Question About Cryptolocker or Cryptowall

Brucex64

New member
Member
Local time
6:43 PM
Messages
65
Location
Jackson, MS USA
I am not sure if I have this ransomware. I've looked at a few of my files and they open ok.

I was browsing the web and came to a bad page which redirected to a screen - I did not take the time to read all of it but it said something about the FBI and I saw the words "your files are being encrypted". I immediately closed all browsers.

I should mention that I have MS Security Essentials active. My files are backed up on the cloud with CrashPlan. I did a scan with Security Essentials, it did not find anything. I installed Malwarebytes & Spybot with the latest updates and ran full scans - nothing unusual was found. I had to reboot a couple times, but still nothing. No warning screen came up saying I had to pay etc.

So the thing is, I am not sure if it actually installed itself or if the AV program blocked it. One question is, how long after one of these viruses infect your system do you see the signs of its damage? Would I have seen something by now if I had it? And 2nd question, is there a program I can use to analyze the system and tell me if I have it? Do MS Security, Malwarebytes, and Spybot S&D catch these ransomwares, or is there something else I should scan with?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Pro SP1
CPU
Intel i7-4770
Motherboard
Gigabyte B85M-D3H
Memory
8gb
Graphics Card(s)
NVIDIA GeForce GT640
Hard Drives
Samsung SSD 120gb
Seagate HDD 500gb
Antivirus
Microsoft Security Essentials
Browser
Firefox
Run a scan with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Ok, here is what ESet found after 17 hours!

C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll a variant of Win32/Systweak.N potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe a variant of Win32/Systweak potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe a variant of Win32/Systweak.L potentially unwanted application
C:\ProgramData\{0159ba11-68c4-b6d9-0159-9ba1168ce845}\Intuit TurboTax Deluxe _ Home.rar.exe a variant of Win32/Adware.MultiPlug.FQ application
C:\Users\All Users\{0159ba11-68c4-b6d9-0159-9ba1168ce845}\Intuit TurboTax Deluxe _ Home.rar.exe a variant of Win32/Adware.MultiPlug.FQ application
C:\Windows\Installer\11f4d697.msi a variant of Win32/Systweak.L potentially unwanted application
D:\Software\Installed\Extracted\Winzip\WinZip Pro 19.0 Build 11293 (x64) + Key\winzip190-64.msi a variant of Win32/Systweak.L potentially unwanted application
D:\Software\Old Stuff\WinZip Pro 18.0 Build 11023 Final.zip a variant of Win32/Systweak.L potentially unwanted application
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Pro SP1
CPU
Intel i7-4770
Motherboard
Gigabyte B85M-D3H
Memory
8gb
Graphics Card(s)
NVIDIA GeForce GT640
Hard Drives
Samsung SSD 120gb
Seagate HDD 500gb
Antivirus
Microsoft Security Essentials
Browser
Firefox
Looks like a 'crack' .... WinZip Pro 19.0 Build 11293 (x64) + Key :huh:
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top