• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Hostage ware, posted in GD for views!

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

Archer0915

"The Expert"
Joined
Nov 3, 2008
Ran into an issue with a PC that I was asked to fix! What happened?

There's a new iteration of malware going around that locks files and demands payment.

CryptoLocker - the name sounds like a legit encryption program but this is malicous software that encrypts Word docs and PhotoShop files and then demands the user pay $300 in bitcoins or risk having all the files on the computer cryptographically locked and lost forever. Have you received one of those phony FedEx or UPS tracking notifications? That's the way they're spreading this one.

Read more here:

http://www.ibtimes.com/cryptolocker...0-within-100-hours-threatens-encrypt?ft=61pb1

http://www.windowsecurity.com/blogs/shinder/new-hostageware-holds-files-ransom.html


Look, if you do not know who an email is from delete it or open it on a droid or something with no secure files on it.

Pay attention when installing third party software! These days you are hit with a barrage of crapware when you try to install a utility...

Only work with reputable sites!

Please add to this thread! Suggestion, tips...
 
Make regular backups of your data.

If you work in enterprise hope that there are shadow copies/snapshots of the storage volumes.
 
Make regular backups of your data.

If you work in enterprise hope that there are shadow copies/snapshots of the storage volumes.
Relying on shadow copies is not perfect, either. New versions of this software know that most filesystems will delete old snapshots when the volume starts getting full. I know at least one version will fill the volume with garbage data to force deletion of snapshots/shadow copies, then it encrypts the data. Whoops no backups!
 
Relying on shadow copies is not perfect, either. New versions of this software know that most filesystems will delete old snapshots when the volume starts getting full. I know at least one version will fill the volume with garbage data to force deletion of snapshots/shadow copies, then it encrypts the data. Whoops no backups!

Sync docs with a cloud service.
 
Not always a solution when you have HIPAA

A company can set up a private cloud. Not only store files on the server but on a cloud, off site, server (company server) as well.

Still best that people pay attention to what they are doing.
 
we keep full images of every machine at certain intervals, we have 2 yearly backups, 2 monthly's and 2 daily's. so we can go back a day 2 days, a month, two months, one year two years, if we need to.
has actually came in handy a couple times. very un necessary but we dont have a huge network at all. but better to be safe than sorry :shrug:

edit: at work^

at home... i just keep snapshots of my vm's on an external usb drive and a clonezilla image of my SSD on my server just incase.
 
Last edited:
for the home user, buy a cheap backup device and backup weekly, drive with backup sofware is only $75, all your family photos are priceless.
I use a toshiba cavino, it turns on and off with the rig and backs it up automagicly once set up, just get something please.
 
I use, well...

I have data redundancy (no good in situations like this), I have 2x external 2TB drives that are clones of each other for important data. Furthermore I use several cloud services that are redundant.
 
This has been around for years now and has plagued many many many many many a machine. Ransomware is a very annoying thing albeit quite ingenious for the creators getting those over the years to pay to release the "encryption".
 
Back