Bitcoin Forum
May 05, 2024, 09:47:07 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 »  All
  Print  
Author Topic: Please Help - Ransomware has stolen my files and I need to pay in BitCoins  (Read 3884 times)
notlist3d
Legendary
*
Offline Offline

Activity: 1456
Merit: 1000



View Profile
April 27, 2015, 07:14:17 AM
 #41

Frankly I would not trust the op.  He refused to meet with  danny h.  Strong chance he is looking to con someone to take a fake cc or paypal.

Also he could be a signature shill. Posting a topic to allow people in signature campaigns to post here with legit answers.

I won't post again.  And I do not believe him as he would not meet with danny h.

Also classic excuse I forgot to backup my files.  Feel sorry for him and send him a coin that he charges on his cc and good luck to you.

Thanks for advice I will leave thread alone after this post aswell.

I found it hard to believe he did not backup important files.  The last company I worked for I know pushed backing up important files.  It was stressed very much to use the network drive.  We also had a enterprise anti-virus that forced you to update in background, so most computers did not get infected unless very very early after the malware release.
1714945627
Hero Member
*
Offline Offline

Posts: 1714945627

View Profile Personal Message (Offline)

Ignore
1714945627
Reply with quote  #2

1714945627
Report to moderator
Each block is stacked on top of the previous one. Adding another block to the top makes all lower blocks more difficult to remove: there is more "weight" above each block. A transaction in a block 6 blocks deep (6 confirmations) will be very difficult to remove.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
April 27, 2015, 07:17:57 AM
 #42

We have nothing to do with ransomware and this isn't an exchange site.
So, Why the fuck would you create an account here looking for help.
Too bad localbitcoins won't sell at market rate, that is our problem some how?
You can't figure out how to buy them at an exchange but you figured out how to create an account here
and troll the forums.
Don't click on BS links, you deserved what you got.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
btchris
Hero Member
*****
Offline Offline

Activity: 672
Merit: 504

a.k.a. gurnec on GitHub


View Profile WWW
April 27, 2015, 01:14:26 PM
 #43

I wish OP could give us exact virus/malware he has.  If he had that we could tell him a lot more.  My bachelors degree is actually based on computer security.

Your degree clearly wasn't in reading comprehension. OP stated the exact virus name in the first post Roll Eyes
notlist3d
Legendary
*
Offline Offline

Activity: 1456
Merit: 1000



View Profile
April 27, 2015, 02:19:11 PM
 #44

I wish OP could give us exact virus/malware he has.  If he had that we could tell him a lot more.  My bachelors degree is actually based on computer security.

Your degree clearly wasn't in reading comprehension. OP stated the exact virus name in the first post Roll Eyes

And if you have one it's not in diplomatic skills, or business communication.

But it stated the threat yes, but malware is not one size fit's all. I was assuming OP was taking steps to remove it.   But read last few post's it seems he might not be legit person with problem.

Malware is remade many... many times.  So we don't know if he has a new version with it making past virus protection, it has a different fingerprint.  And what new version does could be different.  Or OP has bad/old virus protection and it's did not detect it even though it's been out in the world for a while.

Chances are most versions will be close on effects and removal, but you never know.
achow101_alt
Sr. Member
****
Offline Offline

Activity: 268
Merit: 250


View Profile
April 27, 2015, 08:13:38 PM
 #45

I wish OP could give us exact virus/malware he has.  If he had that we could tell him a lot more.  My bachelors degree is actually based on computer security.

Your degree clearly wasn't in reading comprehension. OP stated the exact virus name in the first post Roll Eyes

And if you have one it's not in diplomatic skills, or business communication.

But it stated the threat yes, but malware is not one size fit's all. I was assuming OP was taking steps to remove it.   But read last few post's it seems he might not be legit person with problem.

Malware is remade many... many times.  So we don't know if he has a new version with it making past virus protection, it has a different fingerprint.  And what new version does could be different.  Or OP has bad/old virus protection and it's did not detect it even though it's been out in the world for a while.

Chances are most versions will be close on effects and removal, but you never know.

He clearly states in the first post that he has the TeslaCrypt virus. Later, he also says that his antivirus prevented the virus from hijacking his desktop. It may have even removed the virus itself, but the encrypted files are still there.

I don't even think you have even read this thread. With your signature, I think you are just posting here for the posts, and don't even know what this thread is even about.

Tip Me!: 1AQx99s7q1wVinbgXbA48BaZQVWpHe5gYM | My PGP Key: Fingerprint 0x17565732E08E5E41
toddball (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
April 27, 2015, 09:52:27 PM
 #46

Frankly I would not trust the op.  He refused to meet with  danny h.  Strong chance he is looking to con someone to take a fake cc or paypal.

Also he could be a signature shill. Posting a topic to allow people in signature campaigns to post here with legit answers.

I won't post again.  And I do not believe him as he would not meet with danny h.

Also classic excuse I forgot to backup my files.  Feel sorry for him and send him a coin that he charges on his cc and good luck to you.

Wow man.  Your conjecture is pretty amazing here.

I didn't see where Danny said in the forum that I wouldn't meet with him, but the truth is, he's 450+ miles from where I am so how exactly was I going to meet him?  It's pure coincidence that my place of work is actually in Illinois, and seems not far from where Danny was located.

I'm the guy that got ripped off, by the hacker that infected my computer with a virus.

Some of you need to read more, think less.  I did exactly tell you what virus is was, it's called TeslaCrypt and seems to be a newer version of the cryptolocker virus.

In the end, I thanked Danny much for his time, and he told me that not paying the ransom was the right call.  More on that in a minute.....

DannyHamilton
Legendary
*
Offline Offline

Activity: 3388
Merit: 4616



View Profile
April 27, 2015, 10:10:37 PM
 #47

- snip -
(a bunch of nonsense from someone spamming the forum to make money)
- snip -

Wow man.  Your conjecture is pretty amazing here.

I didn't see where Danny said in the forum that I wouldn't meet with him, but the truth is . . .
- snip -

toddball,

Perhaps you didn't notice where I said:

- snip -
Yeah, some of you haven't read thru the parts where I stated
- snip -

You would do well not to take advice from anybody that has an advertisement in their signature space on this forum.

The vast majority of those are people that are being paid per post to advertise with those signatures.  Therefore, they'll say just about anything in a discussion thread just to increase their post count (and therefore increase their income).  Generally, they know less about the topic they are discussing than the person asking the questions.

See that colorful "bit-x" "The reputable bitcoin mining service" at the bottom of philipma1957's post?  That's the "advertisement in their signature space" that I was talking about.

If you see someone with such an ad, you can simply click the "ignore" under their userID at the left of the post.  Then you won't have to see any more of their nonsense.

See my signature link for more information on how to quickly block a significant number of these forum spammers.
toddball (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
April 27, 2015, 10:20:53 PM
 #48

I only stopped in here to thank you guys for your time and let you know what I decided to do.....

I'll set the remaining facts straight for those that would prefer to make up your own.   Roll Eyes Roll Eyes

I got the Teslacrypt virus.  I'm not sure how.  I haven't had a virus in years.  Water under the bridge at this point......

This isn't the normal kind of virus most of us have gotten from a friend's email or some bad advertising malware.  It encrypted all of my files, without the key it's just like deleting them.  As far as I was aware before this, the concept was something out of the movies.  I didn't know that there were viruses that severe that regular people could get.

I'm an independent consultant.  I got the job in a hurry, and had to get set up to work from home in a hurry.  It's been a-holes and elbows since then, for 6 months now.  The only assistance I've had from the companies IT was the installation of the AV software.  It's a small company, even the IT guy is an outside contractor.

I checked my "continuous backup drive" and the dates on the backup file that I believed contained my files was old, this led me to believe something went wrong and I did not have a recent backup.  I'm a mechanical engineer, not a computer specialist.

I decided not to pay the ransom.  Mostly because I don't have the means where I live to easily get bitcoins to pay the ransom.  Danny H, who offered to help me, said that was probably the smartest thing to do anyway and I thanked him for his help.

I found when I restored from the backup that in fact it was an incremental backup, and I had files from my last backup from the end of March.  I left for a prototype build in S. Illinois right after that and didn't really author too many new files between then and now, so I'm not losing a lot - but I didn't know that when I came here in a panic.

Why did I come here?  Someone was pretty hot and bothered about that.  Well like I said, I was having a tough time figuring out how to buy the coins with the payment means that I have available.  And so many places that claim to be exchanges that I signed up for and haven't heard anything since.  

And I lack patience, and like many of us, I use the internet for information gathering - Don't you?  Or do you just automatically know everything, Mr BCWinning?

Whatever, you're a chump for saying what you did.  I'm no crook and I found the advice I was looking for.  So it seems I'm a little smarter than you think.  And BTW, I'm not a troll either, I don't know what gave you that idea.  I was in a panic over lost data in a critical portion of a prototype development, and I'm the entire engineering department on this, so I had a right to become a little panicked.

To the rest of you that were helpful, thanks again very much.

In the end, I lost alot of time, was able to recover the Bill of Material from the hackers "free trial" download, and so only lost several other files that I can recreate.  I got off super lucky.

This won't happen again, as soon as my computer and data are back up and running IT is going to get me connected to their network for regular backups.

Thanks again everyone

Toddball

PS  Danny just saw your post...  So I guess they are the trolls you warned about.  Hah.  I don't like being accused of trolling.  Live and Learn.  You guys are alright by me.  Good Luck
grue
Legendary
*
Offline Offline

Activity: 2058
Merit: 1431



View Profile
April 28, 2015, 12:22:49 AM
 #49

http://blogs.cisco.com/security/talos/teslacrypt

It is pitch black. You are likely to be eaten by a grue.

Adblock for annoying signature ads | Enhanced Merit UI
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
April 28, 2015, 01:44:29 AM
 #50

I only stopped in here to thank you guys for your time and let you know what I decided to do.....

I'll set the remaining facts straight for those that would prefer to make up your own.   Roll Eyes Roll Eyes

I got the Teslacrypt virus.  I'm not sure how.  I haven't had a virus in years.  Water under the bridge at this point......

This isn't the normal kind of virus most of us have gotten from a friend's email or some bad advertising malware.  It encrypted all of my files, without the key it's just like deleting them.  As far as I was aware before this, the concept was something out of the movies.  I didn't know that there were viruses that severe that regular people could get.

I'm an independent consultant.  I got the job in a hurry, and had to get set up to work from home in a hurry.  It's been a-holes and elbows since then, for 6 months now.  The only assistance I've had from the companies IT was the installation of the AV software.  It's a small company, even the IT guy is an outside contractor.

I checked my "continuous backup drive" and the dates on the backup file that I believed contained my files was old, this led me to believe something went wrong and I did not have a recent backup.  I'm a mechanical engineer, not a computer specialist.

I decided not to pay the ransom.  Mostly because I don't have the means where I live to easily get bitcoins to pay the ransom.  Danny H, who offered to help me, said that was probably the smartest thing to do anyway and I thanked him for his help.

I found when I restored from the backup that in fact it was an incremental backup, and I had files from my last backup from the end of March.  I left for a prototype build in S. Illinois right after that and didn't really author too many new files between then and now, so I'm not losing a lot - but I didn't know that when I came here in a panic.

Why did I come here?  Someone was pretty hot and bothered about that.  Well like I said, I was having a tough time figuring out how to buy the coins with the payment means that I have available.  And so many places that claim to be exchanges that I signed up for and haven't heard anything since.  

And I lack patience, and like many of us, I use the internet for information gathering - Don't you?  Or do you just automatically know everything, Mr BCWinning?

Whatever, you're a chump for saying what you did.  I'm no crook and I found the advice I was looking for.  So it seems I'm a little smarter than you think.  And BTW, I'm not a troll either, I don't know what gave you that idea.  I was in a panic over lost data in a critical portion of a prototype development, and I'm the entire engineering department on this, so I had a right to become a little panicked.

To the rest of you that were helpful, thanks again very much.

In the end, I lost alot of time, was able to recover the Bill of Material from the hackers "free trial" download, and so only lost several other files that I can recreate.  I got off super lucky.

This won't happen again, as soon as my computer and data are back up and running IT is going to get me connected to their network for regular backups.

Thanks again everyone

Toddball

PS  Danny just saw your post...  So I guess they are the trolls you warned about.  Hah.  I don't like being accused of trolling.  Live and Learn.  You guys are alright by me.  Good Luck
You don't use it (the internet for information gathering) very well to come here make your first post whining about how you got a virus from being stupid and can't buy btc at market price.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
judypug1956
Sr. Member
****
Offline Offline

Activity: 355
Merit: 276


View Profile
April 28, 2015, 03:15:22 AM
 #51

I am philipma1957 this is my secondary none signature account as I promised I will not post here with my signature account more then once.


   Here goes my opinion on the op after I posted  to not sell the op any coins. He has fixed his issue. He does not need coins. So I guess my signature post saved the day here.

  

 I realize some people do not like signature campaigns. They believe  posters post just to make money.  Which is why I am using this non signature account to point out that the op has fixed his problem.  

He no longer needs us to sell him coins with a cc as payment.

1956jUdYPFwiBSzt9AECdWj3KE4WV7taiM I can't do 1957philma.. for btc address the i are not allowed This is a secondary account for Philipma1957, don't do business with this account deal with philipma1957
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1499


No I dont escrow anymore.


View Profile WWW
April 28, 2015, 07:48:48 AM
 #52

-snip-
You don't use it (the internet for information gathering) very well to come here make your first post whining about how you got a virus from being stupid and can't buy btc at market price.

Oh shut up. If someone comes anywhere for help you do your best to help them or - if you cant - stay out of it and direct them to someone that can.

Yes, this is not bitcoin related or only remotly, but instead of attacking someone seeking help, just report the thread to be moved into offtopic and go on your way.

@Danny moving this into offtopic also has the benefit that no one here gets any satoshi for their posts.

-snip-
Posts in the off-topic board do not count.
-snip-

-snip-
Disqualified posts:
-snip-
- Off-topic and altcoin boards.
-snip-

Im not really here, its just your imagination.
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
April 28, 2015, 09:17:05 AM
 #53

-snip-
You don't use it (the internet for information gathering) very well to come here make your first post whining about how you got a virus from being stupid and can't buy btc at market price.

Oh shut up. If someone comes anywhere for help you do your best to help them or - if you cant - stay out of it and direct them to someone that can.

Yes, this is not bitcoin related or only remotly, but instead of attacking someone seeking help, just report the thread to be moved into offtopic and go on your way.

@Danny moving this into offtopic also has the benefit that no one here gets any satoshi for their posts.

-snip-
Posts in the off-topic board do not count.
-snip-

-snip-
Disqualified posts:
-snip-
- Off-topic and altcoin boards.
-snip-
yep you're part of the problem too, holding the crybabies hands.
Keep coddling the stupid's it will only increase them.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1499


No I dont escrow anymore.


View Profile WWW
April 28, 2015, 09:40:14 AM
 #54

-snip-
yep you're part of the problem too, holding the crybabies hands.
Keep coddling the stupid's it will only increase them.

I applaud your darwinism I should probably make a note somewhere to make sure I dont help you accidentally. Education and help are never part of the problem, they are always part of the solution. Holding someones hands is perfectly fine while they are still growing. Not letting them make mistakes in the first place is a problem. If you cant see the difference Im not going to teach it to you. OP certainly learned a few valuable lessons and not only about IT systems and how to keep them secure. Wether or not the data was lost in the process is irrelevant for the lessons learned.

Even in the event that OP had been a troll answering in a constructive manner can still be helpful for someone else silently reading.

Im not really here, its just your imagination.
sgk
Legendary
*
Offline Offline

Activity: 1470
Merit: 1002


!! HODL !!


