It was CryptoDefense that I was hit by, not CryptoLocker. It was just a variant of CL. As I said before, I had everything backed up and it went after the smallest files first. This is a copy of the ransom note I got, this HTML file was present in the root directory of any folder that had files that were encrypted. Basically this text instructs the affected user to first download a TOR browser so that they are able to enter the Dark Web.
The string of x’s that you see in this snapshot was originally a unique string for me and would have directed me to the proper place to pay their ransom and get the right key to decrypt my files.
In my case, because I was fully backed up, they got NOTHING!
BTW, the reason I believe this happened when it did to me is because I was running XP with MicroSoft Security Essentials. MS ended support for XP and Security Essentials for XP in early April. I was hit on April 21………
After this happened, MS quietly gave out free copies of Win7 for awhile.
When I first looked into it, I came across a text that explained that up until a certain date (a short time before my troubles) the key was actually accidently stored on each victims computer. The perps didn’t even know that until some smart ass published a report on the fact. They quickly changed their code after that. AFAIK there are no keys on my drive. As I mentioned, I put aside any affected drives for further study at a later date.
Interesting idea, i wonder if there is a way i can implement this automatically, i currently backup to a usb 3 drive every so often, but if i got a ransomware and had bad timing it could foul up that drive as well.
The town of Decatur Texas and their sheriffs department were recently encrypted. They both paid the ransom. The town got their data back, sheriff did not.
make sure it needs a strong login.the newer varient attempts to bruteforce logins on shares!
and will encrypt any drive mounted on the system.
i see too many backup drives killed by the same event that took out the system.
put the backup in the safe!