Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Decryption keys are now freely available for victims of CryptoLocker


  • Please log in to reply
217 replies to this topic

#46 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  •  Avatar image
  • Malware Response Instructor
  • 6,088 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:03:56 PM

Posted 19 November 2014 - 11:18 AM

I want to make something very clear to any users just now getting to this thread because they were infected by "CryptoLocker"! The real Cryptolocker has been down, and has not returned for awhile now! This means that what ever infection you have, is a new one Fake one! Before EVER considering paying for the ransom you should always make it first priority to ask on the thread first or PM any member to ask for help! Things that will help us identify your infection is Screenshots of any windows, The Ransom Note, and the EXE if you have it..

Nathan (DecrypterFixer), Security Colleague Post #3223


...For those of you emailing me about CryptoLocker: Stop. You do not have CryptoLocker, that infection has been dead for awhile and you most likely have TorrentLocker, or a copycat of some kind.

Nathan (DecrypterFixer), Security Colleague Post #3241
 
Information about a fake CryptoLocker can be found in this discussion topic: TorrentLocker Support and Discussion Thread (CryptoLocker copycat)

 

xXToffeeXx~


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


BC AdBot (Login to Remove)

 


#47 bradison

bradison

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:56 AM

Posted 25 November 2014 - 08:17 AM

Infection Detection Tool v1.6 - Nathan Scott -------------------------------------------- Date/Time: 11/25/2014 7:59:59 AM Operating System: Windows 7 Service Pack: Service Pack 1 Version Number: 6.1 Product Type: Workstation -------------------------------------------- [Detected Flags] 1.| Possible CryptoWall Flag , HKCU\Software\AD8F25D1305DB699C22D34C42CE7C315\1222334457CCCCDE

#48 adrian432

adrian432

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:56 AM

Posted 14 December 2014 - 07:37 PM

One of our users recently got some form of this malware, all of his files were changed to a .umjdpuf extension.  Its even effected some of the files on a network drive he connected to.  Is there anything I can use or try to decrypt the files? I tried https://www.decryptcryptolocker.com/ but it fails to detect anything. Thanks. 



#49 TechnicianOnline

TechnicianOnline

  •  Avatar image
  • Members
  • 125 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Online
  • Local time:06:56 AM

Posted 17 January 2015 - 03:14 PM

This paired with Foolibleep is pretty awesome, it's been a few months since I hear of Cryptolocker but man it was a pain in the butt if they didn't have any backups.


A Network isn't something you 'own' or 'have'; you may only wield it like the sword of Excalibur.


#50 boxer68

boxer68

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:56 PM

Posted 20 January 2015 - 06:13 PM

Infection Detection Tool v1.6 - Nathan Scott -------------------------------------------- Date/Time: 11/25/2014 7:59:59 AM Operating System: Windows 7 Service Pack: Service Pack 1 Version Number: 6.1 Product Type: Workstation -------------------------------------------- [Detected Flags] 1.| Possible CryptoWall Flag , HKCU\Software\AD8F25D1305DB699C22D34C42CE7C315\1222334457CCCCDE

I have the same problem  !!!!! 

 

Infection Detection Tool v1.6 - Nathan Scott
--------------------------------------------
Date/Time: 20/01/2015 23:45:09
Operating System: Windows 7
Service Pack: Service Pack 1
Version Number: 6.1
Product Type: Workstation
--------------------------------------------
[Detected Flags]
1.|  Possible CryptoWall Flag , HKCU\Software\B83FEF0C208EDDF4393F07BAFB4B817D\013347789ABBBDFF


#51 Nathan

Nathan

    DecrypterFixer


  •  Avatar image
  • Security Colleague
  • 1,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:56 AM

Posted 20 January 2015 - 06:25 PM

? The tool is telling you that you have the CryptoWall infection, not Cryptolocker. Please use the thread that the tool provides for you for support / info.


Have you performed a routine backup today?

#52 boxer68

boxer68

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:56 PM

Posted 21 January 2015 - 09:11 AM

Thanks Nathan

#53 SabiW

SabiW

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:56 AM

Posted 21 January 2015 - 09:57 PM

Ok, just read a few of the threads, and still have all our files locked.  Here is a copy of the html page that pops up:

WARNING

We have encrypted your files with CryptoLocker virus

Your important files (including those on the network disk(s), USB, etc): photos, videos, documents etc. were encrypted with CryptoLocker virus. The only way to get your files back is to buy our decryption software. 

Caution: Removing of CryptoLocker will not restore access to your encrypted files. The only way to save your files is to buy a decryption software. Otherwise, your files will be lost.

Can you please advise if there is a decryption tool now?

 

Thanks

 

Sabina



#54 waelonly1

waelonly1

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:56 PM

Posted 29 January 2015 - 05:16 AM

My PC has been infected by CTB-cryptolocker... I have tried getting the decryption key through the site: www.decryptolocker.com; however, it couldn't detect that the uploaded file is encrypted by cryptolocker and it's returning the message "please upload a file that is encrypted by cryptolocker". Please advise... Thanks



#55 LiquidTension

LiquidTension

  •  Avatar image
  • Malware Response Team
  • 1,278 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:56 PM

Posted 30 January 2015 - 04:16 AM

Hello, 
 

My PC has been infected by CTB-cryptolocker... I have tried getting the decryption key through the site: www.decryptolocker.com; however, it couldn't detect that the uploaded file is encrypted by cryptolocker and it's returning the message "please upload a file that is encrypted by cryptolocker". Please advise... Thanks

CTB Locker is not CryptoLocker, so uploading files to www.decryptolocker.com will not work. 
 
Please see the following for information on CTB Locker:
http://www.bleepingcomputer.com/forums/t/546045/new-critroni-variant-offers-free-test-decryption-and-now-uses-ctb2-extension/
http://www.bleepingcomputer.com/virus-removal/ctb-locker-ransomware-information
http://www.bleepingcomputer.com/forums/t/542564/ctb-locker-or-decryptallfilestxt-encrypting-ransomware-sets-extension-to-ctbl/
http://malware.dontneedcoffee.com/2014/07/ctb-locker.html


Posted Image

#56 romina52

romina52

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:56 PM

Posted 05 February 2015 - 07:14 AM

HELP ME

THE INFECTED FILE HAVE THIS EXTENSION: .enpzmmg

 

PROGRAM WHICH I HAVE TO DOWNLOAD TO TRY TO REPAIR MY FILE ?

PLEASE HELP ME



#57 JUNGLEJIM04

JUNGLEJIM04

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:56 AM

Posted 26 April 2015 - 11:39 AM

I was originally infected with the first crytolocker virus in October of 2013. I seemed to be AHEAD of the wave. My IT guy stays on top of it, and we made big mistakes trying to repair. Months went by, and I just waited for a decryption tool to arrive. After 6 months I gave up. recently I found out that I had missed out on the decryption solution by a couple of months.

I have recently utilized the free service to isolate my key. It works, I have successfully unlocked five types of files.

the problem I have today, is that I missed out on the big wave of people repairing drives, I have seen a couple of GUI interfaces that allow multiple files to be loaded to be decrypted, however, with the new wave of virus' I cannot find a place to download this GUI.

I have over 23,000 encrypted files. The one at a time method is just not going to cut it.

Could someone please post a CURRENT link to a mass decryption routine please.

I have the ORIGINAL virus. I HAVE the key. I just need a program to mass apply the key.

Seems the FALSE positives, have rendered my attempts to get back on the curve pretty tough.

#58 Nathan

Nathan

    DecrypterFixer


  •  Avatar image
  • Security Colleague
  • 1,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:10:56 AM

Posted 26 April 2015 - 01:59 PM

shoot me at email at nscott@easysyncsolutions.com and ill get u a link to the GUI app I made for it, if that's what ur referring to


Have you performed a routine backup today?

#59 HugoL3

HugoL3

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:56 PM

Posted 09 July 2015 - 04:06 AM

Hello,

 

I have a lot of infected files and i don't have any idea how to fix them. Decryptolocker page doesn't have menu to upload files... What can I do? I have files in DLSZTNF format. Please, give me some advices... My computer is clear now.

 

Best regards,

Kamil



#60 Aura

Aura

    Bleepin' Special Ops


  •  Avatar image
  • Malware Response Team
  • 19,709 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:56 AM

Posted 09 July 2015 - 05:39 AM

Hi HugoL3 :)

You have been infected with a different Cryptoware called CTB-Locker (or one of it's variant). The current support thread for it can be found below.

CTB Locker or DecryptAllFiles.txt Encrypting Ransomware sets extension to .CTBL

If you want to know more about CTB-Locker, you can read the FAQ hosted on BleepingComputer.

CTB Locker and Critroni Ransomware Information Guide and FAQ

animinionsmalltext.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users