Notices

Overclockers Forums > Software > Microsoft Operating Systems
Microsoft Operating Systems Microsoft Operating Systems and Applications
Forum Jump

Virus that demands payment to decrypt your files.

Post Reply New Thread Subscribe Search this Thread
 
 
Thread Tools
Old 03-08-06, 10:17 PM Thread Starter   #1
jstutman

 
jstutman's Avatar 

Join Date: Oct 2001
Location: MOOissouri

10 Year Badge
 
Virus that demands payment to decrypt your files.


I was wondering if anyone else has run into this and if there is any hope for the client. I searched google for about an hour and found where one other person had been infected with it but no clues on how to fix it. Any help that can be give would be greatly appriciated. This might be a big hoax and all the guys files could have been deleted but I at least want to try to help him out.

The following is the contents of the txt file that was found on the computer:

Code:
OUR E-GOLD ACCOUNT: 2917497

INSTRUCTIONS HOW TO GET YUOR FILES BACK
READ CAREFULLY. IF YOU DO NOT UNDERSTAND, READ AGAIN.

This is automated report generated by auto archiving software.

Your computer catched our software while browsing illigal porn
pages, all your documents, text files, databases was archived
with long enought password.

You can not guess the password for your archived files - password
lenght is more then 10 symbols that makes all password recovery
programs fail to bruteforce it (guess password by trying all
possible combinations).

Do not try to search for a program what encrypted your information - it
is simply do not exists in your hard disk anymore.
If you really care about documents and information in encrypted files
you can pay using electonic currency $300.
Reporting to police about a case will not help you, they do not know
password. Reporting somewhere about our e-gold account will not help
you to restore files. This is your only way to get yours files back.

------------------------------

How to pay to get your information back.

1. click on this link to open your free e-gold account - the first
   screen is the e-gold "terms and conditions" page. You need to
   agree to these by clicking on the "I AGREE" button on the bottom
   on the page.
2. On the next page is the sign up form:
    1. "Account name" - here is where you name your account - tip:
        make it easy to remember (as you will be asked for it) and
     reasonably short, example, "John's e-gold", "My Money e-gold"
        or perhaps "Felix" (whatever you like, just make it easy for
        you to remember it).
    2. "User Name" - here just repeat the account name (from 1 above).
    3. "Point of Contact" - this is where you put our name, address,
        phone number and email address (any email address can be used
        here but it is recommended you use your ISP address - not a
        free hotmail, etc address).
        It is also recommended your also include a fax number
        (don't have a fax number? This company offers free fax to email
        services). Try and make it as easy as possible for e-gold to contact you.
    4. "Passphrase" - this is the most important piece of information
        connected to any e-gold account. We can not stress enough how
        important it is that your passphrase is kept safe and secure.
    5. "Turing Number Entry" - type the 6 numbers you see there into the input
        box below.
    6.  The last step click "Open"

On the next page it will tell you that your e-gold account number has been emailed to you.

check your email - you can expect to wait up to 5 minutes for your account number
to arrive. If it does not arrive after 5 minutes then that means the email address
you supplied was incorrect and you will have to open another new account (go through
and repeat what you just did above again).

To buy e-gold to your account please use official exchange services
http://www.me-gold.com/
http://www.goldex.net/
http://usece.com/

or try to search own way with
http://gold-pages.net/e-Gold__1MDC__Pecunix_Wizard_Links/Purchase_E-gold/index.html
http://www.google.com/search?hl=en&q=buy+e-gold&btnG=Google+Search

FINALLY when you bought e-gold you have to transfer $300 to our e-gold account.
In next 24 hours you will recieve $1 back to your account. Transfer details
of this $1 transfer will have a link to software that will automatically
unzip all your files back to normal state.

Next day login to your account https://www.e-gold.com/acct/login.html,
press History and press submit, you will see LINK TO UNZIP-software.