View Profile
April 28, 2015, 09:58:26 AM
 #55

<snip>
I found when I restored from the backup that in fact it was an incremental backup, and I had files from my last backup from the end of March.  I left for a prototype build in S. Illinois right after that and didn't really author too many new files between then and now, so I'm not losing a lot - but I didn't know that when I came here in a panic.
<snip>

Good to know you were able to restore a backup and didn't have to pay ransom. It would have been an awful and costly thing to do anyway.
For all people reading this topic, here are a few links for future reference:

How to protect against CryptoLocker malware
http://support.kaspersky.com/viruses/common/10646#block2

CryptoLocker Is Dead: Here’s How You Can Get Your Files Back!
http://www.makeuseof.com/tag/cryptolocker-dead-heres-can-get-files-back/

FireEye and Fox-IT have partnered to provide free keys designed to unlock systems infected by CryptoLocker.
https://www.decryptcryptolocker.com/

How to decrypt or get back encrypted files infected by known encrypting ransomware viruses.
http://www.wintips.org/how-to-decrypt-or-get-back-encrypted-files-by-known-encrypting-ransomware-crypt-viruses/

How to recover files from CryptoLocker for free
http://www.expertreviews.co.uk/technology/8063/how-to-recover-files-from-cryptolocker-for-free


btchris
Hero Member
*****
Offline Offline

Activity: 672
Merit: 504

a.k.a. gurnec on GitHub


View Profile WWW
April 28, 2015, 11:19:08 AM
 #56

toddball,

It's great to hear you managed to recover most of your files w/o even having to pay a ransom!

Although you may not need it now, did you see grue's post?


It links to a decryption utility for TeslaCrypt posted just yesterday by researchers over at Cisco, which may or may not work depending on which version of TeslaCrypt you have. It might be worth a try to recover your remaining files.

Even if it doesn't work, they're trying to improve it to work on newer versions of TeslaCrypt as well, so you may want to keep an eye on their blog for future updates.
pedrog
Legendary
*
Offline Offline

Activity: 2786
Merit: 1031



View Profile
May 01, 2015, 03:09:33 AM
 #57

Check https://noransom.kaspersky.com/ again.

April 29 update: 13 decryption keys added to the database

You might get lucky this time.

btchris
Hero Member
*****
Offline Offline

Activity: 672
Merit: 504

a.k.a. gurnec on GitHub


View Profile WWW
May 01, 2015, 12:07:24 PM
 #58

Check https://noransom.kaspersky.com/ again.

April 29 update: 13 decryption keys added to the database

You might get lucky this time.

pedrog,

Your post is irrelevant because OP was never infected by CoinVault, but rather by TeslaCrypt which is completely unrelated.

Had you read either the very first post or the very last one (above), you would have seen this, but you did not.
BCwinning
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
May 01, 2015, 10:09:41 PM
 #59

-snip-
yep you're part of the problem too, holding the crybabies hands.
Keep coddling the stupid's it will only increase them.

I applaud your darwinism I should probably make a note somewhere to make sure I dont help you accidentally. Education and help are never part of the problem, they are always part of the solution. Holding someones hands is perfectly fine while they are still growing. Not letting them make mistakes in the first place is a problem. If you cant see the difference Im not going to teach it to you. OP certainly learned a few valuable lessons and not only about IT systems and how to keep them secure. Wether or not the data was lost in the process is irrelevant for the lessons learned.

Even in the event that OP had been a troll answering in a constructive manner can still be helpful for someone else silently reading.
Best thing that could happen to this world is stupid fucks like him and you die off.
 Keep holding the stupids hands and they won't ever learn.
Show them google and how to read
give a man money they eat for a day, make the person work, they eat for a lifetime.
Trust me, I know how to use the internet and wouldn't be here asking for help.

The New World Order thanks you for your support of Bitcoin and encourages your continuing support so that they may track your expenditures easier.
pedrog
Legendary
*
Offline Offline

Activity: 2786
Merit: 1031



View Profile
May 01, 2015, 10:17:24 PM
 #60

Check https://noransom.kaspersky.com/ again.

April 29 update: 13 decryption keys added to the database

You might get lucky this time.

pedrog,

Your post is irrelevant because OP was never infected by CoinVault, but rather by TeslaCrypt which is completely unrelated.

Had you read either the very first post or the very last one (above), you would have seen this, but you did not.

They are related, TeslaCrypt appears to be a direvative of Cryptolocker.

Here's a post detailing how to decrypt it:

http://blogs.cisco.com/security/talos/teslacrypt

Pages: « 1 2 [3] 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!