Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


CryproLocker

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Discussions
View previous topic :: View next topic  
Author Message
Madghostek
How do I cheat?
Reputation: 0

Joined: 26 Aug 2016
Posts: 6
Location: Poland

PostPosted: Sat Sep 10, 2016 7:40 am    Post subject: CryproLocker Reply with quote

Hi!

I'm wondering how anti virus can decrypt files infected by viruses like CryptoLocker.They say that files are encrypted with RSA,and encryption of this would take decades...
So how antivirus can do all this work in some secs.They are lying about encryption? XD

_________________
Still learning Smile
Back to top
View user's profile Send private message
Zanzer
I post too much
Reputation: 126

Joined: 09 Jun 2013
Posts: 3278

PostPosted: Sat Sep 10, 2016 9:10 am    Post subject: Reply with quote

CryptoLocker encrypts your file system.
It, itself, is a normal executable like any other.
Antivirus software detects that executable.
Back to top
View user's profile Send private message
++METHOS
I post too much
Reputation: 92

Joined: 29 Oct 2010
Posts: 4197

PostPosted: Sat Sep 10, 2016 10:01 am    Post subject: Reply with quote

Also, even if something is encrypted, does not mean that nothing is readable. Data is still there, it just may not make much sense. That said, some files may leave traces of identifiable code, be it in the form of repeated patterns in code or partial strings etc.. Additionally, if something isn't readable due to limited read/write access protection or the like, you can typically identify the program or methods that are being used such as Zanzer has pointed out. It really depends on how sophisticated the AV software or other has been programmed to detect various things. Some AV is not sophisticated at all, and just throws up a red flag on any little thing that it can't make sense of.
Back to top
View user's profile Send private message
mgostIH
Expert Cheater
Reputation: 3

Joined: 01 Jan 2016
Posts: 159

PostPosted: Sat Sep 10, 2016 10:16 am    Post subject: Reply with quote

There's no antivirus that can decrypt the work of a good cryptolocker entirely, but there are many that can detect it before it gets executed or stop it while it's running, leaving you with just some unreadable files.

The best protection from a ransomware is an external backup of your computer.

_________________
Do you need to ask me something? Feel free to join my discord server at: https://discord.gg/At4VZXA or ask me something in my YouTube channel: https://www.youtube.com/c/mgostIH
Back to top
View user's profile Send private message
STN
I post too much
Reputation: 43

Joined: 09 Nov 2005
Posts: 2676

PostPosted: Sat Sep 10, 2016 12:02 pm    Post subject: Reply with quote

Easy. Everything that is encrypted is a virus. The good ones have sort of a virtual machine/sandbox inside them which lets the program run/decrypt. I figured this out once when i XOR'ed all the "viral signature" of my trainer (getasynckeystate, writeprocessmemory, xm player) in an effort to evade the false-positives and only included the encrypted code but also had a decryption routine which self-modified the trainer and decrypted the code. It wasn't detected as a virus until i executed it and interestingly, it failed to detect it when i removed the decryption routine but that also rendered the trainer not able to function lol.

Anything it doesn't understand is a virus and anything that tries to modify another program be it a system program or normal user one is automatically flagged as virus.

It doesn't take much skill to code an antivirus these days, most antiviruses rely on a database they leech off bigger antiviruses which pretty much functions like PEiD identifying the OEP (original entry point) of most viruses. The formula for a successful antivirus is the more detection you can generate, the more sense of security you can give your user = $$$

_________________
Cheat Requests/Tables- Fearless Cheat Engine
https://fearlessrevolution.com
Back to top
View user's profile Send private message
kuntz
Cheater
Reputation: 0

Joined: 29 Aug 2016
Posts: 44
Location: Canada

PostPosted: Sat Sep 10, 2016 12:42 pm    Post subject: Re: CryproLocker Reply with quote

Madghostek wrote:
Hi!

I'm wondering how anti virus can decrypt files infected by viruses like CryptoLocker.They say that files are encrypted with RSA,and encryption of this would take decades...
So how antivirus can do all this work in some secs.They are lying about encryption? XD


Some companies/states hacked the CryptoLocker people and acquired their database of decryption keys/hashes. That database was made public so now there are tools and Anti-Virus software packages that will detect CryptoLocker and/or files encrypted by it (and it's variants) and decrypt your files for you by looking up your hash in the public decryption-key database.

Without the entire database of keys, then what you said would likely be true. It would take decades, maybe even centuries, to decrypt just one person's files.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Discussions All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites