We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
What is this thing?
Options

laguini
Posts: 21 Forumite
in Techie Stuff
This message appeared in large black letters across my desktop about 10 minutes ago:
"All your personal files were encrypted with a strong algorythm RSA-1024 And you can't get access to them without making of what we need!
Read "How to decrypt" txt-file on your desktop for details.
Just do it as fast as you can!
Remember don't try to tell anyone about this message if you want to get your files back! Just do all we told"
The decrypt file is now on my desktop but I'm sure it's a no go and am about to scan my comp. Contrary to what it said I can actually access my files, so it doesn't look like they have been encrypted or whatever.
But I haven't had anything quite like this before, anyone familiar with it?
"All your personal files were encrypted with a strong algorythm RSA-1024 And you can't get access to them without making of what we need!
Read "How to decrypt" txt-file on your desktop for details.
Just do it as fast as you can!
Remember don't try to tell anyone about this message if you want to get your files back! Just do all we told"
The decrypt file is now on my desktop but I'm sure it's a no go and am about to scan my comp. Contrary to what it said I can actually access my files, so it doesn't look like they have been encrypted or whatever.
But I haven't had anything quite like this before, anyone familiar with it?
0
Comments
-
Sounds like a virus to me - even though it is citing the use of a real encrypting algorithm. The English in that message is poor and algorithm is not spelled correctly either.
I googled but couldn't find a related link - but for sure I would avoid following those instructions in that text file until someone can help you identify what's going on.Hi, I'm a Board Guide on the Old Style and the Consumer Rights boards which means I'm a volunteer to help the boards run smoothly and can move and merge posts there. Board guides are not moderators and don't read every post. If you spot an inappropriate or illegal post then please report it to forumteam@moneysavingexpert.com. It is not part of my role to deal with reportable posts. Any views are mine and are not the official line of MoneySavingExpert.Never ascribe to malice that which is adequately explained by incompetence.DTFAC: Y.T.D = £5.20 Apr £0.50
0 -
Download MALWAREBYTES (Make sure you click 'DOWNLOAD LATEST VERSION')
http://www.filehippo.com/download_ma..._anti_malware/
Open malwarebytes and goto UPDATE and click 'check for updates'. After its updated goto SCANNER and click PERFORM QUICK SCAN then click SCAN
Remove everything thats found (needs to be ticked)
Post the COMPLETE log here AFTER youve deleted everything it finds
If anything was found then do the exact same but run a FULL scan4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy0 -
nice
can i ask what precautions you have installed? what antivrus software etc..
seems like you know it's fake..and you're doing the right thingsUtinam logica falsa tuam philosophiam totam suffodiant.0 -
http://www.computing.net/answers/security/how-to-encode-files-after-trojan-1024-cypher/31879.html
This is a similiar virus but the guys files were encoded. Not of much use I'm afraid.0 -
Gpcode (ransomware), what site had you been on just before you got this or was it in a download?0
-
DatabaseError wrote: »nice
can i ask what precautions you have installed? what antivrus software etc..
seems like you know it's fake..and you're doing the right things
I have microsoft security essentials, zone alarm pro and malware bytes. Nothing has been coming up on them lately though really, perhaps I need something stronger.
Debitcardmayhem- here is the log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5189
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
25/11/2010 17:54:36
mbam-log-2010-11-25 (17-54-36).txt
Scan type: Quick scan
Objects scanned: 143388
Time elapsed: 9 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\bumbly\AppData\Local\Temp\0.8626637234042882.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
So it was trojan, I guess after doing a full scan that should be the end of it? Not sure how and why I've been getting them so much in the past six months.
Thanks0 -
Hi All. I've had the exact same attack!
I've tried to rename and open the files but I can't open them – the files are really encrypted. I managed to stop the process of encryption, using Task Manager to stop a suspicious process, so "only" about half my files are encrypted. The attack started 9:49PM yesterday and I noticed and stopped the process 10:38. The process deletes the original files and replaces them with encrypted files. I did not download any torrents or P2P, only email and general surf at the time.
I use XP, SP 3. - Suspect that XP is a reason for the attack (old system). I suppose that a system restore don't help since the virus-program has changed my files - system restore only restores the system as I recall.
They've added a key that they want me to send to an email address [EMAIL="datafinder@fastmail.fm"]datafinder@fastmail.fm[/EMAIL], plus money to a bank account, claiming that they will then send a decryption key and instructions. - I'm off course not going to do that, I just thought it might help with a little info on the attack.
If someone can help it’s much appreciated, but I guess the only thing is to reinstall everything on the computer.0 -
More details here:
http://www.securelist.com/en/descriptions/old313444
Below is an excerpt;
This malicious program encrypts files on the victim machine. It is a Windows PE EXE file 8030, bytes in size.
Removal instructions
If you think your computer has been infected, contact us at [EMAIL="stopgpcode@kaspersky.com"]stopgpcode@kaspersky.com[/EMAIL]. Include details about the exact date and time of infection, as well everything you did on the computer in the 5 minutes before the machine was infected:- which programs you ran,
- which websites you have visited, etc.
At the moment, it's not possible to decrypt files encrypted by Gpcode. However, you can use PhotoRec to recover your original files which were deleted by Gpcode after the virus created an encrypted version of the files.
The utility can be used to recover Microsoft Office documents, executable files, PDF and TXT documents, and also certain file archives. Here is a full list of supported file formats.
PhotoRec is part of the TestDisk package. The latest version of TestDisk, including PhotoRec, can be found here.2014 running challenge 471.95 km / 1000 km.0 -
Even more details (actually had just read this an hour ago!) - http://nakedsecurity.sophos.com/2010/11/26/drive-by-ransomware-attack-demands-120/
Agree with the PhotoRec advice above (unless you have backup copied of the files?).0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.9K Banking & Borrowing
- 253.1K Reduce Debt & Boost Income
- 453.5K Spending & Discounts
- 243.9K Work, Benefits & Business
- 598.7K Mortgages, Homes & Bills
- 176.9K Life & Family
- 257.1K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards