Saturday, November 23, 2013

Dangerous "New" Ransomware Makes Your Files Unrecoverable (Cryptolocker)


There is a new type of Malware that is very difficult to remove.  What it does is encrypt your personal files, which results in your files becoming unreadable.  The files selected include anything in "My Documents".  This Malware can also cloak programs used to run Microsoft.  Once it has done its thing, it asks for a ransom of $100 or more to fix the problem.

In general, I can't do a thing for you.   Your programs and files are lost if you do not pay the ransom.  For details on this nasty stuff, read this.  It will tell you that the way you get infected is to click on a file that is attached to an official looking message that looks like the following.  This message could "look like" a pdf file.  Please read about this in the above link so you know what the malware enticement looks like in order to avoid infection.

Cloud backup services will probably vary in their ability to rescue you when you have an infection that either changes or encrypts files.  Depending on the service and how the service is set up, the encrypted files will begin making their way to your cloud storage.  So your primary storage in the cloud will be corrupted.  The best advice I can give you is to notify your service as soon as you notice something suspicious, which might not be until the ransom message is displayed.  The cloud service support people will have to recover your files to a time before encryption started.  You'll need to figure out when that was; perhaps the support people can help.

Note:  If you use a free cloud service, such as Microsoft's or Google's,  it is going to be more difficult to recover the right backups.  Generally you are on your own to figure out how to get back earlier versions of files.

-----Original Message-----
From: John Doe [mailto:John@mydomain.com]
Sent: Tuesday, October 15, 2013 10:34 AM
To: Jane Doe
Subject: Annual Form - Authorization to Use Privately Owned Vehicle on State Business
All employees need to have on file this form STD 261 (attached). The original is retained by supervisor and copy goes to Accounting. Accounting need this form to approve mileage reimbursement.
The form can be used for multiple years, however it needs to re-signed annually by employee and supervisor.
Please confirm all employees that may travel using their private car on state business (including training) has a current STD 261 on file. Not having a current copy of this form on file in Accounting may delay a travel reimbursement claim.

Printfriendly

Print Friendly and PDF