NonSports Forum

Net54baseball.com
Welcome to Net54baseball.com. These forums are devoted to both Pre- and Post- war baseball cards and vintage memorabilia, as well as other sports. There is a separate section for Buying, Selling and Trading - the B/S/T area!! If you write anything concerning a person or company your full name needs to be in your post or obtainable from it. . Contact the moderator at leon@net54baseball.com should you have any questions or concerns. When you click on links to eBay on this site and make a purchase, this can result in this site earning a commission. Affiliate programs and affiliations include, but are not limited to, the eBay Partner Network. Enjoy!
Net54baseball.com
Net54baseball.com
ebay GSB
T206s on eBay
Babe Ruth Cards on eBay
t206 Ty Cobb on eBay
Ty Cobb Cards on eBay
Lou Gehrig Cards on eBay
Baseball T201-T217 on eBay
Baseball E90-E107 on eBay
T205 Cards on eBay
Baseball Postcards on eBay
Goudey Cards on eBay
Baseball Memorabilia on eBay
Baseball Exhibit Cards on eBay
Baseball Strip Cards on eBay
Baseball Baking Cards on eBay
Sporting News Cards on eBay
Play Ball Cards on eBay
Joe DiMaggio Cards on eBay
Mickey Mantle Cards on eBay
Bowman 1951-1955 on eBay
Football Cards on eBay

Go Back   Net54baseball.com Forums > Net54baseball Main Forum - WWII & Older Baseball Cards > Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions

Reply
 
Thread Tools Display Modes
  #1  
Old 04-07-2015, 08:44 PM
orator1's Avatar
orator1 orator1 is offline
Paul C.
Member
 
Join Date: May 2009
Location: NYS
Posts: 207
Default Nasty ransom virus called Cryptowall 3.0 infected all my files

My computer recently got hit with a horrible ransomware virus called Cryptowall 3.0 that locked every image, document, pdf, etc. file.

The virus infects every drive connected to your computer, so if your backup drive or USB drive is connected - like mine were - they also get locked. The virus creates impossible to open encrypted copies of every file on your computer and deletes all your original files. The only way you can open your now encrypted files is to pay the $500 ransom in Bitcoins, which increases to a $1000 ransom after 7 days. Once they verify your Bitcoin payment a "key" is sent to you which will unlock your files.

I haven't paid the ransom yet because I'm still researching this virus, and because I've never used Bitcoins before. I have a lot of scans of vintage cards, memorabilia, and family photos on my computer that have taken many years to accumulate, so losing them would be a huge personal loss.

But I just wanted to warn anybody who thinks their files are safe because you have a backup - that they are not necessarily safe. I learned the hard way that once you back up your files you must UNPLUG your backup drive and USB drives from your computer, otherwise the virus can infect them too.

Last edited by orator1; 04-07-2015 at 08:46 PM. Reason: .
Reply With Quote
  #2  
Old 04-07-2015, 09:01 PM
irishdenny's Avatar
irishdenny irishdenny is offline
Member
 
Join Date: May 2009
Posts: 1,538
Default

Paul,
Thanks fir the Heads uP... I am Really Sorry to hear of Your Troubles, Sounds like We are all at Risk!
I do hope fir a quick resolve fir Your/Our situation. A lot of us MiGHT Be RiGHT behind You...

Do You Recall Any Details from Your Inception of the Virus?
__________________
Life's Grand,
Denny Walsh
Reply With Quote
  #3  
Old 04-07-2015, 09:28 PM
orator1's Avatar
orator1 orator1 is offline
Paul C.
Member
 
Join Date: May 2009
Location: NYS
Posts: 207
Default

Denny,
There is some good information about Crypotowall 3.0 on the site BleepingComputer.com. I think my computer got infected by clicking on a fake program "update" which kept popping up on my desktop. It is also spread by opening an infected email. Messages are inserted into every folder instructing how to pay the ransom. Once you see those messages start to pop up, some people have unplugged their computer which stops the virus from encrypting more files. When I saw the messages keep popping up in each folder I didn't think to pull the plug. I went to Best Buy and asked the Geek Squad but they said the files are gone unless the ransom is paid. I bought the recommended anti-malware program called Malwarebytes and ran it several times to remove the virus, but that doesn't get the files back.
Paul
Reply With Quote
  #4  
Old 04-07-2015, 09:51 PM
Leon's Avatar
Leon Leon is online now
Leon
peasant/forum owner
 
Join Date: Mar 2009
Location: near Dallas
Posts: 34,336
Default

Most computers have a restore feature so you can restore to a time in the past. I have done it and it has worked but I have not encountered this virus either. (knock on wood)
__________________
Leon Luckey
Reply With Quote
  #5  
Old 04-08-2015, 12:54 PM
Zach Wheat Zach Wheat is offline
Member
 
Join Date: Apr 2009
Posts: 1,666
Default Decrypto

Apparently www.decryptolocker.com will decrypt a sample file and send you a code to decrypt the remainder of the files. I have not tried this before.

Z Wheat
Reply With Quote
  #6  
Old 04-08-2015, 01:01 PM
4815162342's Avatar
4815162342 4815162342 is offline
Daryl
Member
 
Join Date: Apr 2009
Posts: 3,263
Default

Paul, I have read and heard from a few different sources that it is possible to use a product such as R-Studio to recover at least some of the original files.

Here's an excerpt from a weekly podcast that I listen to, Security Now:

Quote:
LEO: Energized. And, after all, since you picked them, I presume you know the answers to them. Starting with Question #1 from Joe Pracht, and that's how he says you pronounce it, in North and South Carolina. That's a little bit of a mystery, but we'll just leave that to you, Joe. He writes, and this is a long one, he's recovered CryptoWall files without paying any ransom: Steve, I am a network and systems administrator for a large nonprofit covering North and South Carolina. Ah, you have given us the answer. We have had two XP computers infected by CryptoWall. We have a Group Policy block in place for CryptoLocker and are working to remove all XP machines from the network. However, in both cases we had the users disconnect the computers and ship them over to us. During Episode 496, Listener Feedback #207, Joe Meedy wrote you with a question about CryptoWall and made the statement, "I've read that CryptoWall makes a copy of your data file. It encrypts it, then deletes the original file." So, smart man, Joe Pracht.

STEVE: Uh-huh.

LEO: He thought about this. He said: I created a full image of the infected drive - that's always the first thing to do, just image that sucker off - and then used R-Studio to attempt the recovery of deleted files. I'm not promoting R-Studio over other products, he writes. This just happened to be one our department had a license to. The recovery brought back deleted files of all types. I contacted the user of the initially infected laptop to discuss some of the files we found. I mentioned a picture of kids at a Japanese steak house, and the user was ecstatic. Not all files were recovered, but we recovered enough to make the user very happy. Thank you and Leo for the last 10 years. I'm a longtime listener and can't wait for the new show every week. Joe Pracht. Wow, that's a great story.

STEVE: Well, yeah. I thought this was important to share because this demonstrates that, clever as these CryptoWall/CryptoLocker crypto bad guys are, they're making a fundamental mistake, and that is they're not overwriting the unencrypted files.
Reply With Quote
  #7  
Old 04-08-2015, 01:36 PM
orator1's Avatar
orator1 orator1 is offline
Paul C.
Member
 
Join Date: May 2009
Location: NYS
Posts: 207
Default

Thanks for the replies. I will look into R-Studio and see if it's a possibility. I have Windows XP and from what I understand, Microsoft stopped supporting XP last year so there were more vulnerabilities for viruses/malware.
Reply With Quote
  #8  
Old 04-08-2015, 02:50 PM
Joshchisox08's Avatar
Joshchisox08 Joshchisox08 is offline
J0$H B^ck!ey
Member
 
Join Date: Feb 2015
Location: C0nn3cticu+
Posts: 1,943
Default For those who aren't entrenched in Windows

Sorry to hear about your situation but I'd never pay anything. You'll probably just end up being out of money. I highly doubt that they'll unlock your files and I doubt that they'd keep them unlocked for long before they pull the same BS.

If any of you are open to trying and installing a new OS I'd suggest it. After you backup your files of course. Here's a link to a easy group of Linux OSs. They're virtually VIRUS FREE. This just flat out wouldn't happen running that as opposed to Windows. Especially XP as you said is no longer supported. Depending on you memory capacity you'll have to check which would be compatible with your machine.

http://www.ubuntu.com/download

There's also numerous YouTube videos that will demonstrate how to install this onto your machines. It will replace Windows so back up your files. It's fairly simple just following directions.
__________________
429/524 Off of the monster 81%
49/76 HOF's 64%
18/20 Overlooked by Cooperstown 90%
22/39 Unique Backs 56%
80/86 Minors 93%
25/48 Southern Leaguers 52%
6/10 Billy Sullivan back run 60%

237PSA / 94 SGC / 98 RAW

Excel spreadsheets only $5
T3, T201, T202, T204, T205, T206, T207, 1914 CJ, 1915 CJ, Topps 1952-1979, and more!!!!

Checklists sold (20)

T205 8/208 3.8%
Reply With Quote
Reply




Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
1950s Ransom Jackson Cubs Home Rub Ball / LOA drc Baseball Memorabilia B/S/T 0 04-03-2011 01:04 PM
The Virus Has Spread from OH to KY oldjudge Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 11 11-12-2010 08:18 PM
anyone else getting virus e-mails?? Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 2 05-04-2005 03:53 PM
I wrote that virus post Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 0 05-03-2005 09:59 PM
Virus warning!!!!!!!! Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 8 11-27-2001 08:10 PM


All times are GMT -6. The time now is 06:07 AM.


ebay GSB