Become a Site Supporter and Never see Ads again!

Author Topic: Ransomeware _ENCRYPT  (Read 4106 times)

0 Members and 1 Guest are viewing this topic.

Offline waltmon

  • Trade Count: (14)
  • Needs to get out more...
  • *****
  • Posts: 2045
  • Gender: Male
Ransomeware _ENCRYPT
« on: February 02, 2015, 05:24:53 PM »
i think I picked up this virus when I downloaded 2 seasons of Vikings.  I've been fighting malware since...I deleted all of the suspect movie files...

  Now this _ENCRYPT  crap has infected pretty much all music on my laptop...fortunately didn't hit peripheral drives.  Reading on several fixes...any thoughts on the most reliable? 

  I'm hearing take it back to a restore point prior to infection...THEN apply malware.  I have malwarebytes, cc cleaner, adaware, and superspyware cleaner...none of the audio files play...I don't see myself paying a ransome to these hacks.
KM140's, KM150's, U89's, Mixpre-10T II, 788T, F3

CA-14 > UBB > Tascam DR-2D

1 pound non-sequential $50.00 bills

Offline Ultfris101

  • Site Supporter
  • Trade Count: (15)
  • Taperssection Member
  • *
  • Posts: 764
  • Gender: Male
  • Spoon!!!
Re: Ransomeware _ENCRYPT
« Reply #1 on: February 02, 2015, 08:25:38 PM »
That sucks. It's probably worth trying the restore point path, but honestly I would wipe the computer as clean as I can and reinstall everything. This kind of stuff can be very difficult to fully eradicate. A lot of times the restore points apply to system files and files a program changed when it was being installed but not data files. I would be surprised if it fixes any of the encrypted media files but it might I suppose if it's a backup and not just a system restore point.

I'd definitely like to hear how it goes. I've heard about this but don't know anybody with first hand experience.

Out of curiosity, did you have any anti-virus or other security software of any kind installed (aside from the anti malware stuff you are planning to install now) and in use prior to this? I'm assuming this is Windows.
Mics: Schoeps MK5,MK41 CMC6,KCY,KC5 | AKG ck63,ck1 C460B,C480B | DPA 4061 | Naiant X-R card,hyper | CA-14o,c
Pres: Sound Devices USBPre2 | Naiant Tinybox | Church Audio 9200, UBB
Recs: Zoom F8 | Edirol R-44 | Sony PCM-M10 | Tascam DR-2d
Video: Sony CX550(2), CX580, HX9

LMA: http://archive.org/bookmarks/ultfris101

Offline Fatah Ruark (aka MIKE B)

  • Trade Count: (11)
  • Needs to get out more...
  • *****
  • Posts: 9945
  • Gender: Male
  • I dream in beige.
    • sloppy.art.ink
Re: Ransomeware _ENCRYPT
« Reply #2 on: February 02, 2015, 09:54:50 PM »
The ONLY safe way to get rid of malware is to wipe EVERYTHING and recover from a backup NOT connected to the computer.

If you're going to download illegal downloads I would avoid public sites like the Pirate Bay. Private sites are safer, but you're still taking your chances.
||| MICS:  Beyer CK930 | DPA 4022 | DPA 4080 | Nevaton MCE400 | Sennheiser Ambeo Headset |||
||| PREAMPS: DPA d:vice | Naiant Tinybox | Naiant IPA |||
||| DECKS: Sound Devices MixPre6 | iPod Touch 32GB |||
|||Concert History || LMA Recordings || Live YouTube |||

Offline waltmon

  • Trade Count: (14)
  • Needs to get out more...
  • *****
  • Posts: 2045
  • Gender: Male
Re: Ransomeware _ENCRYPT
« Reply #3 on: February 03, 2015, 12:18:18 AM »
Symantec detected nothing nor did any of the malware programs...further inquiries stated that the ransomeware is piggybacking on Adobe updates somehow. I guess Adobe reported they fixed the issue and that apparently was crap...

  I was getting repeated requested to update Adobe. ..guessing it started there.
KM140's, KM150's, U89's, Mixpre-10T II, 788T, F3

CA-14 > UBB > Tascam DR-2D

1 pound non-sequential $50.00 bills

ilduclo

  • Guest
  • Trade Count: (0)
Re: Ransomeware _ENCRYPT
« Reply #4 on: February 03, 2015, 07:22:49 AM »

Offline buckster

  • Trade Count: (0)
  • Taperssection Regular
  • **
  • Posts: 183
  • Gender: Male
Re: Ransomeware _ENCRYPT
« Reply #5 on: February 03, 2015, 12:49:07 PM »
Over at Bleeping Computer they have this information on an encryption ransomware: http://www.bleepingcomputer.com/virus-removal/coinvault-ransomware-information.  The last time I dealt with ransomware there were off the shelf tools available to easily take care of it; however, it seems the bad guys have seriously stepped up their game and there's no malware removal tool currently available that can undo the encryption.  So unless you have a backup to resort to, you're screwed. 

If you scroll down that article you'll see there is a free prevention tool available: 

Quote
How to use the CryptoPrevent Tool:

FoolishIT LLC was kind enough to create a free utility called CryptoPrevent that automatically adds the suggested Software Restriction Policy Path Rules listed above to your computer. This makes it very easy for anyone using Windows XP SP 2 and above to quickly add the Software Restriction Policies to your computer in order to prevent CoinVault and Zbot from being executed in the first place. This tool is also able to set these policies in all versions of Windows, including the Home versions.
 

The CryptoPrevent Tool is located here http://www.foolishit.com/

Offline Ultfris101

  • Site Supporter
  • Trade Count: (15)
  • Taperssection Member
  • *
  • Posts: 764
  • Gender: Male
  • Spoon!!!
Re: Ransomeware _ENCRYPT
« Reply #6 on: February 03, 2015, 12:52:30 PM »
The CryptoPrevent Tool is located here http://www.foolishit.com/

"foolishit" ~= "full of shit".  hmmmm
Mics: Schoeps MK5,MK41 CMC6,KCY,KC5 | AKG ck63,ck1 C460B,C480B | DPA 4061 | Naiant X-R card,hyper | CA-14o,c
Pres: Sound Devices USBPre2 | Naiant Tinybox | Church Audio 9200, UBB
Recs: Zoom F8 | Edirol R-44 | Sony PCM-M10 | Tascam DR-2d
Video: Sony CX550(2), CX580, HX9

LMA: http://archive.org/bookmarks/ultfris101

Offline flipp

  • resident curmudgeon
  • Trade Count: (17)
  • Needs to get out more...
  • *****
  • Posts: 4285
Re: Ransomeware _ENCRYPT
« Reply #7 on: February 03, 2015, 01:24:52 PM »
The CryptoPrevent Tool is located here http://www.foolishit.com/

"foolishit" ~= "full of shit".  hmmmm

I prefer either of the following two readings

foolish IT   or
fool is hit

Offline Ultfris101

  • Site Supporter
  • Trade Count: (15)
  • Taperssection Member
  • *
  • Posts: 764
  • Gender: Male
  • Spoon!!!
Re: Ransomeware _ENCRYPT
« Reply #8 on: February 03, 2015, 01:34:43 PM »
Yes I'd assume it is an attempt at "Foolish IT", but how much better is that? "Foolish" as in the Motley Fool?

I'm not going to visit that site from my work computer to check it out.

Just makes me wary. "Here, install this and you'll never have to worry about ransomware. Just need to make a couple simple registry changes. We're the good guys."
Mics: Schoeps MK5,MK41 CMC6,KCY,KC5 | AKG ck63,ck1 C460B,C480B | DPA 4061 | Naiant X-R card,hyper | CA-14o,c
Pres: Sound Devices USBPre2 | Naiant Tinybox | Church Audio 9200, UBB
Recs: Zoom F8 | Edirol R-44 | Sony PCM-M10 | Tascam DR-2d
Video: Sony CX550(2), CX580, HX9

LMA: http://archive.org/bookmarks/ultfris101

Offline 2manyrocks

  • Trade Count: (12)
  • Taperssection All-Star
  • ****
  • Posts: 1664
Re: Ransomeware _ENCRYPT
« Reply #9 on: February 03, 2015, 06:58:35 PM »
I think we are headed towards the day when a junk PC will be used to connect to the internet and important files are kept only on a standalone PC. 

Offline Gene Poole

  • Trade Count: (1)
  • Taperssection Regular
  • **
  • Posts: 104
Re: Ransomeware _ENCRYPT
« Reply #10 on: February 03, 2015, 07:20:01 PM »
I think we are headed towards the day when a junk PC will be used to connect to the internet and important files are kept only on a standalone PC.

Just use linux.

Offline Gordon

  • Trade Count: (22)
  • Needs to get out more...
  • *****
  • Posts: 11783
  • Gender: Male
    • my list
Re: Ransomeware _ENCRYPT
« Reply #11 on: February 22, 2015, 10:21:38 AM »
Yes I'd assume it is an attempt at "Foolish IT", but how much better is that? "Foolish" as in the Motley Fool?

I'm not going to visit that site from my work computer to check it out.

Just makes me wary. "Here, install this and you'll never have to worry about ransomware. Just need to make a couple simple registry changes. We're the good guys."

He is 100% legit! I run a computer repair business and use many of the tools Nick (foolishit) makes. I implement CryptoPrevent on every machine I service.

Edit: ransomeware and lots of other malware installs itself in the appdata folder.  CryptoPrevent simply creates a group policy to block items from installing in that directory. utorrent and spotify are the only legit things I know of that load their exe files in that location. You can easily white-list them so they will install and work.
« Last Edit: February 22, 2015, 10:26:45 AM by Gordon »
Microtech Gefell M20 or M21 > Nbob actives > Naiant PFA > Sound Devices MixPre-6 II @ 32/48

https://archive.org/details/fav-gordonlw

https://archive.org/details/teamdirtysouth

Offline it-goes-to-eleven

  • Trade Count: (58)
  • Needs to get out more...
  • *****
  • Posts: 6696
Re: Ransomeware _ENCRYPT
« Reply #12 on: February 22, 2015, 04:37:31 PM »
I think we are headed towards the day when a junk PC will be used to connect to the internet and important files are kept only on a standalone PC.

Another option is to run your browser in a virtual machine or sandbox.  Of course those can run on Linux, with any version of windows, or macos, running under linux.  Though nothing is completely foolproof - there is malware that breaks out of virtual machines.

The other huge advantage of a virtual machine is the ability to run an old copy of windows, say XP, on much newer hardware. You can also save the image of that OS and move it to new computers in the future. It saves the OS installation drama.

If you'd like to play with free virtual machine software, I recommend virtualbox.  It is quite easy to use.

https://www.virtualbox.org/wiki/Downloads

 

RSS | Mobile
Page created in 0.099 seconds with 37 queries.
© 2002-2024 Taperssection.com
Powered by SMF