Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Do I have a new variant of Cryptolocker? A copycat, maybe?

  • Please log in to reply
2 replies to this topic

#1 syndac


  • Members
  • 7 posts
  • Local time:12:52 AM

Posted 26 March 2014 - 01:34 PM

I think I may have run into a new variant of Cryptolocker. This one doesn't change the wallpaper, renames all targeted extensions to .CRYPTOLOCKER, and seems to have more limited registry entries. Unfortunately, it also doesn't seem to work with the Tor site, f2d2v7soksbskekh.onion/ -- it gives an error that the uploaded file is not encrypted, even though I've tried 5-6 different files. I've paid the BTC ransom, but it's been 24 hours and still no decryption. Any ideas how to fix this? I'm happy to upload whatever is needed. See pictures for more info:









I'm on a Windows 7 x64 machine. This affected both my machine, the server it's connected to, and 2 different USB backup drives (we swap them out every Friday/Monday, which means this started working before Friday--although we didn't notice it until Monday).

BC AdBot (Login to Remove)


#2 noknojon


  • Banned
  • 10,871 posts
  • Gender:Not Telling
  • Local time:05:52 PM

Posted 27 March 2014 - 04:21 AM

Hello -


CryptoLocker Ransomware Information Guide and FAQ from our FAQ files.

Please read and post all questions here Cryptolocker Hijack program <= Our current running topic on Cryptolocker.

Sorry but we prefer to keep all of this in one topic (we do hope you understand :) ).

#3 quietman7


    Bleepin' Janitor

  • Global Moderator
  • 52,047 posts
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:52 AM

Posted 28 March 2014 - 05:31 AM

Since this infection is so widespread, rather than have everyone start individual topics, it would be best (and more manageable for staff) if you posted any questions or comments in that topic discussion link provided by noknojon.

If you only need removal instructions, refer to Malwarebytes Anti-Malware Removal instructions for CryptoLocker.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users