free

News

collapse

User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

* Recent Posts

NOTICE OF PARKING ENFORCEMENT CHANGES by Huntsman
[June 19, 2025, 05:22:50 pm]


Re: Stopping by by Sinister
[June 08, 2025, 01:58:04 pm]


Re: Stopping by by Ehks
[June 04, 2025, 12:25:17 am]


Re: Rest in peace by Stefanrsb
[June 02, 2025, 03:38:02 am]


Re: [SA:MP]House of Sforza | The Elite Power | Estd. 2006 | LS - LV by Stefanrsb
[June 02, 2025, 03:09:22 am]


Re: The Soprano Family | Royal Loyalty by Stefanrsb
[June 02, 2025, 03:00:31 am]


Re: The Gvardia Family || San Fierro's Main Power || Best criminal group of 09/10/11 by Stefanrsb
[June 02, 2025, 02:47:01 am]


Re: BALLAS | In memory of INFERNO 9 and NBA by Stefanrsb
[June 02, 2025, 02:31:29 am]


Re: Count to 1,000,000. by Stefanrsb
[June 02, 2025, 02:15:04 am]


Re: Stopping by by Traser
[June 01, 2025, 10:23:13 pm]


Re: Stopping by by Old Catzu
[May 18, 2025, 07:27:06 pm]


Re: Stopping by by TheRock
[May 18, 2025, 06:44:49 am]

* Who's Online

  • Dot Guests: 467
  • Dot Hidden: 0
  • Dot Users: 0

There aren't any users online.

* Birthday Calender

June 2025
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 [26] 27 28
29 30

Cerber Ransomware.

CharlieKasper · 1749

0 Members and 1 Guest are viewing this topic.

Offline CharlieKasperTopic starter

  • Retired (SA:MP Admin)
  • Orc
  • *****
    • Posts: 3196
    With us since: 24/04/2010
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
on: September 18, 2016, 06:09:03 am
My father's laptop got infected with some ransomware named Cerber and now his desktop wallpaper is something like this.



I looked it up on the internet and apparently there's no way to decrypt those files and the only way out is restoring a backup (which I doubt my father has), or paying the ransom.

Am I royally fucked or is there a chance to fix this?



Offline Exterminator

  • Hero
  • ****
    • Posts: 2232
    With us since: 17/04/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: Philip_Ancelotti
Reply #1 on: September 18, 2016, 07:51:02 am
First of all, even if you do pay the ransom you'd probably just get scammed. It's way too risky for the hackers to try to make contact with your computer manually and send a decrypt order.

Luckily for you, there's a chance that they might be bluffing about encrypting (I've seen it happen once or twice). First thing you need to do is download Ubuntu, install it on a flash drive and check out your hard drive. Are all the files there?

Note: If you do make a backup, ONLY backup .pdf, .doc, .xlsx e.t.c. Do not backup files like .exe, .bat. jar e.t.c. They could have been infected.

As for the computer itself, reformat it. There is a very good chance they infected and then encrypted some other .exe files. Even if you do get rid of the virus, you might still have another virus leftover which could send sensitive data to the attacker.

Edit: In the meantime, make sure you do not keep windows booted. Encrypting takes time, it's possible that while you're looking at that screen the virus is encrypting more files.


Philip_Ancelotti - Clans & Groups Moderator - Ancelotti Boss


Offline Janar

  • Hero
  • ****
    • Posts: 3954
    With us since: 07/06/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: [WS]Janar
Reply #2 on: September 19, 2016, 11:51:11 am
Exterminator is right there.

For future information - the only way to actually keep your files safe is by having (regular) backups. Very often these cryptoviruses use rather hard encryption, quite possibly AES256 or SHA-somethingsecure. These are pretty much impossible to be cracked at this time.



Offline CharlieKasperTopic starter

  • Retired (SA:MP Admin)
  • Orc
  • *****
    • Posts: 3196
    With us since: 24/04/2010
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #3 on: September 19, 2016, 01:26:26 pm
Luckily for you, there's a chance that they might be bluffing about encrypting (I've seen it happen once or twice). First thing you need to do is download Ubuntu, install it on a flash drive and check out your hard drive. Are all the files there?

Note: If you do make a backup, ONLY backup .pdf, .doc, .xlsx e.t.c. Do not backup files like .exe, .bat. jar e.t.c. They could have been infected.
When I checked, every file was already encrypted (even doc and jpeg files). Even in the deepest folders, the files had different extensions, so I guess its done.
So yep, I will reinstall Windows.

Exterminator is right there.

For future information - the only way to actually keep your files safe is by having (regular) backups. Very often these cryptoviruses use rather hard encryption, quite possibly AES256 or SHA-somethingsecure. These are pretty much impossible to be cracked at this time.
The first thing I/my father has to figure out is the source of the ransomware. It could be from his email or external sources. I will reformat his laptop and have occasional backup set up.



 


free
SimplePortal 2.3.7 © 2008-2025, SimplePortal