MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 1:22 
Offline

Joined: August 8th, 2007, 6:32
Posts: 1238
Location: inside ROM
I have a client which has CryptoLocker Malware infected to all his office files, any known solutions to decrypt the encrypted files?


Top
 Profile  
 
 Post subject: Re: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 5:10 
Offline

Joined: November 9th, 2006, 15:15
Posts: 2984
That thread is not really useful. The short answer is there is no known solution for the more recent variants of this cryptolock, at least none that I am aware of. Each inidividual file on newer variants are encrypted with a new key, some variants claim to encrypt with 2048 bit encryption. Some of the older variants can be done, but if its a modern version Im not sure it can be done.


Top
 Profile  
 
 Post subject: Re: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 6:34 
Offline

Joined: November 6th, 2006, 6:58
Posts: 1752
Hi,

If it's the newer version (and I think so, as nowadays only new version is around), there's no chances without paying the ransom, because it's using asymetric crypto, and the private key is on the hacker server and without it no goal.


Top
 Profile  
 
 Post subject: Re: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 13:09 
Offline

Joined: December 5th, 2013, 22:50
Posts: 5
Location: Europe
If you are lucky, the files didn't get erased properly -> try undelete/file carving.


Top
 Profile  
 
 Post subject: Re: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 14:32 
Offline

Joined: September 22nd, 2013, 23:14
Posts: 23
Location: United States
If your computer has shadow copy enabled, you may have backup versions of the files which were not encrypted
http://www.shadowexplorer.com


Top
 Profile  
 
 Post subject: Re: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 14:56 
Offline

Joined: July 2nd, 2011, 14:16
Posts: 463
Location: England
I think the program will overwrite the sector that was in use by the file, that would be the way I would make that program work, not just create a new file and then delete the old one. Overwriting the content will make it impossible to recover. I've look up on this program, very nasty and makes me cringe whats around the corner.

At least that porn collection will vanish if you are in a pinch. Perhaps that would be a good evadance hiding tool if you are up to no good to run quickly when the FBI are on your doorstep.

I feer this is a deadly program that once open, you are royally screwed (Like Pandora's Box) unless you have a offline USB backup.


Top
 Profile  
 
 Post subject: Re: Infected with CryptoLocker Malware
PostPosted: December 9th, 2013, 20:59 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3903
Location: Adelaide, Australia
newer versions also search for networked drives and online storage. Ive heard from bob that more people are trying to find these guys and have a little chat than they are to prosecute them. I hope their OpSec is 100%, for their sake.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 165 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group