Link to home
Start Free TrialLog in
Avatar of gesolink
gesolink

asked on

crypto locker virus

how to remove crypto locker virus and uncrypt files
Avatar of ☠ MASQ ☠
☠ MASQ ☠

Removal is the easy part. Create a Kapersky bootable CD and run a scan from it to remove the active part.
https://support.kaspersky.com/viruses/rescuedisk

Still working on the decryption :(
If you have backed up versions of the files affected you can run a comparison to get the encryption key used.

See also
http:Q_28246288.html
ASKER CERTIFIED SOLUTION
Avatar of Shane McKeown
Shane McKeown
Flag of Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
How much is the data worth to you?  If you don't have a back up the only option at this point is to pay the ransom.  I would do everything I could first but I understand they destroy the unencryption key within 72 hours.  Maybe there will be a fix soon but at this time I'm not aware of one.
Avatar of gesolink

ASKER

Cleaned virus, but no way to unencrypt data
Are they going to track-'em-n-wack-'em the bad guys who are getting all these ransom money? It is ridiculous if Feds don't step in and try to find those behind the virus.
The FBI (for one) is looking into it and is asking victims to file a report with them.

http://www.ic3.gov/media/2013/131028.aspx