##########################################################################
Remember you are just $300 away from your files
##########################################################################
jstutman is offline   QUOTE Thanks
Old 03-08-06, 10:27 PM   #2
bchur83
Member



Join Date: Jan 2003
Location: Land of 10,000 Lakes

10 Year Badge
 
Thats funny. What else will they think of.

__________________
Main Rig: Asus P8Z68 Pro Gen3 * Core i7 2600K @ 4.4Ghz * 8GB (2x 4GB) Mushkin Blackline PC3-1600 * GeForce GTX 560TI 448 1280MB * 6TB Storage * LG BD/RW * Lian-Li PC-V2000B * Dell 24" 2407FPW & Asus 24" VS248H
Backup Rig: Gigabyte EP45-UD3P * C2Q Q9400 @ 3.2Ghz * 4GB (2x 2GB) G-Skill PC2-8000 * Sapphire Radeon 4870 512MB * 320GB Storage * Samsung SH-S203N DVD+/-RW * Apex Full Tower Case * 2x Dell 19" LCD
HTPC: Abit IP35PRO * C2D E6600 @ Stock * 2GB G-Skill PC6400 * Geforce 8600GT 256MB * 640GB Storage * Lite On 16x DVD-ROM * 55" Samsung 1080p 3D LED LCD via HDMI

Media Server: DFI Lanparty UT NF4 Ultra-D * A64 3800+ X2 * 1GB PC3200 * Powercolor X800XL * 14TB Storage * Lite On 16x DVD-RW

Heatware
bchur83 is offline   QUOTE Thanks
Old 03-08-06, 10:47 PM   #3
Randyman...
Member

 
Randyman...'s Avatar 

Join Date: May 2004
Location: Houston, TX

 
Wow. That is crappy! Sorry - no info, but that does suck... What to say but I hope you were backed up?


__________________
Randy V - Audio-Dude/Musician/PC Guru/Crazy Guy

PC#1 (Main Rig) : Lian Li PC-V1010 / P8Z68-V-GEN3 / 3750K @ 4.5GHz + Ven-X / 16GB G.Skill DDR3-1600 / HD5770 "XXX" 1GB / Samsung 830 256GB SSD / (6x) 2TB 5K3000 on Areca ARC1222 in RAID-6 / Seasonic X660 PSU / 2407WFP-HC / RME "Multiface" 38 Ch. Audio I/O / Dynaudio AIR-15 + AIR-BASE-2 Studio Monitors
PC#2 (Realtime DAW) : Lian-Li PC-K65B / Sabertooth X79 / i7-3820 @ 4.8GHz + TRUE / 8GB RipJaws DDR3-2133 / HD6570 / 120GB Intel 520 / 4x 1TB on Areca ARC-1210 in RAID-5 / RME "HDSPe MADI" 128 Channel Audio I/O / 2x SSL AlphaLink MADI AX / 48 Mic Inputs + Fully-discrete Mic Preamps + 4260Watt PA System with 5x 18" JBL Subs :-)
NAS#1: NSC-800 ITX Case / Asus P8H61-ITX / i3-2120 / (8x) 1TB 7200.12's in RAID-6 on Areca ARC-1220 Card
NAS#2: 12TB ReadyNAS Ultra-4+ / (4x) 3TB 5K3000's
And 7 other i7/i5/C2D/C2Q PC's
Randyman... is offline   QUOTE Thanks
Old 03-08-06, 11:00 PM   #4
nikhsub1
Unoriginal Macho Moderator

 
nikhsub1's Avatar 

Join Date: Oct 2001
Location: Los Angeles

10 Year Badge
 
Someone claims to have cracked it... see if works.

http://johnnyblanco.livejournal.com/

__________________
Loading Signature ...
nikhsub1 is offline   QUOTE Thanks
Old 03-08-06, 11:01 PM   #5
outhouse
Senior Member

 
outhouse's Avatar 

Join Date: Mar 2001
Location: Auburn California

 
dont pay whatever the client decides. This will not only teach the client to back-up, but to have good antivirus and spyware protection and a good firewall. His rig probably needed fomatting anyway.

__________________
GOODLUCK! p3 1g@1285 abit VH6-2 512,133corsair, lapped,ducted Gladiator radioshack compound gf3 ti 200 171FSB 2.10CV generic 10G 7200rpm hard drive xp\pro tdk 32x10x40 cdrw [2 years at 2.10]

p4 3.2e @ 4087, abit ic7-g, 1g corsair 4000 1to1 2x512, antec500w ps,lapped 3.2e, as5, bie, rbx ,maze 4 ,chip an gpu
leadtek 6800 U, 3dmark03 15,009 488/1.25 160 hd, tdk 32/10/40

XPS170 2g/cpu 2g/ram 60g/7200 rpm hd 7800gtx

8400@4g. 680i EVGA blackpearl. 4G ballistic 800mhz. RBX and inovatech NB. DDC BIX EVGA GTX260sc
outhouse is offline   QUOTE Thanks
Old 03-09-06, 10:37 AM   #6
DvBoard
Member

 
DvBoard's Avatar 

Join Date: Dec 2005
Location: Mars

 
Any lawyer would love to see this as they should most likely have a field day if the "company" is based in the US. If it's not then you will just have to get a better brute force cracker.

Whatever you do, DO NOT PAY. NEVER reward someone for this kinda **** by giving in.

__________________
*Dead* CPU:Intel Pentium 4 (Northwood) 2400MHz with the 533MHz Bus Speed.; Mobo:First International Computer, Inc. (FIC) Motherboard, model: VI13, Chipset: Sis645DX, BIOS: Phoenix Technologies, LTD version 6.00PG; GPU:ATi Radeon 9000Pro (128MB) Video card (4x AGP); RAM:1 stick 512MB PC2700 (166MHz) Xerox RAM; 1 stick 512MB PC3200 (200MHz) Corsair RAM; HD's:WD 250 Gig HD (x2); Optical:Lite-On DVD+/-RW, DVD-Rom; PSU:Antec SL400; OS:Windows XP

*Current Rig* CPU:E6600; Mobo:Asus P5B Deluxe; GPU:ATi Radeon HD 4870 w/1GB GDDR5 (PCI Express); RAM: (2 x 1GB) PC2-6400 DDR2 Corsair TWIN2X2048-6400PRO & (2 x 1GB) PC2-6400 DDR2 Corsair TWIN2X2048-6400; HD's:(2x 320GB) Seagate Barracuda 7200.10 SATA Drive & (2x 500GB) Seagate Barracuda 7200.11 SATA Drive & (2x 250GB) WD IDE Drive; Optical: Lite-on SATA DVD +/- RW & Lite-on IDE DVD +/- RW; PSU:Corsair 520HX; OS:XP; Case:Thermaltake Armor;
DvBoard is offline   QUOTE Thanks
Old 03-09-06, 10:45 AM   #7
cornbread
Member

 
cornbread's Avatar 

Join Date: Nov 2001
Location: The great USA!

10 Year Badge
 
Tell him to just take his losses and learn from his mistake, then reformat. I wouldn't pay anyone to fix that, especially the person that wrote the virus.

__________________
Microsoft Windows 7 Home Premium
Intel i5-2500 CPU @ 3.30GHz
10GB Memory
ATI Radeon HD 7570
cornbread is offline   QUOTE Thanks
Old 03-09-06, 11:24 AM   #8
nahmus
Member

 
nahmus's Avatar 

Join Date: Apr 2002
Location: Sailing the Azure seas

 
someone at this company wrote a decrypt. Send them an e-mail maybe they will send it to you

http://www.lurhq.com/

__________________
Shame on the night..... for places i've been and what i've seen... For giving me the strangest dreams - Dio(RIP)
nahmus is offline   QUOTE Thanks
Old 03-09-06, 11:44 AM   #9
FudgeNuggets
Member



Join Date: Mar 2006
Location: Gone Racing

 
I can tell from the way the language is written that it is from Russia or one of the former Soviet states. As far as any legal action goes, you're screwed. I'd try the decrypters mentioned above and if that didn't work I'd just pop in the XP CD and boot from it then reformat.
FudgeNuggets is offline   QUOTE Thanks
Old 03-09-06, 12:04 PM   #10
White Runner
Member

 
White Runner's Avatar 

Join Date: Jun 2005

 
Overclocker's don't negotiate with virtual terrorists.

__________________
Asrock Extreme4 Z68 / / / I7 2600K @ 4.5Ghz
Phanteks PH-TC14PE / / / DDR3-1600 2x8
2 x Gigabyte 7970's / / / Clocks 1150/1550
OCZ Vertex3 120GB / / / 2 x 4TB WD Black
Corsair HX850 PSU / / / Corsair 650D Case

\m/ OverClockers mATX L33T Club \m/ >>>JOIN NOW<<< .Heatware.
Folding User Stats
White Runner is offline Heatware Profile   QUOTE Thanks
Old 03-09-06, 12:08 PM   #11
mrgreenjeans
Member

 
mrgreenjeans's Avatar 

Join Date: May 2003
Location: Cleveland, GA

 
Yeah, these are just the guys I want to give my credit card number to. Where do I sign up?

Were files actually missing? And what files did it target? It'd almost have to be a common directory location I would think.

And any clue as to how he got it? Or is porn really bad for your financial health as well? Two strikes, gotta find a new vice, darn.

__________________
"A little bit of knowledge is a dangerous thing."
ASUS A8N32-SLI Deluxe bios 1009 w/FX-60 on a Zalman Resterator
Corsair 2048 TwinX3500LL matched dual channel 1:1 @ 2-3-3-6
BFG8800GTXwc768 DVI~Sharp Aquos LC-46D92U
BFG Ageia PhysX card
36g Raptor boot, 150g Velociraptor game drive, and 320g storage drive
LG GGC-H20L BR & HD
Auzentech xPlosion 5.1 ~ Sony DA3ES Receiver~ Infinity's
Silverstone LC-10m w/Silverstone Strider ST60 PSU
Win XP pro
mrgreenjeans is offline   QUOTE Thanks
Old 03-09-06, 01:08 PM   #12
Captain Newbie
Senior Django-loving Member

 
Captain Newbie's Avatar 

Join Date: Jan 2004
Location: Right seat with a bored "don't kill me" expression

 
Quote:
Originally Posted by White Runner
Overclocker's don't negotiate with virtual terrorists.
As George Carlin might say, "You're goddamn right!" Don't pay them. We do not negotiate with terrorists.

I will run down the websites mentioned in the message and get back to you, to see who they belong to, and where they are physically located. This information could be of value to both you and to law enforcement, should you choose to pursue this.

*starts hammering furiously at the keyboard*

edit: 10 character password? Eh, that's definitely not unbreakable...

__________________
B.S. Computer Science, B.A. Political Science | Commercial Pilot Airplane Single and Multiengine Land, Instrument Airplane
"And, while with silent lifting mind I've trod
The high untresspassed sanctity of space
Put out my hand, and touched the face of God."

Strong * Focused * Safe
Apple Mac Pro 4,1, Two Nehalem Xeons 2.26GHzx4 (Hyperthreaded), 12 GB DDR3 FBDRAM | MacBook Pro 15" (2009)
Captain Newbie is offline   QUOTE Thanks
Old 03-09-06, 06:38 PM   #13
El<(')>Maxi
Blank Senior Member

 
El<(')>Maxi's Avatar 

Join Date: May 2003
Location: Seattle

 
Have you checked to see if he really has no access to his files? Try the decrypt fixes mentioned and then backup & reformat his system. Everyone needs a good firewall & antivirus these days, without them you are always at risk.

