If your files were all changed to the
.CRYPT extension, we have bad news for you. You have been 'attacked' by a ransomware known as Chimera. It's currently active in Germany, but ransomware authors often like to switch their targets overnight.
Possible reasons for the ransomware intrusion are:
- Opening corrupted emails posing as official establishments.
- Exploit kits.
As a result of the infection, a ransom message was displayed to you. It may be written in your language.
This may be because the threat may be able to detect your location. The message usually says that a ransom should be paid via the Tor network. Some Chimera versions were also reported to demand 0.93002414 Bitcoins in exchange for the decryption of the users' files.
A brand new Chimera campaign can extort users in more ways than just asking for bitcoins. The authors may threaten victims to publish their personal files if the demanded amount is not paid within the given deadline. Read more about this particular case here:
http://sensorstechforum.com/chimera-ransomware-variant-frightens-to-publish-victims-files/Also, make sure to read how to deal with the Chimera malicious piece:
http://sensorstechforum.com/remove-chimera-ransomware-and-restore-your-files/