Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Middle Tenn. sheriff pays ransom for files held hostage by malware
AP via Johnson City Press ^ | November 13, 2014

Posted on 11/13/2014 12:09:05 PM PST by don-o

DICKSON, Tenn. — The Dickson County Sheriff's Office in Middle Tennessee ended up paying a ransom after a malicious computer program blocked access to their files.

Detective Jeff McCliss told WTVF-TV that malware on a computer locked the agency's case files, which included autopsy reports, witness statements and crime scene photos. He says the malware, called "Cryptowall," doesn't tamper with files on a computer, but keeps them locked until a ransom is paid.

(Excerpt) Read more at johnsoncitypress.com ...


TOPICS: Crime/Corruption; News/Current Events
KEYWORDS: cryptolocker; donutwatch
Navigation: use the links below to view more comments.
first previous 1-2021-40 last
To: Moonman62

Is it simply automated copies of what they got on paper or independent media? I guess he could have it all re-scanned. Putting it on a computer that is hackable has just opened up a pandora’s box for all manner of evidence past and future. Cases could get tossed out. Lawyers are grinning.


21 posted on 11/13/2014 12:51:09 PM PST by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: don-o

This bastard crypto virus hit my computers Halloween night. Took out all my email. Looks like hieroglyphics. I just got everything back up, spent the last two weeks downloading my backup. Found a demand on my hard drive for $500 bitcoins before wiping the drives. They can pound sand before I pay. I will shut down my business and go on welfare before I would pay extortion. My emails that were scrambled are still gobblygook. I would like to be alone with whoever is responsible. I can’t even say what I really want to say. My daddy raised a good Christian girl.


22 posted on 11/13/2014 12:53:44 PM PST by Cats Pajamas (Wonder what Slick and Cankles did with the rent a dogs now they have grandbaby for optics?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ingtar

I don’t think you missed it. I was just being a smart a—.


23 posted on 11/13/2014 12:54:02 PM PST by billhilly (First eligible to vote in 1958)
[ Post Reply | Private Reply | To 19 | View Replies]

To: billhilly; Ingtar
I don’t think you missed it. I was just being a smart a—.

You?? Surely you jest!
24 posted on 11/13/2014 1:11:09 PM PST by SoConPubbie (Mitt and Obama: They're the same poison, just a different potency)
[ Post Reply | Private Reply | To 23 | View Replies]

To: AppyPappy

I betcha Barney Fife never backed-up his hard drive either.


25 posted on 11/13/2014 1:12:30 PM PST by Buckeye McFrog
[ Post Reply | Private Reply | To 5 | View Replies]

To: SoConPubbie

The election is over, and as far as I’m concerned, so are you.


26 posted on 11/13/2014 1:14:37 PM PST by billhilly (First eligible to vote in 1958)
[ Post Reply | Private Reply | To 24 | View Replies]

To: Mr. K

That’s what I use also.


27 posted on 11/13/2014 1:15:51 PM PST by Georgia Girl 2 (The only purpose o f a pistol is to fight your way back to the rifle you should never have dropped.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: rockrr

Think someone clicked something they shoundn`t have.

My understanding it copies the original then encrypts

it then deletes the original generates a key you must buy.


28 posted on 11/13/2014 1:30:25 PM PST by Harold Shea
[ Post Reply | Private Reply | To 9 | View Replies]

To: rockrr
"There should be a bounty on the heads of authors of cryptolocker and similar ransom-ware. A lamppost is too good for them."

Heads on a pike staff in front of the COMDEX, DEFCON, etc main venues.

29 posted on 11/13/2014 1:30:53 PM PST by BwanaNdege (Mother of Epidemics- "Gang Green and the Government Staff Infection" - G. Morgan, Freedom Foundation)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Harold Shea

Had that screen come up two weeks back!

Crap! I can install a new system in about 20 minutes with a quick link. Bound to lose some settings and recent work...

With dual monitors one for work and the other to waste time at FR. That may be a bad idea?

Closed all the programs took a look around ran a virus check everything AOK!

THANK YOU LINUS TORVALDS!!!


30 posted on 11/13/2014 2:07:38 PM PST by DUMBGRUNT (The best is the enemy of the good.)
[ Post Reply | Private Reply | To 28 | View Replies]

To: don-o
Must have been a Mac; I’m always reading about how there is a virus that will destroy the Apple universe.

