Author Topic: Update your virus detection: Cryptolocker is loose  (Read 3335 times)

Offline idolminds

  • ZOMG!
  • Administrator
  • Forum god
  • *
  • Posts: 11,933
Update your virus detection: Cryptolocker is loose
« on: Sunday, November 03, 2013, 12:41:10 AM »
You don't want to be hit by this one.

TLDR: Once infected the virus will seek out document and image files like doc, odt, pdf, jpeg, raw, etc and then encrypt them. You will then see a countdown window which is how much time you have to pay via bitcoin or some other anonymous money exchange to the tune of $100-300 for your files to be unencrypted or they will be lost forever.

I assume most of you guys aren't in the habit of opening random email attachments, but still figured I'd give a heads up in case you haven't heard about this one.

Offline Quemaqua

  • 古い塩
  • Administrator
  • Forum god
  • *
  • Posts: 16,498
  • パンダは触るな。
    • Bookruptcy
Re: Update your virus detection: Cryptolocker is loose
« Reply #1 on: Sunday, November 03, 2013, 05:51:04 AM »
Pretty nasty, thanks for the heads up.

天才的な閃きと平均以下のテクニックやな。 課長有野

Offline Cobra951

  • Gold Member
  • *
  • Posts: 8,934
Re: Update your virus detection: Cryptolocker is loose
« Reply #2 on: Sunday, November 03, 2013, 08:37:35 AM »
Yes, thank you.  I find it most disturbing that any suggested path to a solution involves paying the ransom.  No way in hell would I ever do that.  So who's tracking these fuckers down?  It can't be impossible to do so if money transfers are involved, even with bitcoins.

Offline ren

  • Veteran
  • ****
  • Posts: 1,672
Re: Update your virus detection: Cryptolocker is loose
« Reply #3 on: Sunday, November 03, 2013, 11:11:48 AM »
The only thing I have digitally that I value are my photos which have duplicate copies on external hard drives all over the place.

Other than that, come at me bro.

Offline Cools!

  • Administrator
  • Veteran
  • *
  • Posts: 1,628
  • Let's burn.
Re: Update your virus detection: Cryptolocker is loose
« Reply #4 on: Sunday, November 03, 2013, 02:58:45 PM »
I have over 6 years of photo and video projects, probably over 200,000 photos at this point, so if my main drives AND backups where compromised paying $300 would be a no brainer. Luckily I'm on a Mac (though still have to worry about my Win 7 partition) and only have "cold" backups.


Offline K-man

  • Post-aholic
  • *****
  • Posts: 2,966
  • HOW'S IT FEEEEEL IDOL
Re: Update your virus detection: Cryptolocker is loose
« Reply #5 on: Sunday, November 03, 2013, 03:58:58 PM »
Yes, thank you.  I find it most disturbing that any suggested path to a solution involves paying the ransom.  No way in hell would I ever do that. 

I have my pictures of Willa backed up to two places on my desktop, an external drive, and in the process of backing up to Crashplan.  But if this were to ever happen to those?  Goddamn right I'd be paying the $300. 
 
It is unfortunate that people don't place any sort of emphasis on backups.

Offline Cools!

  • Administrator
  • Veteran
  • *
  • Posts: 1,628
  • Let's burn.
Re: Update your virus detection: Cryptolocker is loose
« Reply #6 on: Sunday, November 03, 2013, 05:17:35 PM »
I think most people are starting to value it with most modern operating systems remind you of it and/or provide features for it (for example Mac OS X Time Machine, etc.). However it can get very expensive and complicated once you go beyond a single drive.

Offline Quemaqua

  • 古い塩
  • Administrator
  • Forum god
  • *
  • Posts: 16,498
  • パンダは触るな。
    • Bookruptcy
Re: Update your virus detection: Cryptolocker is loose
« Reply #7 on: Monday, November 04, 2013, 03:33:48 PM »
I need to be better about it. I used to keep my writing junk on a thumb drive, my hard drive, and my Dropbox account, but lately I've stopped updating the thumb drive. Backing shit up always seems to confound me, somehow.

天才的な閃きと平均以下のテクニックやな。 課長有野

Offline gpw11

  • Gold Member
  • *
  • Posts: 7,180
Re: Update your virus detection: Cryptolocker is loose
« Reply #8 on: Tuesday, November 05, 2013, 12:15:08 AM »
Through an amazing series of events I recently lost every digital picture I had from the last ten years or so. I had two disc backups of "My Documents (with the images)", as well as a digital copy. Basically: I'm an idiot.

Offline Quemaqua

  • 古い塩
  • Administrator
  • Forum god
  • *
  • Posts: 16,498
  • パンダは触るな。
    • Bookruptcy
Re: Update your virus detection: Cryptolocker is loose
« Reply #9 on: Tuesday, November 05, 2013, 10:01:49 AM »
Jesus, was your house swallowed by a sinkhole or something?

天才的な閃きと平均以下のテクニックやな。 課長有野

Offline gpw11

  • Gold Member
  • *
  • Posts: 7,180
Re: Update your virus detection: Cryptolocker is loose
« Reply #10 on: Tuesday, November 05, 2013, 11:21:44 AM »
Like I said: I'm an idiot.

My parents moved out of their house into an apartment, meaning I had to clear a metric shit ton of stuff accumulated over the years and throw it out.  One of these things was a binder I used for various burnt discs, including backups made over the year.  I took the most recent one of these, placed it in a spindle with some other disks and took it with me.  I "tossed the rest out".

Fast forward a month or so and I'm also moving to a much smaller place (and throwing out a metric shit ton of stuff). In the downsizing fervor I combine my two spindles of disks - one for audio cds, one for data into one of just the disks I want.  I throw out one copy of the disk. The rest of the spindle is literally the backup disk and a bunch of audio CDs.

While in my parent's storage locker I come across a the binder from before.  I guess I never tossed it.  "Great, I'll just leave this hear".

Unpacking my stuff I realize I no longer have a CD player at all and toss out the spindle of disks. Shortly after, I vaguely remember realizing that I had my backup on there. Not a big deal, I still have the "one in the binder", but I'll burn another backup anyways because it's about that time.

Working from home a couple of weeks later and I'm having some kind of computer problem.  Might as well switch to the notebook and get paid to reformat, right? I copy "my documents" over to my non-os drive, along with other stuff, and reformat my main drive.  Upon putting the data back I realize that the file structure changed between XP and Windows 7 - "My Pictures" is no longer a subfolder within "My Documents" but rather a separate folder with only a shortcut in My Documents."  Pictures have been deleted.

Almost hilariously, it immediately hit me that I'm a moron and that the backup disk is no longer in that binder in my parents storage locker and I had actually thrown out both copies.  Everything else was fine as it was copied over to the second drive.  The only other thing that would have been affected is music but that was all kept on the second drive anyways and just linked through a shortcut in "My Music".  Sure enough, there were actually no other backup disks in the binder (I had hoped I at least had one from years earlier).  In the confusion from all the moving and everything I must have gone through the binder itself, pulling out and throwing out disks I didn't need, only deciding at the end to change plans and just take the 2-3 I wanted to keep and put them in a spindle.

Basically, I fucked up.

Offline Cools!

  • Administrator
  • Veteran
  • *
  • Posts: 1,628
  • Let's burn.
Re: Update your virus detection: Cryptolocker is loose
« Reply #11 on: Tuesday, November 05, 2013, 12:29:06 PM »
Wow :(

Offline Quemaqua

  • 古い塩
  • Administrator
  • Forum god
  • *
  • Posts: 16,498
  • パンダは触るな。
    • Bookruptcy
Re: Update your virus detection: Cryptolocker is loose
« Reply #12 on: Tuesday, November 05, 2013, 07:05:18 PM »
Damn. That's a terrible story. It almost makes me not want to back anything up to avoid heartbreak.

天才的な閃きと平均以下のテクニックやな。 課長有野

Offline Xessive

  • Gold Member
  • *
  • Posts: 9,918
    • XSV @ deviantART
Re: Update your virus detection: Cryptolocker is loose
« Reply #13 on: Wednesday, November 06, 2013, 01:36:17 AM »
I've started using Avast! Free Edition on one of my PCs now, to compare and contrast with the Windows Defender experience.

So far so good. It's a pain-free and resource conscious antivirus solution, it works a lot faster than Windows Defender and with better detection. I find it's best when you switch it to "Silent/Gaming Mode" to minimize the popups and notifications.

Offline scottws

  • Gold Member
  • *
  • Posts: 6,602
    • Facebook Me
Re:
« Reply #14 on: Wednesday, November 06, 2013, 10:19:06 AM »
I've started using Avast! Free Edition on one of my PCs now, to compare and contrast with the Windows Defender experience.

So far so good. It's a pain-free and resource conscious antivirus solution, it works a lot faster than Windows Defender and with better detection. I find it's best when you switch it to "Silent/Gaming Mode" to minimize the popups and notifications.
I like Avast because it allows you to do a boot-time scan before Windows loads.  That prevents rootkits from hiding themselves.  Personally I use Eset NOD32.  It doesn't have a built-in boot-time scan but you can make a bootable disc.

Regarding this virus itself, I have most of my stuff backed up but it is on a failing external drive.  I have been meaning to get a new one.

Offline Cobra951

  • Gold Member
  • *
  • Posts: 8,934
Re: Update your virus detection: Cryptolocker is loose
« Reply #15 on: Wednesday, November 06, 2013, 07:52:56 PM »
It seems the safest thing to do is to have external backups on drives you turn off when not performing backups.  I have 2 that way, plus one that's always on.  I need to do more thorough backups of important files to those 2 idle drives.