Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

New CryptoTorLocker2015 Ransomware discovered and easily decrypted


  • Please log in to reply
40 replies to this topic

#16 Nathan

Nathan

    DecrypterFixer


  •  Avatar image
  • Security Colleague
  • 1,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:09:18 AM

Posted 11 February 2015 - 08:21 PM

upload a zip file with a encrypted file and ur ransom note, and email it to decryptorbit@outlook.com with the subject "cryptotorlocker 2015" and ill take a look. You prob. Were infected with a different variant.


Have you performed a routine backup today?

BC AdBot (Login to Remove)

 


#17 minimel

minimel

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 11 February 2015 - 08:21 PM

Hi Lawrence,

 

I've just been hit with the CryptoLocker virus (strain unknown, I'm not IT proficient, can't figure out how to paste screenshot of virus warning, sorry!)

 

I also finally clicked on their ransom website (only got an apparent 69hrs left to pay $640AUD/3bitcoins - don't have that disposable cash but desperately need my work files back..I work from home).

 

I've tried to initiate Nathan's Decrypter app (thanks so much!) but I'm unable to go further with it. Does this mean my viral strain is not the new CryptoTorLocker2015 or I'm doing something simply wrong? I've downloaded & uncompressed the zip file and when I try to open/start it, nothing happens and I'm unsure what to do next.

 

I also tried various files on the FireEye decryptor but that too doesn't work, assumably it's for the original strain. Message warns that my files aren't affected.

 

Any ideas?

 

Would appreciate any help you can provide. Am desperately running out of time and eating into my work time!



#18 minimel

minimel

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 11 February 2015 - 08:24 PM

upload a zip file with a encrypted file and ur ransom note, and email it to decryptorbit@outlook.com with the subject "cryptotorlocker 2015" and ill take a look. You prob. Were infected with a different variant.

Gee that was quick! Thanks so much Nathan, am doing it now.



#19 Nathan

Nathan

    DecrypterFixer


  •  Avatar image
  • Security Colleague
  • 1,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:09:18 AM

Posted 11 February 2015 - 08:28 PM

minimel,

640 sounds like torrent locker (also named crypto locker), please search for torrentlocker on this site for more info.


Have you performed a routine backup today?

#20 Comptech72

Comptech72

  •  Avatar image
  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:08:18 AM

Posted 11 February 2015 - 08:45 PM

What Causes this in the first place? 



#21 rgranada

rgranada

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:18 PM

Posted 11 February 2015 - 09:19 PM

Hello Nathan,

 

I've also infected with this crypto locker... where can I send my sample infected files?



#22 minimel

minimel

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 11 February 2015 - 09:20 PM

Thanks again Nathan for all your help, really appreciate it, and how quickly you responded :)

 

Will start reading up on torrentlocker now and see what I can find..

 

Cheers



#23 trucker2838

trucker2838

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:18 AM

Posted 11 February 2015 - 09:45 PM

Hi this is what I get when I tried to unzip it 

 

Category: Trojan
 
Description: This program is dangerous and executes commands from an attacker.
 
Recommended action: Remove this software immediately.
 
Items: 
containerfile:C:\Users\sam\AppData\Local\Temp\Rar$EX00.438\CryptoTorLocker2015_Decrypter.exe
containerfile:C:\Users\sam\Downloads\CT2015_Decrypter.zip
file:C:\Users\sam\AppData\Local\Temp\Rar$EX00.438\CryptoTorLocker2015_Decrypter.exe->[MSILRES]
file:C:\Users\sam\Downloads\CT2015_Decrypter.zip->CryptoTorLocker2015_Decrypter.exe->[MSILRES]
webfile:C:\Users\sam\Downloads\CT2015_Decrypter.zip|http://ransomwareanalysis.com/CT2015_Decrypter.zip
 
Get more information about this item online.
Ransom:Win32/Genasom.FO

Microsoft security software detects and removes this threat.

This ransomware can stop you from using your PC or accessing your data. It might ask you to pay money to a malicious hacker.

Our 

Microsoft security software detects and removes this threat.

This ransomware can stop you from using your PC or accessing your data. It might ask you to pay money to a malicious hacker.

Our ransomware page has more information on this type of threat



#24 minimel

minimel

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 11 February 2015 - 10:03 PM

Do you know whether, if you DO end up paying the ransom, that there's a time limit on the decryption key?

Does it take long to decrypt, given of course the amt and size of files.

 

I'm getting desperate now as I don't want to risk not finding a solution AND having the ransom double, seeing as it's nearly the weekend and financial transactions may not be 'received' in time.



#25 minimel

minimel

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:18 AM

Posted 11 February 2015 - 10:04 PM

Hello Nathan,

 

I've also infected with this crypto locker... where can I send my sample infected files?

 

upload a zip file with a encrypted file and ur ransom note, and email it to decryptorbit@outlook.com with the subject "cryptotorlocker 2015" and ill take a look. 



#26 Nathan

Nathan

    DecrypterFixer


  •  Avatar image
  • Security Colleague
  • 1,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:09:18 AM

Posted 11 February 2015 - 10:22 PM

trucker, u have to disable ur Av temporarily.


Have you performed a routine backup today?

#27 trucker2838

trucker2838

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:18 AM

Posted 11 February 2015 - 10:41 PM

ok tried it will not work for me $hit



#28 Nathan

Nathan

    DecrypterFixer


  •  Avatar image
  • Security Colleague
  • 1,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:09:18 AM

Posted 11 February 2015 - 11:10 PM

So I have had over 12 people email me saying that the decrypter wont work or asking me to decrypt files. This is ONLY for CryptoTorLocker 2015, which currently isn't active really. This will not work for CTB Locker, or torrentlocker which is the infections everyone has been emailing me about


Have you performed a routine backup today?

#29 Andres Pedreno

Andres Pedreno

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canary Island. Spain
  • Local time:01:18 PM

Posted 12 February 2015 - 03:57 AM

Hi all!

 

I have used the decrypter in a small folder but it doesn´t work.

 

The message I get  in the end is Ø files decrypted. This folder contains  about ten files encrypted.

 

It´s  good news  that someone is working for a solution.

 

Nathan, I send you an email with all you said

 

 

Best regards... and Good luck, Andrés 


Edited by Andres Pedreno, 12 February 2015 - 04:05 AM.


#30 RobertHD

RobertHD

  •  Avatar image
  • Members
  • 348 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Somewhere in Oz
  • Local time:11:48 PM

Posted 13 February 2015 - 06:06 AM

Thanks Nathan Um i shall keep this decryptor when i need it but yeah


Robert James Crawley Klopp





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users