i got a popup notepad now All my files are encrypted

Discussion in 'Malware Help (A Specialist Will Reply)' started by skippyd, Dec 14, 2010.

  1. skippyd

    skippyd Private E-2

    Hi, thanks for reading this any help will be greatly apprechiated.
    I had a popup notepad that said " Attention!!!
    All your personal files (photo, documents, texts, databases, certificates, video) have been encrypted by a very strong cypher RSA-1024. The original files are deleted. You can check - just look for files in all folders.
    There is no possibility to decrypt these files without a special decrypt program! Nobody can help you - even don't try to find another method or tell anybody. Also after n days all encrypted files will be completely deleted and you will have no chance to get it back.
    We can help to solve this task for 120$ via wire transfer (bank transfer SWIFT/IBAN). And remember: any harmful or bad words to our side will be a reason for ingoring your message and nothing will be done."


    I don't know what to do. I have some very important info on my computer. I would like to save or at least put on a disk. I have a gateway computer -windows xp- home edition-service pack 3.

    Thank in advance for your help
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do not create duplicate threads in other forums. You should have started this thread in the Malware Forum ( moved there now ).

    This may be the below infection
    http://www.sophos.com/security/analyses/viruses-and-spyware/trojransomu.html

    This may or may not be fixable, but let's check a few things out.


    Please download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. skippyd

    skippyd Private E-2

    hey thank you for replying,

    I can't copy/paste into this or save anything to my computer so I am writing exactly what the MBRCheck says:

    -----------------------------------------------------------------------------------------------------------

    MBRCheck, Version 1.2.3
    <c> 2010. AD

    Command - line:
    Windows Version: Windows XP Home Edition
    Windows Information: Service Pack 3 < build 2600>

    Logical Drives Mask: 0x000001fd

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000001`326a6200 <NTFS>
    \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 <FAT32>

    Size Device Name MBR Status
    149GB \\.\PhysicalDrive0 Gateway MBR Code Detected
    SHA1: 007DADCB3671462B53686F6996D328CFD544ABBD


    Done!
    Press enter to exit...

    -------------------------------------------------------------------------------------------------------

    What does this mean? Is this ransomware something I can get rid of and still keep my files?

    Thank you again
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log shows a normal MBR.

    Not likely. As far as I know, there is no known fix for the file encryption that has occurred.

    If you send money trying to pay them to get a fix, you may just be wasting your money as in most cases, they just take the money and run. They do not care at all about helping you fix what they have done.

    You need to be more careful in the future where you surf and what you download.

    You may want to give the below a read. There was no real true fix posted but some ideas were there and a lot of people complaining about the problem.

    http://www.computing.net/answers/security/how-to-encode-files-after-trojan-1024-cypher/31879.html
     
    Last edited: Dec 18, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds