Yesterday I was pissed with the sync speed even after I reinstalled windows
so I tried to sync on a different PC without the protection (I disabled
HIPS to see if it syncs faster) but it didn't, sadly I forgot somehow to turn the protection back on......
Bad news
after 3 or 4 hours I noticed one of the external hard drives flashing and spinning like hell
when I looked at the screen I saw the icon disabled for the protection and had a bad feeling
I immediately turned off the PC, restart from USB,.......but the damage was done
35673 files were encrypted
(263Gb) by
CryptoWall Ransomwarewhich uses RSA2048 encryption to encrypt personal crucial files like .txt .jpg .mp4 .....
and leaves you a note that you have to pay:
500$ in the first week or 1000$ after that to get the encryption key sent to youCryptoWall 4.0 will inject itself into Explorer.exe and disable System Restore, delete all Shadow Volume Copies,
and use bcdedit to turn off Windows Startup Repair.
It will then inject itself into svchost.exe and encrypt the data on all local drives, removable drives, and mapped network drives, basically all drives with a letter!
Once it has completed encrypting your files it will launch the ransom notes that explain what happened and how to purchase the decrypter
and erases itself from the computer.
There is no known method to decrypt the files in feasible time
Luckily after 3 decades of working with computers I learned my lesson and had backups of everything
Restarting with armor on HIPS detected it in an instant and blocked it forever
but imagine loosing all your precious moments from your life, your memories, your work in a blink of an eye
unless you pay your hard earned money
Funny enough for us in the cryptoworld you can only pay in BTC Bitcoins probably because they are not as easy to track as the true money
So never leave your guard down not even for a secondThis is by far the worst nightmare you could have and it could be addressed to the cryptoworld, some even saying that it could come from bitcoin world
so they know you have the means to pay
There are not too many cases yet, it's only a year since this threat is around. I could be the first in Ireland as far as I could see some spread maps
It took a day anyway to restore all the data back, but now I can relax and have a drink
after all what doesn't kill you - makes you stronger
Backup you wallet and personal files because these ones you cannot download from the net, unless you're using cloud services, which I don't trust myself.
Stay safe