Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Crypto Locker Virus Takes Over Windows PCs With 'Ransomware'
The Inquisitor ^ | 27 October 2013 | James Kosur

Posted on 10/27/2013 10:48:13 AM PDT by Windflier

The Crypto Locker virus is a new piece of “ransomware” that is said to be one of the worst viruses to ever infect Windows PCs. The virus takes over a computers files, encrypts them, and then holds the files ransom until a user pays to have them freed by clearing out the virus.

The Crypto Locker virus is sent to users through emails that have innocent enough looking senders, such as UPS or FedEx. Once the file is installed a display pops up demanding upwards of $100 to restore a users important files. In same cases users have stated that Crypto Locker has demanded two to four bitcoins, or the equivalent of approximately $700 to $800.

Technology expert Anthony Mongeluzo tells Mountain News:

“Ransomware causes your computer files to be non-accessible and when that happens you have two choices. You can recover if you have a backup which I hope you do or pay the ransom within 100 hours. If you do not pay the ransom you lose all of your data.”

The program disguises itself as a JPEG, PDF, or other Microsoft Office file.

To recover files users are given a strict time-frame of 100 hours. Users who have actually paid the fee have reported receiving their files back in a 3-4 hour time period. Crypto Locker after payment is made states that all files will be returned after payment is verified. Regular credit cards (which are subject to chargebacks) can not be used. If you don’t have Bitcoins you can purchase a Green Dot MoneyPak to make the purchase.

Windows PC users are being encouraged to back up all of their important files at all times. Once infected brute force hacking your files back is not really something to be considered as the files are RSA-encrypted with strong backup technology.

If you want to prevent Crypto Locker from being installed there is a handy tool by FoolishIT LLC that creates software restriction policies on your Windows PC. The tool is free, easy to install and a necessity for users with thousands of files to protect.


TOPICS:
KEYWORDS: computers; cryptolocker; virus
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-73 next last
To: Windflier

That thread also has instructions for a Windows setting that will stop it outright, and a few other things. That’s where all my other solutions came from.


41 posted on 10/27/2013 11:41:51 AM PDT by discostu (This is Jack Burton in the Pork Chop Express, and I'm talkin' to whoever's listenin' out there.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: Venturer
You send them money, how hard could it be for the FBI with all its, super powers to find where the money goes and bust this bunch?

Protecting the American people isn't part of Emperor Obama's mission directives to his spy agencies.

Now get back to work, prole. Someone's got to feed the 47%.

42 posted on 10/27/2013 11:42:20 AM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 34 | View Replies]

To: ZULU
These people should be skinned alive

Slowly. In public. Tied over fire ant mounds.

43 posted on 10/27/2013 11:43:33 AM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 36 | View Replies]

To: Moltke
the ‘hide file extension’ function is one of the easiest to undo.

Are the instructions to do that something you can quickly type out for those of us who don't know how?

44 posted on 10/27/2013 11:46:46 AM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Windflier

You should already be backing up your important files especially your digital photos anyway. External hard drives are cheap and there are cloud storage sites that will provide a limited amount of storage for free. To be really safe I back up my photo files on flash drives and store them in my bank safety deposit box.


45 posted on 10/27/2013 11:48:14 AM PDT by The Great RJ
[ Post Reply | Private Reply | To 1 | View Replies]

To: Windflier

I’m bookmarking this. I’m not that computer savvy but this sounds like something that should be done.


46 posted on 10/27/2013 11:51:11 AM PDT by Lurkina.n.Learnin (If global warming exists I hope it is strong enough to reverse the Big Government snowball)
[ Post Reply | Private Reply | To 44 | View Replies]

To: The Great RJ
You should already be backing up your important files especially your digital photos anyway.

That's true, but life is messy, and not everyone backs up their files when they should. Criminals, such as those who launched this menace, are exploiting that human shortcoming.

They ought to be hung by the neck til dead for committing this crime.

47 posted on 10/27/2013 11:54:49 AM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 45 | View Replies]

To: Lurkina.n.Learnin

Glad I could help, friend. That’s the whole idea of this thread.


48 posted on 10/27/2013 11:56:31 AM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 46 | View Replies]

To: Windflier
The CryptoLocker virus is being called one of the worst computing threats ever seen...

There's this from Malwarebytes...

Cryptolocker Ransomware: What You Need To Know

49 posted on 10/27/2013 11:57:18 AM PDT by NoCmpromiz (John 14:6 is a non-pluralistic comment.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Windflier; Moltke
Are the instructions to do that something you can quickly type out for those of us who don't know how?

A pet peeve of mine - *No* windows box leaves my bench with extensions hidden, ever.

WinXP-Win7 (32/64bit)
Control Panel => Folder Options [Tab='View'] - Remove the check from 'Hide extensions for known file types'. Apply/OK.

