Virus Warning - Cryptolocker

  • Thread starter Thread starter -
  • Start date Start date

The latest in a long line of 'Ransomware', the Cryptolocker Virus is a nasty example....ensure you take steps to protect yourself.

We had a client infected this week, they've literally lost all their MS Word and Excel documents, as they've all become encrypted as a result of this virus. There is no 'normal known repair tool' to get your files back (yet anyway), and without a Data Specialist or a proper Backup - you could have some serious problems.

It's new, it's nasty and whilst easy enough to remove....the side effects of leaving you with encrypted files is a horror.

We blogged about it today

BACKUP and keep your backed up files on a device external to your PC/network....or risk not having them.
 
This virus is nasty, it encrypts your files, getting rid of the virus is actually really easy, but it still leaves your files encrypted, at the moment the only way is to pay the ransom. Another reason why you should be backing up.
 
Upvote 0
can you backup everything including the virus, and they will encrypt your backups as well?
 
Upvote 0
If your PC sees a directory of files (whether it be a Network Shared Drive, a mapped Drive, an External drives, etc.......then the virus can see and encrypt them. Once encrypted, they are not openable regardless of which PC you try on.

The only way of ensuring your backups will be 'clean' is to ensure the files on there are not connected to your PC...ie keep them external (except when backing up), and keep an external copy while you backup a new one.

The virus itself won't hide for any length of time, you'll pretty much see it straight away, so providing you have a decent backup routine (grandfather, father, son, etc) you should be fine.

Paying them IS an option as someone said, but weould you like to label yourself to hackers/scammers as 'one who pays'? Or would you trust them not to have a backdoor to reinfect you again?

Paying them hasn't been an option with any I've seen, except one person who did....they have their files back after about a week...but no guarantees from that on either.

Nasty virus, nasty results....and this is the way things are heading with the old t'internet...so now's the time to review your internal procedures !!
 
Upvote 0
DR Web (link to correct section in my blog post) have had some success in cracking the encryption....but they've stopped offering the service to anyone other than their paying customers because of the quantity of enquiries....fair enough I suppose. I suppose you could just buy a product of theirs, then submit as if you were a customer.
 
Upvote 0
I was wondering that and will it be able to get my files on the SkyDrive?

If the sync'ing process lifts encrypted files off your PC, then it could affect your Skydrive alright. Before you allow any sync'ing, run a full scan with Malwarebytes or something to ensure there's notinhg untoward on there.
 
  • Like
Reactions: estwig
Upvote 0
... so providing you have a decent backup routine

I think this emphasises the need for version controlled backup that will allow recovery to a pre-infection state. Same is true of any other file corruption.

Offsite file storage is *not* backup, any more than RAID is. Two copies of an encrypted file you cannot unlock are of no more use than one.

BTW: Thanks for the heads up!
 
  • Like
Reactions: Comspec
Upvote 0
is this standard for a backup service?

For a backup service, as distinct from file storage, yes.

We keep 30 days worth as standard, can be more at client request, but we only backup for clients that buy other services.

As it happens a friend of mine has just launched a service open to allcomers:

http://runlevel.co.uk/

and there is also Lee Mason's service:

http://www.backupsanywhere.com/

Both of those are what I would call proper backup solutions rather than just file storage.
 
Upvote 0
I must admit, it's only at times of crisis (like a few have had this week) that I can get business customers to have a serious look at their backup provision. I harp on about it, but it falls on deaf ears.

This type of virus, and there have already been a load of variants, make it obvious to me that backups have to become a much more important procedure in any business reliant on their IT.....and the need to have clean backups available will become more and more important as this type of virus spreads.....and spread it will, since half the people are paying the criminals to get their files back.

I actually rang Action Fraud on Monday past, as I was grasping at straws trying to help a client....they weren't even aware of this virus, and I had to provide them with details on it.
 
Upvote 0
For a backup service, as distinct from file storage, yes.

We keep 30 days worth as standard, can be more at client request, but we only backup for clients that buy other services.

As it happens a friend of mine has just launched a service open to allcomers:

http://runlevel.co.uk/

and there is also Lee Mason's service:

http://www.backupsanywhere.com/

Both of those are what I would call proper backup solutions rather than just file storage.

This type of virus will always reveal itself within a day or two, so this type of service offered will always provide a clean copy of files.....getting that through and into customers heads can be difficult though.
 
Last edited:
Upvote 0
One other thing I didn't mention (apart from the fact that my typing has fallen to an ass, going by my previous posts), is the encrypted files themselves....
They do not change size at all, and their 'last modified' date doesn't change either, so it's not blatantly obvious which files have been corrupted, until you try to open them....and by then it's too late.

It did not affect the Sage Data files of a client thankfully, only the doc, xls, jpg, etc.

I really cannot stress enough how dangerous this virus is, and how it could seriously hurt some businesses.
 
Upvote 0

Latest Articles