryptoLocker, then, yea, kill it with fire.

Note the CL only encrypts certain kinds of files. Mostly stuff used in office settings, like word processor documents, PDFs, spreadsheets, etc. Small, high-value irreplaceable stuff that it can get to quickly; it won't bother with large files that you can easily re-download, like, say, your porno collection. So check those your Word docs if you're trying to determine if you've really been it.
 
Last edited:

G73S

Senior member
Mar 14, 2012
635
0
0
how did you get it in the first place? are you one of those people who run without an AV thinking your common sense knows better? (no offense)
 

code65536

Golden Member
Mar 7, 2006
1,006
0
76
how did you get it in the first place? are you one of those people who run without an AV thinking your common sense knows better? (no offense)

Did you miss all the stories about Crypto Locker hitting victims who naïvely thought they were protected by AV? This one, for example.

Hint: Search for "fud crypter" and maybe you'll finally understand why AV is largely ineffective as a primary defense and why it's little more than money-grabbing security theater.
 
Last edited:

G73S

Senior member
Mar 14, 2012
635
0
0
Did you miss all the stories about Crypto Locker hitting victims who naïvely thought they were protected by AV? This one, for example.

Hint: Search for "fud crypter" and maybe you'll finally understand why AV is largely ineffective as a primary defense and why it's little more than money-grabbing security theater.

wow, thanks a lot for that link, very informative and made me change my opinion of having an AV is not 100% secure against such new threats.
 

Onceler

Golden Member
Feb 28, 2008
1,264
0
71
I don't know how I got it, I do run AV but somehow this got through.
I don't have it anymore.
 

nk215

Senior member
Dec 4, 2008
403
2
81
best way to protect yourself is to browse the web inside a Linux virtual machine. Zorin is looks just like WinXP and run fast under VMware environment.
 

Kaido

Elite Member & Kitchen Overlord
Feb 14, 2004
48,518
5,340
136
I've seen full-page ads on client machines twice this week pretending to be the Cryptolocker Moneypak virus - it bounces between tabs so you can't close it without killing the browser exe or rebooting. Pretty slick coding, but very annoying & scares you into thinking you got the crypto.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |