Cryptolocker Decryption website open

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Apr 13, 2013
3,272
25,108
4,188
NYC
This is too cool for words (but I'll try anyway); As many here know, one malware strain that has caused particular problems lately has been Crptolocker. The malware will encrypt various filetypes while connecting to a Server where a decryption key will be generated and stored. Once the malware has finished doing what it does a screen like this will be presented to the user:

cryptolocker.png


An issue for the hard working malware author has been the very success of Cryptolocker. Most AV firms have been bery good at pushing out definitions to remove all traces of the malware, while sadly still leaving all the files still encrypted. The removal process will also zap the screen presented above, so now the user will not know where to go to buy the unlock key, and the poor starving criminal won't get paid.

The remedy is obvious- start a website where the infected can go any buy the decryption key online! The specifics of this have just been published here:

http://thehackernews.com/2013/11/CryptoLocker-Ransomware-Decryption-service-malware-keys.html

Please note that when the decrypt codes were first sold the price was 1 bitcoin and was recently doubled to 2 BC. Now however, to defray the cost of setting up the website (located in Central Russia) the price of the key has been upped to 10 BC (current exchange rate of 1 BC = 222 USD).

One last thing- Cryptolocker-blocking tools have been published. One from BitDefender can be found here:

http://labs.bitdefender.com/2013/10/cryptolocker-ransomware-makes-a-bitcoin-wallet-per-victim/

and another good one, CryptoPrevent, can be found here:

http://www.foolishit.com/vb6-projects/cryptoprevent/

(I personally haven't checked to see if these tools will work against the latest variants)
 
or you can use EAM 7.0 and Online armor 7.0 both can prevent and remove cryptolocker
 
free remove tool from sophos
http://www.sophos.com/en-us/products/free-tools/virus-removal-tool.aspx
 
The main problem with Cryptolocker if it gets widespread and popular, new variants will be distributed so fast that no detection will be able to detect or remove all variants of it in a given time.

Your main concern should will be not removing or detecting it but avoiding it altogether. You can start by downloading nothing from the web except from trusted download sites that scan all hosted files.

Keep UAC on defaults and never approve anything that you do know for sure is safe. Never open or runs files, always save files to location and then scan with your AV and scan with VirusTotal (several uploading options are available).

As far as I know only a few variants have been found in the wild but this could get much worse. It will have to run its course just like all malware does, if you watch your actions and don't ignorantly click you can limit the possibilities to getting exposed to it.

Thanks. :D
 
If I ended up infected with Crypto, I would mess about for 10 minutes trying to unlock my files, if I failed I would laugh and hit 8.1 refresh, if that failed, reinstall windows

Moral of the story, anything you can not bear to lose, backup online, or offline away from anything that could encrypt or delete it

Losing my files would only be a PITA, it would not be mission critical, I can download everything again if it came to that
 
Superb point, Littlebits! With much malware, both the vector and payload are written initially with verbose code, so just by noping out a bit will give the file a different identifier thus with a few sends work one will basically transform the same old thing to a fresh Zero day sample day after day. Some form of second line defense, either a BB or sandbox is essential.
 
Cryptolocker-blocking tools have been published

http://labs.bitdefender.com/2013/10/cryp...er-victim/

Is not working a 100% I try enable BitDefender Cryptolocker-Blocking tool.
It said that it is Disable? For use on my parent's in which has Windows XP.
 
Moose said:
Cryptolocker-blocking tools have been published

http://labs.bitdefender.com/2013/10/cryp...er-victim/

Is not working a 100% I try enable BitDefender Cryptolocker-Blocking tool.
It said that it is Disable? For use on my parent's in which has Windows XP.

Not Found

Apologies, but the page you requested could not be found. Perhaps searching will help.

Thanks. :D
 
Littlebits

http://labs.bitdefender.com/2013/10/cryptolocker-ransomware-makes-a-bitcoin-wallet-per-victim/
 
Hi!

http://download.bitdefender.com/removal_tools/BDAntiCryptoLocker_Release.exe
 
BitDefender Crypto Locker is working today on all of my PC's! Just in-stall! Working Perfect!
 
Hello,

Also here is a Decryption Tool for decrypting the files not sure if it will work on CryptoLocker?

http://tmp.emsisoft.com/fw/decmblblock.exe

source is here

http://www.bleepingcomputer.com/forums/t/494759/decrypt-protect-ransomware/page-3

hope this help!
 
Yes! I think it will work on several different ransom-wares that encrypt files!