50 posted on 10/27/2013 12:01:29 PM PDT by roamer_1 (Globalism is just socialism in a business suit.)
[ Post Reply | Private Reply | To 44 | View Replies]

To: Windflier

Any operating system that is so full of holes that this can happen, is nothing but junk.


51 posted on 10/27/2013 12:04:13 PM PDT by I want the USA back (Media: completely irresponsible traitors. Complicit in the destruction of our country.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Windflier

Malwarebytes just picked up 3 files which got past Kaspersky.


52 posted on 10/27/2013 12:07:05 PM PDT by Zathras
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoCmpromiz
There's this from Malwarebytes... Cryptolocker Ransomware: What You Need To Know

Thanks for the link, NC.

Per the article, only paid users of Malwarebytes Pro versions have protection against their computers being infected by this virus. Free users have no protection, and will lose their files (or be forced to pay the ransom) if they're infected.

Here's an interesting tidbit about infection vectors from a link in the article:

CryptoLocker currently has the following infection vectors:

1. This infection was originally spread sent to company email addresses that pretend to be customer support related issues from Fedex, UPS, DHS, etc. These emails would contain an attachment that when opened would infect the computer.

2. Currently dropped by Zbot infections disguised as PDF attachments

3. Via exploit kits located on hacked web sites that exploit vulnerabilities on your computer to install the infection.

4. Through Trojans that pretend to be programs required to view online videos. These are typically encountered through Porn sites.

So this thing isn't just being spread through email attachments. That makes the threat level a lot higher.

53 posted on 10/27/2013 12:11:02 PM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 49 | View Replies]

To: roamer_1

Thanks much, Roamer. I’m going to make that change right away.


54 posted on 10/27/2013 12:12:17 PM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 50 | View Replies]

To: I want the USA back
Any operating system that is so full of holes that this can happen, is nothing but junk.

No point in barking at reality, friend. We live in an imperfect world.

55 posted on 10/27/2013 12:13:34 PM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 51 | View Replies]

To: Windflier
And this from bleepingcomputer.com...

CryptoLocker Ransomware Information Guide and FAQ

56 posted on 10/27/2013 12:13:45 PM PDT by NoCmpromiz (John 14:6 is a non-pluralistic comment.)
[ Post Reply | Private Reply | To 49 | View Replies]

To: Zathras
Malwarebytes just picked up 3 files which got past Kaspersky.

It's structured differently than virus protection programs, and regularly picks up things that anti-virus programs miss. I use the free version and run it at least once a week.

57 posted on 10/27/2013 12:15:17 PM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 52 | View Replies]

To: All
How to block this infection from running on other computers on your computer.

You can use Software Restriction Policies to block executables from running when they are located in the %AppData% folder, or any other folder, which this thing launches from. See these articles from MS:

http://support.microsoft.com/kb/310791
http://technet.microsoft.com/en-us/library/cc786941(v=ws.10).aspx

This can also be set up in group policy.

File paths of the infection are:

C:\Users\User\AppData\Roaming\{213D7F33-4942-1C20-3D56=8-1A0B31CDFFF3}.exe (Vista/7/8)

C:\Documents and Settings\User\Application Data\{213D7F33-4942-1C20-3D56=8-1A0B31CDFFF3}.exe

Please see further instructions at this link to manually protect your computer from the CryptoLocker virus.

58 posted on 10/27/2013 12:27:46 PM PDT by Windflier (To anger a conservative, tell him a lie. To anger a liberal, tell him the truth.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Windflier; I want the USA back
Any operating system that is so full of holes ... is nothing but junk.
No point in barking at reality... We live in an imperfect world.

And this is why you should make sure whatever opsys you use is locked up tighter than the NSA files. You can bark at Windoze all you want but keep in mind that the beloved MACos and the penguin are also subject to attack.

NO operating system is bullet proof. Security is the users' responsibility. What I run may not be everyone's cup of tea so your mileage may vary but for starters Firefox with NoScript. At least with that combo if something executes from a web link, you OK'd it...

There are other options to lock down (originally typed 'lock-up' but windoze manages that quite well on its own..;-) your machine including some in the link in post #56.

Your choice as to whether you want to do that or just complain about the holes...

59 posted on 10/27/2013 12:27:54 PM PDT by NoCmpromiz (John 14:6 is a non-pluralistic comment.)
[ Post Reply | Private Reply | To 55 | View Replies]

To: I want the USA back
Any operating system that is so full of holes that this can happen, is nothing but junk.

I've been calling the use of MS-Windows in the business sphere criminal fiduciary negligence for years. The lost productivity guaranteed by use of microsoft software is staggering.

60 posted on 10/27/2013 12:45:47 PM PDT by zeugma (Is it evil of me to teach my bird to say "here kitty, kitty"?)
[ Post Reply | Private Reply | To 51 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-73 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson