Comments on: New Cryptolocker copycat PClock2 discovered that targets over 2,500 file extensions https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/ Straight-talking security advice from the Malware Experts Fri, 18 Nov 2022 12:16:25 +0000 hourly 1 By: David Biggar https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-786720 Fri, 09 Jun 2017 15:36:00 +0000 http://blog.emsisoft.com/?p=15094#comment-786720 In reply to al_ghul.

As far as I know, PCLock2 is not decryptable. There may come a time when it is decryptable, but unfortunately it currently is not.

However, I’d make sure you’re actually dealing with PCLock2. A good place to start for identification is here; the more information you can give, the more accurate it is: https://id-ransomware.malwarehunterteam.com/

]]>
By: al_ghul https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-786665 Thu, 08 Jun 2017 14:59:00 +0000 http://blog.emsisoft.com/?p=15094#comment-786665 In reply to David Biggar.

ok, I understand, but what if I have some original files before encryption of this pclock2 ? is there still a possibility to decrypt files?

]]>
By: Alvaro Legado https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-785345 Mon, 01 May 2017 02:31:00 +0000 http://blog.emsisoft.com/?p=15094#comment-785345 i HAVE THE SAME PROBLEM THAN THE OTHERS! Attack in 27th April 2017, I removed the virus but decrypter did not detect PClock. There is a way to decrypting this? Two important music productions I need to recover

]]>
By: Sukalyan Dey https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-783142 Tue, 03 Jan 2017 02:54:00 +0000 http://blog.emsisoft.com/?p=15094#comment-783142 In reply to David Biggar.

Thanks David, I hope you come up with an updated version of the decrypter. Keep up good work.

]]>
By: David Biggar https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-783141 Tue, 03 Jan 2017 02:24:00 +0000 http://blog.emsisoft.com/?p=15094#comment-783141 In reply to Sukalyan Dey.

You likely have an updated version of PCLock, for which there is no decrypter. Note that this decrypter is over a year old. There’s a bit more information here: https://www.bleepingcomputer.com/news/security/old-cryptolocker-copycat-named-pclock-resurfaces-with-new-attacks/

]]>
By: David Biggar https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-783140 Tue, 03 Jan 2017 02:21:00 +0000 http://blog.emsisoft.com/?p=15094#comment-783140 In reply to Henry Eze.

You’re correct, depending on the version of PCLock. There is more than one version, and the latest ones are indeed not decryptable (at this time).

]]>
By: Sukalyan Dey https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-783090 Mon, 02 Jan 2017 17:17:00 +0000 http://blog.emsisoft.com/?p=15094#comment-783090 Like Mohamed, Henry Eze and Thomas, I have a similar problem. My PC got infected a fortnight ago. it got detected and Malwarebytes removed the virus.When I installed and ran the decrypt_pclock2.exe, the program wrote: “No previous PClock infection found” …
“This system does not appear to have been targetted by the PClock malware in the past. To prevent you from damaging your files by accident the decrypter will close now.”
The problem is that it mimics Cryptolocker and hence normally we tend to run the antivirus and delete it. It is only afterwards that we get to know that it is PClock ransomware. So, unless you improvise your system to run and decrypt the infected files regardless of the presence of virus, the software loses much of its purpose. Please enable your software to decrypt the files even if the virus has been removed. If it cannot be done, please reply so that I can delete the junk of encrypted files.

]]>
By: Paul Abruzzo https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-782863 Sat, 24 Dec 2016 08:02:00 +0000 http://blog.emsisoft.com/?p=15094#comment-782863 In reply to Henry Eze.

Thank you Henry. I have a lot of stuff backuped so I was able to restore a large amount, but like you, there are still some files I did not have backups for and I am saving them in the hopes that in the future I will be able to find a way to reverse the encryption. Thanks.

]]>
By: Henning Berg https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-782848 Thu, 22 Dec 2016 22:25:00 +0000 http://blog.emsisoft.com/?p=15094#comment-782848 ]]> In reply to Emre Kirpiksiz.

I have paid them The ransom and i got almost my picture and movies back. I dont know why it didnt work on all files but i got 90 % back 😕

]]>
By: Emre Kirpiksiz https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-782845 Thu, 22 Dec 2016 17:50:00 +0000 http://blog.emsisoft.com/?p=15094#comment-782845 In reply to Henning Berge.

I have a same problem.. Do you solved?

]]>
By: Henry Eze https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-782842 Thu, 22 Dec 2016 10:35:00 +0000 http://blog.emsisoft.com/?p=15094#comment-782842 In reply to Paul Abruzzo.

Hello Paul
From my online research, there seems to be no current solution to this ransomware. Unfortunately, I had no much back up to all my files.
I cut my losses and damage, and moved on with a few things left. I still have the tons of encrypted files on the system (hoping someday a remedy would pop in).
If you made back-ups, I suggest you move ahead with them.
I am always an advocate for backing up files to others, but do not always back up myself. I learnt the hard way this time.
All the best!

]]>
By: Paul Abruzzo https://www.emsisoft.com/en/blog/15094/new-cryptolocker-copycat-pclock2-discovered-that-targets-over-2500-file-extensions/#comment-782839 Thu, 22 Dec 2016 09:01:00 +0000 http://blog.emsisoft.com/?p=15094#comment-782839 In reply to Henry Eze.

I am in the same situation. I got hit on November 28th. It encrypted my files but it DID NOT change the extension and it DID NOT give me a ransom note! I just left me with a ton of encrypted files. I downloaded Malware bites and it found a bunch of stuff related to cryptolocker and removed it but I still can’t get anything to decrypt my files. Any ideas?

]]>