Cryptolocker Decryption website open

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,225
This is too cool for words (but I'll try anyway); As many here know, one malware strain that has caused particular problems lately has been Crptolocker. The malware will encrypt various filetypes while connecting to a Server where a decryption key will be generated and stored. Once the malware has finished doing what it does a screen like this will be presented to the user:

cryptolocker.png


An issue for the hard working malware author has been the very success of Cryptolocker. Most AV firms have been bery good at pushing out definitions to remove all traces of the malware, while sadly still leaving all the files still encrypted. The removal process will also zap the screen presented above, so now the user will not know where to go to buy the unlock key, and the poor starving criminal won't get paid.

The remedy is obvious- start a website where the infected can go any buy the decryption key online! The specifics of this have just been published here:

http://thehackernews.com/2013/11/CryptoLocker-Ransomware-Decryption-service-malware-keys.html

Please note that when the decrypt codes were first sold the price was 1 bitcoin and was recently doubled to 2 BC. Now however, to defray the cost of setting up the website (located in Central Russia) the price of the key has been upped to 10 BC (current exchange rate of 1 BC = 222 USD).

One last thing- Cryptolocker-blocking tools have been published. One from BitDefender can be found here:

http://labs.bitdefender.com/2013/10/cryptolocker-ransomware-makes-a-bitcoin-wallet-per-victim/

and another good one, CryptoPrevent, can be found here:

http://www.foolishit.com/vb6-projects/cryptoprevent/

(I personally haven't checked to see if these tools will work against the latest variants)
 

rebel4life

Level 9
Verified
Sep 30, 2012
667
or you can use EAM 7.0 and Online armor 7.0 both can prevent and remove cryptolocker
 

kevinssi

Level 1
Sep 23, 2013
9
free remove tool from sophos
http://www.sophos.com/en-us/products/free-tools/virus-removal-tool.aspx
 

Littlebits

Retired Staff
May 3, 2011
3,893
The main problem with Cryptolocker if it gets widespread and popular, new variants will be distributed so fast that no detection will be able to detect or remove all variants of it in a given time.

Your main concern should will be not removing or detecting it but avoiding it altogether. You can start by downloading nothing from the web except from trusted download sites that scan all hosted files.

Keep UAC on defaults and never approve anything that you do know for sure is safe. Never open or runs files, always save files to location and then scan with your AV and scan with VirusTotal (several uploading options are available).

As far as I know only a few variants have been found in the wild but this could get much worse. It will have to run its course just like all malware does, if you watch your actions and don't ignorantly click you can limit the possibilities to getting exposed to it.

Thanks. :D
 

Detection

Level 1
Feb 25, 2011
247
If I ended up infected with Crypto, I would mess about for 10 minutes trying to unlock my files, if I failed I would laugh and hit 8.1 refresh, if that failed, reinstall windows

Moral of the story, anything you can not bear to lose, backup online, or offline away from anything that could encrypt or delete it

Losing my files would only be a PITA, it would not be mission critical, I can download everything again if it came to that
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,225
Superb point, Littlebits! With much malware, both the vector and payload are written initially with verbose code, so just by noping out a bit will give the file a different identifier thus with a few sends work one will basically transform the same old thing to a fresh Zero day sample day after day. Some form of second line defense, either a BB or sandbox is essential.
 

Moose

Level 22
Jun 14, 2011
2,271
Cryptolocker-blocking tools have been published

http://labs.bitdefender.com/2013/10/cryp...er-victim/

Is not working a 100% I try enable BitDefender Cryptolocker-Blocking tool.
It said that it is Disable? For use on my parent's in which has Windows XP.
 

Littlebits

Retired Staff
May 3, 2011
3,893
Moose said:
Cryptolocker-blocking tools have been published

http://labs.bitdefender.com/2013/10/cryp...er-victim/

Is not working a 100% I try enable BitDefender Cryptolocker-Blocking tool.
It said that it is Disable? For use on my parent's in which has Windows XP.

Not Found

Apologies, but the page you requested could not be found. Perhaps searching will help.

Thanks. :D
 

MrXidus

Super Moderator (Leave of absence)
Apr 17, 2011
2,503
Littlebits

http://labs.bitdefender.com/2013/10/cryptolocker-ransomware-makes-a-bitcoin-wallet-per-victim/
 

Paul.R

Level 17
Verified
Well-known
May 16, 2013
844
Hi!

http://download.bitdefender.com/removal_tools/BDAntiCryptoLocker_Release.exe
 

Littlebits

Retired Staff
May 3, 2011
3,893
MrXidus said:
Littlebits

http://labs.bitdefender.com/2013/10/cryptolocker-ransomware-makes-a-bitcoin-wallet-per-victim/

Thanks, I wonder will this product also block safe encryption programs like AxCrypt, BitLocker, Wise Hidden Folder and My Lockbox?

Enjoy!! :D
 

Moose

Level 22
Jun 14, 2011
2,271
BitDefender Crypto Locker is working today on all of my PC's! Just in-stall! Working Perfect!
 

Moose

Level 22
Jun 14, 2011
2,271
Hello,

Also here is a Decryption Tool for decrypting the files not sure if it will work on CryptoLocker?

http://tmp.emsisoft.com/fw/decmblblock.exe

source is here

http://www.bleepingcomputer.com/forums/t/494759/decrypt-protect-ransomware/page-3

hope this help!
 

Moose

Level 22
Jun 14, 2011
2,271
Yes! I think it will work on several different ransom-wares that encrypt files!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top