# Don't get this virus vCryptolocker

**URL:** <https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252>\
**Category:** NYSpeed Off Topic\
**Created:** [October 11, 2013, 4:21am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252 "2013-10-11T04:21:42Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 4:21am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/1 "2013-10-11T04:21:42Z")

</div>

Cliffs: virus encrypts \*.odt, \*.ods, \*.odp, \*.odm, \*.odc, \*.odb, \*.doc, \*.docx, \*.docm, \*.wps, \*.xls, \*.xlsx, \*.xlsm, \*.xlsb, \*.xlk, \*.ppt, \*.pptx, \*.pptm, \*.mdb, \*.accdb, \*.pst, \*.dwg, \*.dxf, \*.dxg, \*.wpd, \*.rtf, \*.wb2, \*.mdf, \*.dbf, \*.psd, \*.pdd, \*.eps, \*.ai, \*.indd, _.cdr, ???.jpg, ???.jpe, img\__.jpg, \*.dng, \*.3fr, \*.arw, \*.srf, \*.sr2, \*.bay, \*.crw, \*.cr2, \*.dcr, \*.kdc, \*.erf, \*.mef, \*.mrw, \*.nef, \*.nrw, \*.orf, \*.raf, \*.raw, \*.rwl, \*.rw2, \*.r3d, \*.ptx, \*.pef, \*.srw, \*.x3f, \*.der, \*.cer, \*.crt, \*.pem, \*.pfx, \*.p12, \*.p7b, \*.p7c, \*.pdf, \*.tif and you can’t recover the key only way to decrypt is pay $300

[http://computertutorflorida.com/2013/09/cryptolocker-ransomware-means-changes-to-our-backup-process/](http://computertutorflorida.com/2013/09/cryptolocker-ransomware-means-changes-to-our-backup-process/)

> **[r/sysadmin - Proper Care & Feeding of your CryptoLocker Infection: A rundown on...](https://www.reddit.com/r/sysadmin/comments/1mizfx/proper_care_feeding_of_your_cryptolocker/)**
>
> 592 votes and 544 so far on reddit

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 11, 2013, 4:27am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/2 "2013-10-11T04:27:42Z")

</div>

too late

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 4:32am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/3 "2013-10-11T04:32:10Z")

</div>

Depending on the dropper this could stop it

"to block this infection from running on other computers on your computer.

You can use Software Restriction Policies to block executables from running when they are located in the %AppData% folder, or any other folder, which this thing launches from. See these articles from MS:

[http://support.microsoft.com/kb/310791](http://support.microsoft.com/kb/310791)  
[http://technet.microsoft.com/en-us/library/cc786941(v=ws.10).aspx](http://technet.microsoft.com/en-us/library/cc786941(v=ws.10).aspx)

This can also be setup in group policy 🙂

File paths of the infection are:

C:\Users\User\AppData\Roaming{213D7F33-4942-1C20-3D56=8-1A0B31CDFFF3}.exe (Vista/7/8)  
C:\Documents and Settings\User\Application Data{213D7F33-4942-1C20-3D56=8-1A0B31CDFFF3}.exe

So the path rule you want to setup is:

Path: %AppData%\*.exe  
Security Level: Disallowed  
Description: Don’t allow executables from AppData.

With the bundling of Zbot with Cryptolocker, it is now also recommend that you create a rule to block executables running from a subfolder of %AppData%. This can be done with this path rule:

Path: %AppData%\*\*.exe  
Security Level: Disallowed  
Description: Don’t allow executables from immediate subfolders of AppData.  
"

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [October 11, 2013, 4:37am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/4 "2013-10-11T04:37:13Z")

</div>

Good info…surprised it uses the same GUID all the time.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 4:39am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/5 "2013-10-11T04:39:01Z")

</div>

If you get this you’re best of paying the $300 then disputing the charge with your CC company.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [October 11, 2013, 4:44am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/6 "2013-10-11T04:44:44Z")

</div>

Also keep in mind %AppData% variable directs to C:&lt;blahblahblah\>\AppData\Roaming in Vista+. I’ve seen a few different viruses operate in AppData\Local as well.

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [October 11, 2013, 4:54am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/7 "2013-10-11T04:54:25Z")

</div>

Time to make a quick backup of my source and unplug my external drive before one of the geniuses over in support opens some random email attachment.

---

<div class="post-metadata">

**Author:** ![Gus](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/gus/32/5112_2.png) [@Gus](https://forums.speedlife.net/u/Gus)\
**Post date:** [October 11, 2013, 5:27am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/8 "2013-10-11T05:27:07Z")

</div>

I just read through this… Sent info to privacy and security to look at. Good idea to restrict through GPO, as I can’t think of any applications that require %appdata% as a file path for executable’s.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 5:37am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/9 "2013-10-11T05:37:36Z")

</div>

On the downside you could probably do all this in memory and avoid that application folder entirely.

PS Powershell is the greatest thing to help hackers in a long time :lol:

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [October 11, 2013, 6:48am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/10 "2013-10-11T06:48:00Z")

</div>

GPO in place and email sent out:

> There have been some recent findings on a new virus making it’s rounds to PCs. The virus is called CryptoLocker and is classified as “Ransomware”. This particular virus will encrypt almost all files on a computer and make them inaccessible to you unless a Ransom is paid (ransom varies between $100 and $300). If you don’t pay ransom, the files are irrecoverable and lost forever.

> As always you should make backups of your important files. There are numerous online backup sites like DropBox, Microsoft SkyDrive, Box, Carbonite, etc. You can also purchase physical media for backups such as USB Flash drives or Hard drives.

> Please make sure you check your emails carefully, especially ones with attachments. Verify that you know the sender and are expecting an email that may contain an attachment. If the email looks suspicious and/or contains a ZIP file attachment, please use extra caution. If you’re unsure of an email please contact the Helpdesk (Helpdesk@\*) for assistance before you open it.

---

<div class="post-metadata">

**Author:** ![itsJim](https://avatars.discourse-cdn.com/v4/letter/i/c67d28/32.png) [@itsJim](https://forums.speedlife.net/u/itsJim)\
**Post date:** [October 11, 2013, 6:56am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/11 "2013-10-11T06:56:29Z")

</div>

You should (hopefully) be able to use [http://www.shadowexplorer.com/](http://www.shadowexplorer.com/) to recover any files it encrypts (If you have previous versions enabled).

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [October 11, 2013, 7:05am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/12 "2013-10-11T07:05:30Z")

</div>

We have VSS on our shared folders.

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 11, 2013, 7:29am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/13 "2013-10-11T07:29:53Z")

</div>

> [@LZ](#):
>
> If you get this you’re best of paying the $300 then disputing the charge with your CC company.

You’re going to give a miscreant your credit card number? Have fun with that…

- 
  - 
    - Updated - - -

I wonder if you could capture the key by running a pcap on a freshly infected machine. If it pulls it down from C&C, it’s plausible.

Either way, we’re not fucking with that. We are recovering from snapshots and mounting read-only until this mess is under control.

BTW, if anyone reputable wants some samples, hit me up. We had a second round of messages come through this morning and I am currently working on getting my hands on the binary. Luckily forefront is swallowing some of them up from today, but we’re pulling them down from the quarantine folder there now.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [October 11, 2013, 7:39am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/14 "2013-10-11T07:39:53Z")

</div>

^What A/V?

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 11, 2013, 7:40am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/15 "2013-10-11T07:40:51Z")

</div>

Mostly McAfee (we’re in the middle of migrating to Symantec)… Also have spoke with another reputable university that is a large McAfee shop and they got hosed.

---

<div class="post-metadata">

**Author:** ![Gus](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/gus/32/5112_2.png) [@Gus](https://forums.speedlife.net/u/Gus)\
**Post date:** [October 11, 2013, 7:53am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/16 "2013-10-11T07:53:27Z")

</div>

Any stories of this seriously messing up a company/university?

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 11, 2013, 8:28am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/17 "2013-10-11T08:28:32Z")

</div>

I work for Duke University Medical Center…

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 8:31am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/18 "2013-10-11T08:31:24Z")

</div>

> [@boardjnky4](#):
>
> You’re going to give a miscreant your credit card number? Have fun with that…

Do you even fucking read? lol

You pay with Green Dot - MoneyPak

Another alternate method is paying then telling greendot the wrong person redeemed the money

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [October 11, 2013, 8:38am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/19 "2013-10-11T08:38:52Z")

</div>

> [@LZ](#):
>
> Do you even fucking read? lol
> 
> You pay with Green Dot - MoneyPak
> 
> Another alternate method is paying then telling greendot the wrong person redeemed the money

yeah good point, just being snarky… but still, your credit card company isn’t likely to take kindly to your request seeing as how you really did authorize the payment… Worth a shot I suppose.

Just got done looking at today’s binary. New signature, same behavior…

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [October 11, 2013, 8:44am UTC](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252/20 "2013-10-11T08:44:17Z")

</div>

This is public key encryption

If the key pair is generated on the server and public key is sent and used to encrypt you can only decrypt with the private key on the server that is never transferred to the infected machine.

[Next page](https://forums.speedlife.net/t/dont-get-this-virus-vcryptolocker/233252.md?page=2)