They always tell us that Republicans are sleazy and Democrats are pure as the wind-driven snow, too . . .

31 posted on 11/13/2014 4:01:17 PM PST by conservatism_IS_compassion ("Liberalism” is a conspiracy against the public by wire-service journalism.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rockrr

NEVER OPEN Spy Sheriff! It does the same.

http://en.wikipedia.org/wiki/SpySheriff


32 posted on 11/13/2014 4:10:05 PM PST by Ruy Dias de Bivar (ISLAM, the religion of the criminally insane.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: don-o

This just happened to a fried of mine. He lost a whole bunch of stuff.

http://www.adlice.com/poweliks-removal-with-roguekiller/


33 posted on 11/13/2014 4:38:53 PM PST by rednesss (fascism is the union,marriage,merger or fusion of corporate economic power with governmental power)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Blood of Tyrants

In Nigeria.


34 posted on 11/13/2014 7:25:55 PM PST by UCANSEE2 (Lost my tagline on Flight MH370. Sorry for the inconvenience.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: don-o
never. have. an. important. file. on. only. one. spindle. /
35 posted on 11/13/2014 9:32:24 PM PST by cqnc (Don't Blame ME, I voted for the American!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ingtar
Ahh. Well, Macs are better. There had to be a much better way out of it if it was on a Mac. :)

Yep! It's called "Force Quit".

36 posted on 11/14/2014 6:09:49 PM PST by Drew68
[ Post Reply | Private Reply | To 19 | View Replies]

To: Cats Pajamas; Buckeye McFrog; Harold Shea; BwanaNdege; DUMBGRUNT; Ruy Dias de Bivar; don-o; ...

Please pardon the ping but I wanted to provide an update to my research on the Cryptolocker thread.

My brother caught the damned thing when trying to install “Dropbox” (he selected a malicious link for the download). Unfortunately he neglected to tell me that he was infected until the grace period had expired. I tried everything I knew (which wasn’t much) to get his files back - all with zero success.

So I replaced his hard drive and marked his old one with a red X and a bold “Cryptolocker!” and then set it on a shelf.

In revisiting the issue I came across some info that may be of interest. From Wackypedia:

“On 2 June 2014, the United States Department of Justice officially announced that over the previous weekend, Operation Tovar—a consortium constituting a group of law enforcement agencies (including the FBI and Interpol), security software vendors, and several universities, had disrupted the Gameover ZeuS botnet which had been used to distribute CryptoLocker and other malware. The Department of Justice also publicly issued an indictment against the Russian hacker Evgeniy Bogachev for his alleged involvement in the botnet.[5][13][14]

As part of the operation, the Dutch security firm Fox-IT was able to procure the database of private keys used by CryptoLocker; in August 2014, Fox-IT and fellow firm FireEye introduced an online service which allows infected users to retrieve their private key by uploading a sample file, and then receive a decryption tool.[15][16]”

I did a websearch for Fox-IT and found a free service for recovering files encrypted with the Cryptolocker virus: https://www.decryptcryptolocker.com/

I submitted a sample file from the infected hard drive and got a recovery key from Fox-IT and downloaded the Decryptolocker application (all on a salvage computer because I didn’t trust them either!). I then ran the key against the infected files and was able to recover about 80-90%!

If you know of someone who got hit by this thing and who still has files (didn’t delete or overwrite) I would encourage you to give it a try.


37 posted on 11/22/2014 9:40:30 AM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 22 | View Replies]

To: rockrr

Thanks! Sounds like good work you did and I added keyword


38 posted on 11/22/2014 10:59:23 AM PST by don-o (He will not share His glory and He will NOT be mocked! Blessed be the name of the Lord forever!)
[ Post Reply | Private Reply | To 37 | View Replies]

To: rockrr
WOW!

Thanks for posting!

GREAT PUBLIC SERVICE!

(Nope, I've had no problem with CryptoLocker)

Russian hacker Evgeniy Bogachev awaiting trial


39 posted on 11/22/2014 2:07:34 PM PST by BwanaNdege (I wonder which side they choose whe)
[ Post Reply | Private Reply | To 37 | View Replies]

To: rockrr

btt


40 posted on 11/23/2014 7:22:08 AM PST by don-o (He will not share His glory and He will NOT be mocked! Blessed be the name of the Lord forever!)
[ Post Reply | Private Reply | To 37 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-40 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson