Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Semi-VANITY : Prevention of New Virus sweeping the Interwebs: CryptoLocker
bleepingcomputer.com ^ | Oct 25, 2013 | Bleeping Computer

Posted on 10/26/2013 1:29:26 PM PDT by NoLibZone

Heads up and Prevention of New New Virus sweeping the Interwebs: CryptoLocker

http://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information

PROBLEM:

CryptoLocker is a ransomware program that was released around the beginning of September 2013. This ransomware will encrypt certain files using a mixture of RSA & AES encryption. When it has finished encrypting your files, it will display a CryptoLocker payment program that prompts you to send a ransom of either $100 or $300 in order to decrypt the files. This screen will also display a timer stating that you have 96 hours, or 4 days, to pay the ransom or it will delete your encryption key and you will not have any way to decrypt your files. This ransom must be paid using MoneyPak vouchers or Bitcoins. Once you send the payment and it is verified, the program will decrypt the files that it encrypted.

One Easy Solution:

The easy to use free tool to change group polices to block your Hard Drive from unauthorized encryption: http://www.foolishit.com/vb6-projects/cryptoprevent/

First I scanned the CryptoPrevent using VirusTotal.com to make certain it’s clean. It is.

Then I used MalwareBytes to make sure I an clean.
Then I ran a new restore point.
Then I ran the one click CryptoPrevent and tested. It worked.

Image of the little app dialogue:
http://imgur.com/5M9bDyU">

(Excerpt) Read more at bleepingcomputer.com ...


TOPICS:
KEYWORDS: cryptolocker; malware; ransomware; virus
Navigation: use the links below to view more comments.
first 1-2021-40 next last

1 posted on 10/26/2013 1:29:26 PM PDT by NoLibZone
[ Post Reply | Private Reply | View Replies]

To: NoLibZone
prompts you to send a ransom of either $100 or $300 in order to decrypt the files.
Extortion. Why not call the cops or local FBI?

www.foolishit.com
Surely you jest.
2 posted on 10/26/2013 1:37:14 PM PDT by oh8eleven (RVN '67-'68)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoLibZone

Everything I care about is backed up in a second file on my hard drive, on two thumb drives that alternate from week to week, and if it’s not too sensitive in two email addresses. In no case would I pay extortion money to terrorists, unless the FBI asked me to do so to track and prosecute them (or to put a drone missile where it would do the most good - drone strike for cyber-theft? Yep!).


3 posted on 10/26/2013 1:41:35 PM PDT by Pollster1 ("Shall not be infringed" is unambiguous.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoLibZone

Sounds like Obamacare.


4 posted on 10/26/2013 1:41:38 PM PDT by HereInTheHeartland (Under the Democrats; the Lincoln Memorial is closed; but the southern border is open)
[ Post Reply | Private Reply | To 1 | View Replies]

To: oh8eleven
Why not call the cops or local FBI?

Because they probably don't have free time to go to Latvia or Russia or Turkey or Brazil or South Korea or wherever else the hackers may be hanging out at. And even if they did, it would almost certainly take longer for the Federal Geek Squad to track down the hackers than it would for the encrypted files to get automatically deleted from your computer.

5 posted on 10/26/2013 1:46:22 PM PDT by vbmoneyspender
[ Post Reply | Private Reply | To 2 | View Replies]

To: NoLibZone

A quick Google of “cryptolocker” seems to finger cryptolocker as malware too. How does CryptoLocker have any cred as one of the good guys? Just curious ...


6 posted on 10/26/2013 1:52:54 PM PDT by Springfield Reformer (Winston Churchill: No Peace Till Victory!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Springfield Reformer

sorry my bad, misread & mixed up cryptolocker & cryptoprevent. Argh! Hate when that happens ..


7 posted on 10/26/2013 1:55:03 PM PDT by Springfield Reformer (Winston Churchill: No Peace Till Victory!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: oh8eleven

I can’t rely on the Fed or local Unions to protect me.

The better best is prevention.

Whihc is easy.


8 posted on 10/26/2013 1:55:32 PM PDT by NoLibZone (The reason we are where we are today is the belief that posting on a website will fix the nation.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: NoLibZone

I certainly hope there are a ton of people working on this problem. I also hope they find the people doing this and throw them in prison.


9 posted on 10/26/2013 1:59:50 PM PDT by GeronL
[ Post Reply | Private Reply | To 1 | View Replies]

To: oh8eleven

I don’t really want to type that URL

lol


10 posted on 10/26/2013 2:00:55 PM PDT by GeronL
[ Post Reply | Private Reply | To 2 | View Replies]

To: NoLibZone

The easiest way to prevent this is to do all of your internet surfing from a virtual PC. I’ve been doing this for about 4 years. Any time the Virtual system acts up. I shut it off, erase it and clone in a new untouched virtual system and continue. It takes 10 minutes to clone the backup OS and start over.


11 posted on 10/26/2013 2:01:03 PM PDT by BuffaloJack (Gun Control is the Key to totalitarianism and genocide.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoLibZone
The only way to know that the CryptoPrevent program is safe is look at the code, or have someone else competent review the code. Scanners mostly only look for known malicious code. When you run a program on your computer (a Windows computer) you are essentially giving it access to everything on your machine.
12 posted on 10/26/2013 2:01:06 PM PDT by DB
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoLibZone

does this thing affect Linux?


13 posted on 10/26/2013 2:02:19 PM PDT by GeronL
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoLibZone; All

Run as a limited user, set UAC to high, don’t mindlessly click links in email, don’t open attachments and think before clicking on a file that has one of the following attachments:
BAT Batch File
BIN Binary Executable
CMD Command Script
COM Command File
CPL Control Panel
Extension
EXE Executable Windows
INF Setup Information
File
INS Internet
Communication
Settings
INX InstallShield
Compiled Script
ISU InstallShield
Uninstaller Script
JOB Windows Task
Scheduler Job File
JSE JScript Encoded File
MSC Microsoft Common
Console Document
MSI Windows Installer
Package
MSP Windows Installer
Patch
MST Windows Installer
Setup Transform File
PAF Portable Application
Installer File
PIF Program Information
File
PS1 Windows PowerShell
Cmdlet
REG Registry Data File
RGS Registry Script
SCT Windows Scriptlet
SHB Windows Document
Shortcut
SHS Shell Scrap Object
U3P U3 Smart Application
VB VBScript File
VBE VBScript Encoded
Script
VBS VBScript File Windows
VBSCRIPT Visual Basic Script
WS Windows Script
WSF Windows Script


14 posted on 10/26/2013 2:03:04 PM PDT by pluvmantelo (The issue isn't the issue-power is the issue.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: oh8eleven

bfl


15 posted on 10/26/2013 2:04:05 PM PDT by Oshkalaboomboom
[ Post Reply | Private Reply | To 2 | View Replies]

To: NoLibZone

Malware bytes

Spybot

Fprot

No problemo


16 posted on 10/26/2013 2:06:15 PM PDT by Vendome (Don't take life so seriously-you won't live through it anyway-Enjoy Yourself ala Louis Prima)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoLibZone

http://www.snopes.com/computer/virus/cryptolocker.asp


17 posted on 10/26/2013 2:09:17 PM PDT by maine-iac7 (Christian is as Christian does - by their fruits)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BuffaloJack

It also crypts attached drives.


18 posted on 10/26/2013 2:09:38 PM PDT by AppyPappy (Obama: What did I not know and when did I not know it?)
[ Post Reply | Private Reply | To 11 | View Replies]

To: BuffaloJack

What are you using? I’ve used VMware, but started using Virtualbox on a computer that wouldn’t run VMware. I’m liking Virtualbox a lot better as I use it more.


19 posted on 10/26/2013 2:18:36 PM PDT by Slump Tester (What if I'm pregnant Teddy? Errr-ahh -Calm down Mary Jo, we'll cross that bridge when we come to it)
[ Post Reply | Private Reply | To 11 | View Replies]

To: NoLibZone

“prompts you to send a ransom of either $100 or $300”

so it’s the obamacare of viruses?


20 posted on 10/26/2013 2:22:18 PM PDT by max americana (fired liberals in our company last election, and I laughed while they cried (true story))
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-40 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson