Protect Yourself from CryptoLocker

So I was going to write a post about Tesla's big beat after the market yesterday and how the stock is off to the races today, but I came across a computer virus yesterday that was so nasty I wanted to make you guys aware of it so you don't get victimized.

I do a bit of IT consulting on the side for C-level guys who are technophobic. I was scheduled to do a training with one such CEO yesterday, when he asked me if I'd ever heard of CryptoLocker and was it some kind of service. In fact I had heard of CryptoLocker recently on the Skeptics Guide to the Universe podcast, and the fact that this CEO was asking me about it could only mean one thing: he was infected. Sure enough, he said a timer had popped up on his desktop, his files had been stolen, and he had 72 hours to pay $400 through Bitcoin to get his files back or they'd be deleted forever.

Unfortunately, this thing is for real. It comes disguised as an email from UPS or FedEx with tracking information in PDF format attached, only it ain't a PDF. It's a double-extension executable file that installs itself on your hard drive, steals and encrypts all your files, and then demands a ransom for you to recover them. Because the ransom is paid with Bitcoin, it's impossible to track where the money is going. Up to now, the hackers have been true to their word and have returned the files once the ransom has been paid.

That's not to say they'll continue keeping their word, or won't extort even more money once you've paid them. In short, you should never pay hackers a ransom for your data.

In order to protect yourself from CryptoLocker and other viruses using double extensions to install themselves, you can download the following free application which will make it impossible for you to download them:

http://www.foolishit.com/vb6-projects/cryptoprevent/

It's important to note that this only affects Windows machines, so if you're a Mac weirdo you're in the clear.

The best lines of defense are:

  1. Make regular backups that include a mirror of your hard drive. That way if you have to nuke your hard drive back to the stone age you can just do a restore and be back in business. If you're not backing up, start backing up now.
  2. Never download attachments from people you don't know. I know this goes without saying in this day and age, but obviously people still do it. UPS and FedEx (and the USPS, for that matter) will never send you an attachment with tracking info. Don't fall for it.

This is a nasty bug, and the guys behind it are pretty brazen. If you find that you're infected you can try to do a system restore from a point before the suspected time of your infection, but this has only had limited success. Removal instructions are here:

http://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-i…

As always, the best offense is a good defense. Be wary of attachments and install the above application if you want to be really safe. This thing is really bad news. If you want more info about it, here's a video:

Hope this helps.

 

I found a guy on the internet who intentionally picked up this virus and reverse engineered it. He then sent it to the those who were holding his "files" ransom as some kind of tag along on his bitcoin payment. The hilarity ensued, he tweaked cryptolocker to lock their bitcoin wallet. The hackers then sent him all sorts of threatening communication. It was one of the funniest white hat attacks I have seen in a long time. Ill try and find it again and post it on here. But if you do get hit with this, take the earliest instance of system restore you can. Cryptolocker wont always instantly lock up your computer, often times it is tweaked to take effect after X restarts.

Follow the shit your fellow monkeys say @shitWSOsays Life is hard, it's even harder when you're stupid - John Wayne
 
Edmundo Braverman:
Up to now, the hackers have been true to their word and have returned the files once the ransom has been paid.

Really heartwarming to see such honor among thieves...renews my faith in humanity.

Also I just operate under the assumption that everything is some sort of virus, and it's up to the sender or source to prove to me otherwise. Guilty until proven innocent.

 

Hey @"Edmundo Braverman"

For someone who really doesnt want to pay $100 (or whatever it is) per year for Norton or McAffee, how would you recommend that the average person protect themselves with an anti-virus?

I've tried a few different things, most of which have given me some sort of headache. Now that I may be using my home computer a little bit more I wanted to have at least some average level of security.

twitter: @CorpFin_Guy
 
accountingbyday:

For someone who really doesnt want to pay $100 (or whatever it is) per year for Norton or McAffee, how would you recommend that the average person protect themselves with an anti-virus?

Honestly just be careful what you click on, and don't open any files unless you're sure what they are, especially obviously executable files. Also get Malwarebytes and run that like once a week to give your system a good cleaning. Will at least get rid of any trojans.
 

This has pretty much been my strategy. Since I'm not out there downloading much of anything it has worked relatively well thus far, but I'm getting a whole new office setup and am hoping to get a little side business going, so I'm willing to pay a little for protection if it helps.

twitter: @CorpFin_Guy
 
yeahright:

Best defense: Buy an Apple

That's actually a false hope, there are versions of cryptolocker that work on Mac.
Follow the shit your fellow monkeys say @shitWSOsays Life is hard, it's even harder when you're stupid - John Wayne
 

Going by the guise that females are completely clueless, I had a friend that I went to school with who managed to get a virus on her Mac... 3 different times!!! After the third time I told her to never touch a computer again.

I've never seen any group of people mess up computers more than females.

make it hard to spot the general by working like a soldier
 

Esse dolores nihil eos minima cum ut sed facere. Error est ut cum ut in labore consectetur. Dolor velit saepe aut iure qui.

Alias omnis nihil laudantium soluta. Aut ut minus voluptatum facere id. Odio explicabo maiores est harum quia autem error.

Rerum inventore commodi omnis nobis odio et. Ut doloribus quisquam sit numquam. Ut saepe non qui harum.

 

Architecto cumque nemo id nesciunt. Dolorem odit fugit itaque dolor. Esse sed voluptas ipsam commodi nobis qui velit.

Earum eveniet est et. Minima animi libero et omnis sint saepe similique. Dolor blanditiis alias veritatis voluptas fugiat tempora dolorum. Placeat laudantium numquam ex velit nemo occaecati. Quod facere excepturi fugiat non voluptatem et possimus.

Maiores officiis non ipsum a. Qui omnis asperiores magni quo perspiciatis quis illo.

Id eligendi dolorem pariatur ea modi officia vel. Quo in quas nisi. Consequuntur vero aut numquam ut nostrum quam laborum. Possimus dolor dolore aut nemo.

Career Advancement Opportunities

April 2024 Investment Banking

  • Jefferies & Company 02 99.4%
  • Goldman Sachs 19 98.8%
  • Harris Williams & Co. New 98.3%
  • Lazard Freres 02 97.7%
  • JPMorgan Chase 03 97.1%

Overall Employee Satisfaction

April 2024 Investment Banking

  • Harris Williams & Co. 18 99.4%
  • JPMorgan Chase 10 98.8%
  • Lazard Freres 05 98.3%
  • Morgan Stanley 07 97.7%
  • William Blair 03 97.1%

Professional Growth Opportunities

April 2024 Investment Banking

  • Lazard Freres 01 99.4%
  • Jefferies & Company 02 98.8%
  • Goldman Sachs 17 98.3%
  • Moelis & Company 07 97.7%
  • JPMorgan Chase 05 97.1%

Total Avg Compensation

April 2024 Investment Banking

  • Director/MD (5) $648
  • Vice President (19) $385
  • Associates (87) $260
  • 3rd+ Year Analyst (14) $181
  • Intern/Summer Associate (33) $170
  • 2nd Year Analyst (66) $168
  • 1st Year Analyst (205) $159
  • Intern/Summer Analyst (146) $101
notes
16 IB Interviews Notes

“... there’s no excuse to not take advantage of the resources out there available to you. Best value for your $ are the...”

Leaderboard

1
redever's picture
redever
99.2
2
Secyh62's picture
Secyh62
99.0
3
BankonBanking's picture
BankonBanking
99.0
4
Betsy Massar's picture
Betsy Massar
99.0
5
CompBanker's picture
CompBanker
98.9
6
kanon's picture
kanon
98.9
7
dosk17's picture
dosk17
98.9
8
GameTheory's picture
GameTheory
98.9
9
DrApeman's picture
DrApeman
98.8
10
Jamoldo's picture
Jamoldo
98.8
success
From 10 rejections to 1 dream investment banking internship

“... I believe it was the single biggest reason why I ended up with an offer...”