<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cryptounlocker | Matt Crawford</title>
	<atom:link href="https://mattcrawford.me/tag/cryptounlocker/feed/" rel="self" type="application/rss+xml" />
	<link>https://mattcrawford.me</link>
	<description>Handyman &#124; Geek &#124; YouTuber</description>
	<lastBuildDate>Tue, 14 Jun 2022 23:31:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
<site xmlns="com-wordpress:feed-additions:1">176948450</site>	<item>
		<title>Cryptolocker</title>
		<link>https://mattcrawford.me/cryptolocker/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cryptolocker</link>
					<comments>https://mattcrawford.me/cryptolocker/#comments</comments>
		
		<dc:creator><![CDATA[Matt Crawford]]></dc:creator>
		<pubDate>Wed, 18 Dec 2013 17:35:15 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cryptolocker]]></category>
		<category><![CDATA[cryptounlocker]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[threats]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">http://matt.t3d.us/?p=146</guid>

					<description><![CDATA[<p>Recently I have been dealing with a Cryptolocker infection at work &#160;that has taken out our shared network files twice now and this latest infection is by far the worst one I have seen so far since our backups haven&#8217;t been getting done correctly due an configuration error for&#160;NTFS permissions on the shares. Those who [&#8230;]</p>
The post <a href="https://mattcrawford.me/cryptolocker/">Cryptolocker</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></description>
										<content:encoded><![CDATA[<p><a href="https://t3dus.com/wp-content/uploads/2013/12/CryptoLockerInitialScreen.png"><img decoding="async" class="alignleft size-thumbnail wp-image-171" src="http://g3k.xyz/wp-content/uploads/2013/12/CryptoLockerInitialScreen-150x150.png" alt="CryptoLockerInitialScreen" width="150" height="150"></a>Recently I have been dealing with a Cryptolocker infection at work &nbsp;that has taken out our shared network files twice now and this latest infection is by far the worst one I have seen so far since our backups haven&#8217;t been getting done correctly due an configuration error for&nbsp;NTFS permissions on the shares.</p>
<p>Those who don&#8217;t know, Cryptolocker is a new form of ransomware which encrypts a huge number of file types and then demands you pay $300 USD to decrypt your personal files. Full Details at&nbsp;<a href="http://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information">Bleeping Computer</a>.</p>
<p>Now since our backups at work have failed we were forced to pay the ransom to recover our files since it encrypted over 57,000 of them. After we paid the ransom it went to work and it decrypted all but 3,000 or so of the files.</p>
<p><strong>Screenshots of Cryptolocker</strong></p>

<a href='https://mattcrawford.me/cryptolocker/cryptolockerinitialscreen/'><img decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerInitialScreen-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/cryptolockerpaymentchoices/'><img decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerPaymentChoices-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/cryptolockerbitcoininfo/'><img loading="lazy" decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerBitCoinInfo-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/cryptolockerbitcoinpayment/'><img loading="lazy" decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerBitCoinPayment-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/cryptolockermoneypakinfo/'><img loading="lazy" decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerMoneyPakInfo-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/cryptolockermoneypakpayment/'><img loading="lazy" decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerMoneyPakPayment-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/cryptolockerprocessingpayment/'><img loading="lazy" decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/CryptoLockerProcessingPayment-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://mattcrawford.me/cryptolocker/decrypt/'><img loading="lazy" decoding="async" width="150" height="150" src="https://mattcrawford.me/wp-content/uploads/2013/12/decrypt-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>

<p>Later a co-worker&nbsp;at work found a way to use the &#8220;Your Private Key.bin&#8221; file we got after paying ransom to decrypt the remaining files using a Python script called Cryptounlocker.</p>
<p><strong>Crytounlocker Instructions</strong></p>
<ul>
<li>install python 3.3 &#8211; <a href="http://www.python.org/ftp/python/3.3.3/python-3.3.3.msi">Download&nbsp;</a></li>
<li>install the pycrypto module &#8211; <a href="http://www.voidspace.org.uk/downloads/pycrypto26/pycrypto-2.6.win32-py3.3.exe">Download</a></li>
<li>Download the Crypto-Unlocker script and extract it. &#8211; <a href="http://chief-01.deviantart.com/art/Crypto-Unlocker-UPDATED-V1-1-5-413774308">Download</a></li>
<li>Copy &#8220;Your Private Key.bin&#8221; into the root cryptounlocker folder and the encrypted files into the &#8220;Encrypted Files&#8221; folder under that.</li>
<li>Open a command line, type &#8220;python&#8221;, and it should show the correct version 3.3.3.</li>
<li>On the command line navigate to the cryptounlocker folder and type &#8220;python Crypto-Unlocker-V1.1.5-Run.py&#8221;.</li>
<li>Check the &#8220;Decrypted Files&#8221; folder for the results.</li>
</ul>
<p>I&#8217;m hoping this is the last time I run into Cryptolocker but I somehow doubt this is the case as this Trojan is just getting spread around thicker and thicker as of recent.</p>
<p>Please comment below if you have anything to say about Cryptolocker or if these steps have helped you!</p>The post <a href="https://mattcrawford.me/cryptolocker/">Cryptolocker</a> first appeared on <a href="https://mattcrawford.me">Matt Crawford</a>.]]></content:encoded>
					
					<wfw:commentRss>https://mattcrawford.me/cryptolocker/feed/</wfw:commentRss>
			<slash:comments>16</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">146</post-id>	</item>
	</channel>
</rss>
