Bitcoin Forum
May 13, 2024, 09:16:41 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [2016-03-04] Bitcoin Ransomware Education – Cryptlock  (Read 532 times)
trinaldao (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 1218
Merit: 1007


Post your ann & bounty just contact me


View Profile WWW
March 07, 2016, 02:18:34 AM
 #1

Removing Cryptlock has proven to be less of a hassle compared to other types of Bitcoin ransomware. Installing Norton Power Eraser on the computer seems to be doing the trick just fine, as the software will perform a list of rootkit scans. Cryptlock is on the list of threats, and the program should have little effort with taking the proper actions.

Unlike most versions of Bitcoin ransomware, Cryptlock does not seem to prevent users from accessing files by restoring a previous backup. Shadow volumes seem to remain safe from harm when a computer is infected by Cryptlock, which is an interesting change. Making this malware easy to remove should lead to very few people paying the ransom, either in Bitcoin or through other means.

http://themerkle.com/education/bitcoin-ransomware-education-cryptlock/

INVALID BBCODE: close of unopened tag in table (1)
1715591801
Hero Member
*
Offline Offline

Posts: 1715591801

View Profile Personal Message (Offline)

Ignore
1715591801
Reply with quote  #2

1715591801
Report to moderator
1715591801
Hero Member
*
Offline Offline

Posts: 1715591801

View Profile Personal Message (Offline)

Ignore
1715591801
Reply with quote  #2

1715591801
Report to moderator
1715591801
Hero Member
*
Offline Offline

Posts: 1715591801

View Profile Personal Message (Offline)

Ignore
1715591801
Reply with quote  #2

1715591801
Report to moderator
If you see garbage posts (off-topic, trolling, spam, no point, etc.), use the "report to moderator" links. All reports are investigated, though you will rarely be contacted about your reports.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715591801
Hero Member
*
Offline Offline

Posts: 1715591801

View Profile Personal Message (Offline)

Ignore
1715591801
Reply with quote  #2

1715591801
Report to moderator
Kakmakr
Legendary
*
Offline Offline

Activity: 3444
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
March 07, 2016, 09:21:07 AM
 #2

The only problem is, many of the uneducated computer users do not know about this and when they get this Ransomware on their computer, they go into panic mode and they take the easy way out by paying the ransom. After they have done this, they will hate Bitcoin and also advocate it as being closely associated with this kind of filth. In the end the whole community suffer, because word of mouth travel fast and have a lot of negative consequences.

We should help, by educating the uninformed with articles like this and also forum posts like these everywhere. ^smile^

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
jdebunt
Legendary
*
Offline Offline

Activity: 1596
Merit: 1010


View Profile WWW
March 07, 2016, 10:00:38 AM
 #3

The only problem is, many of the uneducated computer users do not know about this and when they get this Ransomware on their computer, they go into panic mode and they take the easy way out by paying the ransom. After they have done this, they will hate Bitcoin and also advocate it as being closely associated with this kind of filth. In the end the whole community suffer, because word of mouth travel fast and have a lot of negative consequences.

We should help, by educating the uninformed with articles like this and also forum posts like these everywhere. ^smile^

The problem is, a lot of the more sophisticated versions of ransomware do not allow users to restore files from a backup either Smiley For most, paying Bitcoin is the only way out, although I'm sure security experts could come up with alternative options over time.

CryptLock just happens to be one of the few exceptions Smiley
alfaboy23
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500



View Profile
March 10, 2016, 03:54:40 AM
 #4

The example is what happens to me today,

All of my pictures, videos, PDF files, text files document files including Word and Excel docs and DWG files are all encrypted and with extension name .surprise, then in my desktop, there are 3 drops of the ransomware: surprise.exe, DECRYPTION_HOWTO.Notepad and Encrypted_Files.Notepad.

The last 2 file is unencrypted and this is the content of the DECRYPTION_HOWTO.Notepad

Quote
What happened to your files ?
All of your files were protected by a strong encryption.
There is no way to decrypt your files without the key.
If your files not important for you just reinstall your system.
If your files is important just email us to discuss the price and how to decrypt your files.
You can email us to nowayout@protonmail.com and nowayout@sigaint.org
Write your Email to both email addresses PLS
We accept just BITCOIN if you dont know what it is just google it.
We will give instructions where and how you buy bitcoin in your country.
Price depends on how important your files and network is.it could be 0.5 bitcoin to 25 bitcoin.
You can send us a 1 encrypted file for decryption.
Feel free to email us with your country and computer name and username of the infected system.

The other file is too enlarge as it has the list of all of my encrypted files.

Anyone also encountered this?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!