The Forum > General Discussion > Beware of Cryptolocker
Beware of Cryptolocker
- Pages:
-
- Page 1
- 2
- 3
- 4
- 5
-
- All
Posted by sonofgloin, Saturday, 5 September 2015 11:51:06 AM
| |
I use a few programs that possible may have stopped this happening to you.
http://www.sandboxie.com/ you open you emails and browser in this program after you close it everything is gone (you can go to its folder and get out things you want to keep) This program has a few minor faults but for the average person it is better than antivirus alone. http://www.shadowdefender.com/ this one is a bit more specialized you activate it tell it what drives to protect when you restart your computer any changes made to the drives protected will revert back to how they were before you activated the program. still testing other one, what it does it you get a pop up message if something new wants to start you need to be a little computer savvy to know what to do, but if you were looking at an email and a program wanted to start up that would be suspect and you click no. Give the sites a read see what you think. Posted by Philip S, Saturday, 5 September 2015 1:31:47 PM
| |
Thanks Philip...........I will have a look at the sites you suggest.
Posted by sonofgloin, Saturday, 5 September 2015 5:03:11 PM
| |
Sonofgloin, that virus attacked our work computers this past week, causing chaos!
Luckily for me, our IT department warned me before I opened the bogus Australian post email. My colleagues lost much of their work after they opened the email. Posted by Suseonline, Saturday, 5 September 2015 6:27:45 PM
| |
Suse, I paid the ransom but was not granted access to their website for three days, I thought I had lost the money as well. But on the fourth day I could access the buggers web site and down loaded the decryption.
Posted by sonofgloin, Saturday, 5 September 2015 9:21:58 PM
| |
Don't assume it's all over - it's a pretty safe bet that they left a Trojan horse or two on your computer. You may perhaps not detect any problem again, but your friends and family could well later receive the same from your computer without your knowledge.
You should now save aside your recovered personal files, then re-format your disk and re-install an operating-system and all other executables before copying back your personal files. - and of course, there should be the death-penalty to the perpetrators, if ever caught, a painful death that is, so that nobody else would try this ever again. Posted by Yuyutsu, Sunday, 6 September 2015 6:58:51 AM
|
Cryptolocker is a virus that encrypts your files. It will encrypt all Microsoft files including jpegs. My business computer was hit this week. The virus came in on an Australia Post email which informed us that a parcel sent via Australia Post could not be delivered to the destination and that a holding fee was being charged on a daily basis until the posted item was retrieved.
It then invited you to click on a tab to retrieve the information required to claim the item and negate the holding fee. Once you clicked on the tab to get the number of the transaction the virus is downloaded. The virus immediately encrypted the files and none of them could be accessed. Then a ransom demand is inserted into all your files. The demand is blatant, they inform you that all your files are encrypted and they have the only decryption code and any attempt to decrypt would be useless. They also ask for payment within a time period or the ransom amount goes up, and finally they state that all your files will be destroyed if both time periods elapse.
Upon further investigation I found that the only way to retrieve the files is to pay the fee. I paid over $800 in Bitcoin to retrieve my files and true to the threat and reward I was allowed access to their site and downloaded the decryption file. All my files are back to normal and I will back up my files daily so I do not have to pay them again.
Be warned that the encryption virus is also transmitted via other recognised entities such as Telstra and Energy companies.............hope this saves you the grief.