Newbie,

The sites mentioned in the message have nothing to do with this person(s), the only thing that could be used to link to them is the e-gold account # which is proteced by e-gold. I think alot of illegal money is sent via that service.

__________________
rdrash - 'I'm gonna intentionally try to kill this CPU with more volts'
El<(')>Maxi is offline Author Profile   QUOTE Thanks
Old 03-09-06, 07:30 PM   #14
brakezone
Member

 
brakezone's Avatar 

Join Date: Jan 2004

 
well, if it is encrypted, depending upon how many bits of encryption, it could take awhile to crack.
brakezone is offline   QUOTE Thanks
Old 03-09-06, 08:20 PM   #15
AngelfireUk83
Member

 
AngelfireUk83's Avatar 

Join Date: Nov 2004
Location: England

 
"Reporting to police about a case will not help you, they do not know
password."

This part I think sounds like it's just been typed up by a hacker or fraudster "They do not know password". For a start that gives it away as too some stupid person who's trying to fraud money of of you.

DON'T PAY it's people like this which makes Identity fraud and trying to get money out of people rise everyday.

__________________
OS: Windows 7 Ultimate 64bit
Board: Gigabyte Z68AP-D3 Rev.1 F8
CPU: INTEL i7 2600k 3.40ghz (Stock)
RAM: Crucial Ballistix Elite 8GB 1866mhz DDR3 (1600mhz@1.60v)
Storage: Crucial 128GB M4 SSD (FW 040H)
Storage 2: Seagate 500GB 7,200rpm HDD
GPU/Audio: HIS 7850 2GB GDDR5 PCI-E Card (Stock)
PSU: OCZ Fatality 750w Modular PSU
Optical: LG GH24NS90 24x DVD-RW
AngelfireUk83 is offline   QUOTE Thanks
Old 03-10-06, 04:27 PM   #16
Captain Newbie
Senior Django-loving Member

 
Captain Newbie's Avatar 

Join Date: Jan 2004
Location: Right seat with a bored "don't kill me" expression

 
Quote:
Originally Posted by El<(')>Maxi
Have you checked to see if he really has no access to his files? Try the decrypt fixes mentioned and then backup & reformat his system. Everyone needs a good firewall & antivirus these days, without them you are always at risk.

Newbie,

The sites mentioned in the message have nothing to do with this person(s), the only thing that could be used to link to them is the e-gold account # which is proteced by e-gold. I think alot of illegal money is sent via that service.
Indeed, but any link at all is a start.

__________________
B.S. Computer Science, B.A. Political Science | Commercial Pilot Airplane Single and Multiengine Land, Instrument Airplane
"And, while with silent lifting mind I've trod
The high untresspassed sanctity of space
Put out my hand, and touched the face of God."

Strong * Focused * Safe
Apple Mac Pro 4,1, Two Nehalem Xeons 2.26GHzx4 (Hyperthreaded), 12 GB DDR3 FBDRAM | MacBook Pro 15" (2009)
Captain Newbie is offline   QUOTE Thanks

Post Reply New Thread Subscribe


Overclockers Forums > Software > Microsoft Operating Systems
Microsoft Operating Systems Microsoft Operating Systems and Applications
Forum Jump

Thread Tools Search this Thread
Search this Thread:

Advanced Search


Mobile Skin
All times are GMT -5. The time now is 03:58 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
You can add these icons by updating your profile information to include your Heatware ID, Benching Profile ID or your Folding/SETI profile ID. Edit your profile!
X

Welcome to Overclockers.com

Create your username to jump into the discussion!

New members like you have made this the best community on the Internet since 1998!


(4 digit year)

Why Join Us?

  • Share experience
  • Max out your hardware
  • Best forum members anywhere
  • Customized forum experience

Already a member?