Forum Home
Press F1
 
Thread ID: 135105 2013-09-25 08:54:00 A heads up about this ransomware called cryptolocker aka Trojan:Win32/Crilock.A. Speedy Gonzales (78) Press F1
Post ID Timestamp Content User
1354355 2013-09-25 08:54:00 Looks like this is starting to do the rounds. (blog.emsisoft.com)It's a nasty piece of work. It's similar to the other ransomware that's been around, but this includes RSA 256 bit AES, that encrypts everything by the looks of it including files on servers. It may also spread to shared drives / folders.

And unless you pay $100-300 to decrypt the files, or unless you've got backups, you maybe SOL in getting any of the files back.

Altho one of the guys at Emsisoft has made some kind of decryption program (as he says on Neowin - I verified that all sample files that people sent me are decrypted correctly). See post 25 and 29 here on Neowin for the links / usage (www.neowin.net)

The mods may want to sticky this. It may help people or their mates / customers if they get it. It looks like you can get it as an attachment in email too
Speedy Gonzales (78)
1354356 2013-09-25 10:48:00 Thanks, Speedy. Like the world needs another even worse one. linw (53)
1354357 2013-09-25 10:55:00 No probs yer it looks like it does a lot more damage, than the previous ransomware Speedy Gonzales (78)
1354358 2013-09-25 11:06:00 No Doubt we will find out soon enough. kb.eset.com wainuitech (129)
1354359 2013-09-25 12:43:00 Better back up folks. Hope they can't find my system images on my NAS!! linw (53)
1354360 2013-09-25 23:07:00 Microsoft security software detects and removes this threat. Pancake (6359)
1354361 2013-09-25 23:13:00 How might this effect the likes of Skype, is that is considered remote access ? curly (6655)
1354362 2013-09-25 23:34:00 How might this effect the likes of Skype, is that is considered remote access ?

No its not.
Pancake (6359)
1354363 2013-09-25 23:51:00 Another good reason to switch to Linux Agent_24 (57)
1354364 2013-09-26 00:20:00 dont use rdp or restrict use to certain users and check Rdp security and tightern it up, fixed. Read wainuitech link that tell you more beama (111)
1 2