Possible Cryptolocker?
Results 1 to 11 of 11

Thread: Possible Cryptolocker?

  1. #1
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952

    Possible Cryptolocker?

    Please view this file and tell me if you have seen it.
    I cleaned this windows 7 computer today with malwarebytes (122 items) yet
    it was still terribly boggy. I then cleaned using Combofix and this is what it deleted.
    Anyone seen this or know if it is possibly Cryptolocker?
    http://1drv.ms/1qqMpxF

  2. #2
    Registered User Zonie's Avatar
    Join Date
    Apr 2001
    Location
    Phoenix, Arizona
    Posts
    1,461
    Hi Ferrit. It looks like a good possibility as on the first line the NDde.dll file was also removed, which depending on what version this was, had a security hole issue for possible hack & or virus.

  3. #3
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    Yes and I am wondering if because they took down those servers just recently thats why it didnt activate>
    If so wow that was a close one.

  4. #4
    Registered User Zonie's Avatar
    Join Date
    Apr 2001
    Location
    Phoenix, Arizona
    Posts
    1,461
    I hear you. Unfortunately I wasn't that lucky about a month ago with one of my clients. They got hit with it and I had to wipe out their system and start over. Good thing they listened to me and had a backup.

  5. #5
    Registered User
    Join Date
    Mar 2005
    Posts
    1,534
    Is malewarebytes and combofix effective against cryptolocker? I had not even seen it until a week ago. All I have read about it was not much of anything was effective.

  6. #6
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    Nothing is effective against cryptolocker except a full clean backup or to pay them to get the data back.

  7. #7

  8. #8
    Registered User
    Join Date
    Mar 2005
    Posts
    1,534
    Quote Originally Posted by Ferrit View Post
    Nothing is effective against cryptolocker except a full clean backup or to pay them to get the data back.
    I didn't think so and once the data is encrypted there screwed. If the data is recovered before are you ok or is the data infected?

  9. #9
    Super Moderator SpywareDr's Avatar
    Join Date
    Jul 2012
    Location
    Maryland, USA
    Posts
    385
    It's just encrypted.

  10. #10
    Registered User Zonie's Avatar
    Join Date
    Apr 2001
    Location
    Phoenix, Arizona
    Posts
    1,461
    Quote Originally Posted by Kodiak View Post
    I didn't think so and once the data is encrypted there screwed. If the data is recovered before are you ok or is the data infected?
    If you are talking like a backup, the data should be fine. If you are talking about trying to recover after the cryptolocker has been installed, there will be no recovery.

  11. #11
    Super Moderator SpywareDr's Avatar
    Join Date
    Jul 2012
    Location
    Maryland, USA
    Posts
    385
    Correct. Cryptolocker can be removed but, the files that it had encrypted then cannot be unencrypted. The only way to do that is to pay the $300 in order to get the unencryption code.

    Solution: How to prevent your computer from becoming infected by CryptoLocker

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •