![]() |
|
Help im infected (locker v 4.94 ransomware) - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Computers (https://sinister.li/Forum-Computers) +--- Forum: Antivirus & Protection (https://sinister.li/Forum-Antivirus-Protection) +--- Thread: Help im infected (locker v 4.94 ransomware) (/Thread-Help-im-infected-locker-v-4-94-ransomware) |
RE: Help im infected (locker v 4.94 ransomware) - Hyper_ - 05-29-2015 (05-29-2015, 01:08 AM)Reiko Wrote: WOW. Your attitude sure changed quick. Yeah, well, you did the research, can't argue with that. (05-29-2015, 01:06 AM)nothing.nobody Wrote: Yes, now please tell me how to crack a remote box's 4096-bit encrypted SSH RSA key by listening to your computer. Oh wait, you fucking can't. LOL, u in a bad mood? RE: Help im infected (locker v 4.94 ransomware) - roger_smith - 05-29-2015 (05-29-2015, 12:41 AM)Reiko Wrote: Side-channel attacks also don't count. You cannot do that to every implementation of RSA, or even a good implementation of RSA.
RE: Help im infected (locker v 4.94 ransomware) - loading... - 05-31-2015 Here's more info on it that I found http://www.bleepingcomputer.com/virus-removal/locker-ransomware-information#clean Alright guys I have successfully and fully removed the ransomware and here's how in case anyone else gets it. First, open msconfig, go to the services tab and find the service named IDR and disable it. Download sysinternals suite and open the application called "PSkill" and kill the process named "rkcl.exe" (You wont be able to kill it normally because it has enabled by a "Zero Access Rootkit". Open your file explorer and navigate to C:\ProgramData and delete the folder "Rkcl". This will remove the Locker executable and the service executable. Next, download RogueKiller and run a scan with it. http://www.bleepingcomputer.com/download/roguekiller/dl/121/ It will detect any malicious registry keys (and there will be a few) and remove them along with the Zero Access Rootkit and any other malicious files it may have installed. Next, download one of the few free decrypters made specifically for this purpose (google them, they will come up trust me.) and they will TRY to decrypt the files using their database of known keys. It may take awhile, but it works! (at least it did for me and it only took about 40 minutes) Hopefully that helps anyone who gets infected in the future! RE: Help im infected (locker v 4.94 ransomware) - roger_smith - 05-31-2015 (05-31-2015, 09:56 PM)loading... Wrote: Here's more info on it that I found http://www.bleepingcomputer.com/virus-removal/locker-ransomware-information#clean Good work @loading... and congrats on getting your data back. You've been very lucky in this instance. |