Showing posts with label Dormant Ransomware. Show all posts
Showing posts with label Dormant Ransomware. Show all posts

Wednesday, 3 June 2015

Ransomware Maker Decrypts As Promised Infected PCs


The creator of the Locker-ransomware has promised as encrypted files on all computers he infected without charge and automatically decrypted. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.

At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files. Rich is the author therefore did not become. According to Symantec, he would total 152 euros received 22 victims.


Last week the ransomware maker on Pastebin posted a message in which he regret expressed. It was at its say never been his intention to spread the ransomware. He compiled a file with all the encryption keys available and stated that on June 2, all remaining infected computers would be automatically decrypted. And the author has fulfilled that promise, reports Bleeping Computer . For users that their computer had been disinfected, there is a unlocker tool made ​​available. How to distribute the ransomware is managed is still unknown.

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .