Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Decryption keys are now freely available for victims of CryptoLocker


  • Please log in to reply
217 replies to this topic

#31 lurkermihai

lurkermihai

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:03 AM

Posted 29 September 2014 - 04:44 AM

You are infected with Critroni, there is no decrypter to get these files back as of yet.
 
xXToffeeXx~

 

I see. Ok, thanks.



BC AdBot (Login to Remove)

 


#32 karlfk

karlfk

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:03 PM

Posted 02 October 2014 - 11:05 PM

Can we still get the CryptoUnlocker GUI  to download all I'm getting is a html file

 

cheers karl



#33 CB77

CB77

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 15 October 2014 - 07:25 AM

Add me to the bunch who have been infected by this Critroni.

 

My files too have the extension .ctb2 now. (jpg/zip/rar/doc/txt files)

 

So if they are working on a delocker, how long could that take? Are my files ruined forever or is there perhaps hope left?



#34 SabiW

SabiW

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:03 PM

Posted 15 October 2014 - 09:23 PM

We were attacked by what we believe is the Cryptolocker virus, and our external back up files have been encrypted. The virus came through an email on our Windows 7 PC running MS Office 2013. I am still using an old dinosaur XP running MS Office 2003. Documents on my hard drive are not encrypted, but documents on the Win7 hard drive have been encrypted. We have tried using the Microsoft decrypter instructions. Success with .pdf files, but not .doc, .xls etc.

We found a link to FireEye/Foxit scanner, but when I upload an encrypted MS document, it tells me that the document is not encrypted by CryptoLocker. I am confused, as there is a Google Chrome icon in each folder that  links to a CryptoLocker link. I am reluctant to include links in this conversation, as I am not sure whether it would compromise your site. We are running Vipre, who have been informed. They advised us to reinstall Vipre 2015, and have been able to eradicate any future encryptions, but were not able to restore those files infected prior to the reinstall and consequent attempt from the back end.

 

We are at a loss as where to go for assistance. Our hard drive has a lot of years of work that is now off limits. I hope you can assist in some way.

 

Thanks in advance (pleading)



#35 omab

omab

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 15 October 2014 - 11:54 PM

We were attacked by what we believe is the Cryptolocker virus, and our external back up files have been encrypted. The virus came through an email on our Windows 7 PC running MS Office 2013. I am still using an old dinosaur XP running MS Office 2003. Documents on my hard drive are not encrypted, but documents on the Win7 hard drive have been encrypted. We have tried using the Microsoft decrypter instructions. Success with .pdf files, but not .doc, .xls etc.

We found a link to FireEye/Foxit scanner, but when I upload an encrypted MS document, it tells me that the document is not encrypted by CryptoLocker. I am confused, as there is a Google Chrome icon in each folder that  links to a CryptoLocker link. I am reluctant to include links in this conversation, as I am not sure whether it would compromise your site. We are running Vipre, who have been informed. They advised us to reinstall Vipre 2015, and have been able to eradicate any future encryptions, but were not able to restore those files infected prior to the reinstall and consequent attempt from the back end.

 

We are at a loss as where to go for assistance. Our hard drive has a lot of years of work that is now off limits. I hope you can assist in some way.

 

Thanks in advance (pleading)

Hi there,

 

I think you have been infected by CryptoWall, a younger, more sophisticated brother of CryptoLocker. Unfortunately, there is no way to de-crypt files locked by CryptoWall yet. I suggest you just wait and hope. Sorry to be bearer of bad news. If it's any comfort, there are many of us :lmao:   



#36 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,563 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:03 AM

Posted 16 October 2014 - 10:49 AM

Download ID tool from here. It should be able to detect the type of ransomware that have infected you.


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#37 Macpain

Macpain

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 17 October 2014 - 07:55 AM

i'm in the same shame here, Cryptowall, hoping that there will be some solution soon.

I've tried many data recovery, but none worked fine for me, only old stuff, correctly deleted by me, previously :(

 

maybe have you some experience for this issue? any data recovery that worked fine for you with crypto_wall deleted fils?

 

thank in advance

 

(sad.. :( )



#38 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,563 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:03 AM

Posted 17 October 2014 - 05:12 PM

Read here:

 
CryptoWall and DECRYPT_INSTRUCTION Ransomware Information Guide and FAQ


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#39 CB77

CB77

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 17 October 2014 - 07:07 PM

Thanks!

 

I downloaded Photorec but the data recovery method is scaring me. This is all new to me and I am NOT a computer wiz.

It's telling me to use a 2nd computer(I don't have one!) as backup and use for the program or else your hard drive will be busted. Uhm, yeah, I don't want that.

 

Most my encrypted files are on my external hard drive, BUT that hard drive also has tons of uncrypted, and still workable, files. I get the idea that by using this recovery program, my entire drive will be rebooted and I may lose other things because in some folders the encrypted files are in, also have unaffected files/images.

 

So I am hugely scared to use these recovery programs.

As a side note, since we're now 4 days later, obviously my computer has been rebooted several times, and my external hard drive has been unplugged on and off too. I read everywhere that the more you restart your computer, the more is lost. So, I may already have caused irreparable damage, no?

 

I could really use some help with running Photorec and info if I would indeed ruin more on that hard drive than already the encrypted files?


Edited by CB77, 17 October 2014 - 07:08 PM.


#40 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,563 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:03 AM

Posted 17 October 2014 - 07:57 PM

I am not savvy using Photorec.  Did you try restoring from the Shadow Volume Copies? It is the easier way.

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#41 CB77

CB77

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 18 October 2014 - 08:09 AM

Yes I tried that, but there were no shadow copies to retrieve (I suspect Cryptowall deleted those, and sadly because Win8 doesn't automatically enable restore points or previous versions, I wasn't aware that I had to turn that on myself so no "previous versions" or restore points to be found).

I checked via ShadowExplored but even there nothing was of use. At least, not much. Only one option that was the day I received the malware (I think).

 

And I did try it with the pictures on my C drive to that date and it did "restore" the images, it was unable to retrieve the image so it only gave me solid color images in return. I guess the files were already too damaged? It did however restore my documents.

 

However, my bigger issue is my ext. portable drive that got affected which was my backup! (damn Cryptowall infecting ALL attached drives)

I tried Shadow Explorer there too but it can't even see that drive. It only lets me see the drives in my computer, not the external ones so I couldn't restore that drive at all! :(



#42 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,563 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:03 AM

Posted 18 October 2014 - 01:54 PM

However, my bigger issue is my ext. portable drive that got affected which was my backup! (damn Cryptowall infecting ALL attached drives)
I tried Shadow Explorer there too but it can't even see that drive. It only lets me see the drives in my computer, not the external ones so I couldn't restore that drive at all!

 

 

Sadly to say, but we have not been able to find a solution to it. 

 

There is an active CryptoWall support topic, which contains discussion and the experiences of a variety of IT consultants, end users, and companies who have been affected by CryptoWall. If you are interested in this infection or wish to ask questions about it, please visit the CryptoWall support topic. Once at the topic, and if you are a member, you can ask or answer questions and subscribe in order to get notifications when someone adds more information to the topic.

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed

 


#43 tharpdevenport

tharpdevenport

  •  Avatar image
  • Members
  • 59 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:11:03 PM

Posted 27 October 2014 - 12:50 PM

Can we still get the CryptoUnlocker GUI  to download all I'm getting is a html file

 

cheers karl

 

Would that program have worked?  I tried DecryptCryptolocker.com and I was never able to get anywhere; after hours of waiting I gave up.



#44 persmash

persmash

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:03 AM

Posted 18 November 2014 - 08:05 AM

Hi all, I'm infected by Cryptolocker, when I try to decryt service "https://www.decryptcryptolocker.com/", I'm getting an error "The file does not seem to be infected by CryptoLocker. Please submit a CryptoLocker infected file." But It is infected. How can I solve this issue?



#45 Tarza85

Tarza85

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:03 PM

Posted 19 November 2014 - 04:15 AM

Hi Everyone, 

I am not computer savvy at all and this is my first time on a forum so please forgive my ignorance. 

I got infected with the Cryptolocker virus on my work computer, which isn't a big deal because they can just re-image the machine and I don't store anything on there. However, it managed to infect my external hard drive which has EVERYTHING on it. I have tried the FireEye - Fox IT Scanner and it keeps saying that my files aren't infected when they are. Does anyone have any other options I can try? 

Any help is great. 

Thanks






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users