files encrypted by hackers after visiting a bogus Australia Post website

It was CryptoDefense that I was hit by, not CryptoLocker. It was just a variant of CL. As I said before, I had everything backed up and it went after the smallest files first. This is a copy of the ransom note I got, this HTML file was present in the root directory of any folder that had files that were encrypted. Basically this text instructs the affected user to first download a TOR browser so that they are able to enter the Dark Web.
The string of x’s that you see in this snapshot was originally a unique string for me and would have directed me to the proper place to pay their ransom and get the right key to decrypt my files.

In my case, because I was fully backed up, they got NOTHING!

BTW, the reason I believe this happened when it did to me is because I was running XP with MicroSoft Security Essentials. MS ended support for XP and Security Essentials for XP in early April. I was hit on April 21………

After this happened, MS quietly gave out free copies of Win7 for awhile.

April 21 looks like you missed it by a few days but might be worth a try:

When I first looked into it, I came across a text that explained that up until a certain date (a short time before my troubles) the key was actually accidently stored on each victims computer. The perps didn’t even know that until some smart ass published a report on the fact. They quickly changed their code after that. AFAIK there are no keys on my drive. As I mentioned, I put aside any affected drives for further study at a later date.

Interesting idea, i wonder if there is a way i can implement this automatically, i currently backup to a usb 3 drive every so often, but if i got a ransomware and had bad timing it could foul up that drive as well.

the “quirks” aren’t a bug, they’re a feature :stuck_out_tongue:

and Dimbo I wasn’t trying to write a manual, or trying to step on your toes…my apologies if you took it that way

The town of Decatur Texas and their sheriffs department were recently encrypted. They both paid the ransom. The town got their data back, sheriff did not.

They saved the public money by not having proper security to begin with :smiley:

If they had someone would have pointed out they spent money on computer experts and never had any failures hence it was a waste of taxpayer dollars. :open_mouth:

Not even!!! Please don’t apologize to me, for speaking your mind!!! My toes are bulletproof, so step where your heart leads you!

Sometimes I speak/write in a terse manner, and I still don’t tend to use emoticons as much as I should…

Please do not apologize to me. I’d rather you say exactly what you want, using precisely the words that come first to your own mind!

make sure it needs a strong login.the newer varient attempts to bruteforce logins on shares!
and will encrypt any drive mounted on the system.
i see too many backup drives killed by the same event that took out the system.
put the backup in the safe!

A backup connected to the system is NOT a backup. A backup stored in the same building as the system is NOT a backup.

When I got hit, it even reached out over my LAN to affect files on my PogoPlug.

But as I said again and again (see I am redundant, that’s a good thing :slight_smile: ) I was fully backed up.