Showing posts with label Volume Shadow Copies. Show all posts
Showing posts with label Volume Shadow Copies. Show all posts

Saturday, 7 November 2015

CryptoWall-Ransomware Ransom Increases To 700 Euro


There is a new version of CryptoWall-surfaced ransomware that encrypts file names, victims speaks in a derogatory way and the ransom amount has increased to 700 euro, so researchers at the forum Bleeping Computer discovered.

CryptoWall is a form of ransomware which kinds of files on the computer encrypts. For decrypting victims must then pay. The first variant was last May discovered. This release early victims still 500 for decryption. If victims do not paid this amount was increased to 1,000 euros a time. With CryptoWall 4.0 that figure has now 1400 euros.

The new version also stands out because not only the contents of files are encrypted, but the file names. This is probably done to frustrate victims and make it difficult to determine which files need to be restored, says Lawrence Abrams Bleeping Computer. Like previous versions, removes all CryptoWall 4.0 Volume Shadow copies, turn off System Restore and Windows Startup Repair. Also makes use of the computer, on the basis of operating system and processor, a unique identification number.

Another change in Crypto 4.0 is the text to see victims of an encrypted computer get. Namely, that it has acquired a derogatory tone. So victims are addressed as "Congratulations !!! You have become part of the great CryptoWall community."It is also assumed that victims do not understand the explanations about encryption. Next, the creators which CryptoWall is not malicious and that together with the victims make the Internet safe. How the new version spreads exactly is unknown, but previous versions used mainly e-mail attachments and unpatched software.

Friday, 23 October 2015

Ransomware Spreads Via Windows Remote Desktop


Researchers have discovered a new ransomware variant that spread via Windows Remote Desktop and Terminal Services distributes. Victims were mainly located in Bulgaria and Greece, according to a thread on the forum of Bleeping Computer.

Via Remote Desktop, it is possible to log on to remote Windows computers. It is believed that the attackers have overtaken the password through a brute force attack and thus gained access to the machines. In many cases, it appears to go servers. Then, the ransomware is installed which encrypts all kinds of files and a total of four bitcoin for decrypting asks.With the current exchange rate is that an amount of approximately 960 euros.

Because the network servers can attack major consequences for companies. According to researcher Nathan Scott the ransomware does not remove the Volume Shadow Copies. The original files are not removed in a safe manner. This allows victims through a tool like ShadowExplorer trying to get their files back in case they do not have a backup. Several victims say however that having paid the ransom and then got the decryption key to decrypt their files, which also succeeded.

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .

Sunday, 19 April 2015

Ransomware Allows Victims To Recover From Error Files



A new ransomware variant that first appeared in late January and make the last month was increasingly active shows an error causing casualties without paying their files can be recovered. It is the Threat Finder ransomware which spreads through vulnerabilities in Java, Adobe Flash Player and Microsoft Silverlight that Internet users are not patched.

Once the ransomware encrypts which operates numerous files and asks here for 1.25 bitcoins, what with the current exchange rate is 259 euros. A researcher from Bleeping Computer discovered that the ransomware the Volume Shadow Copies are not removed from the computer, making it possible to access the files using the " Previous options can restore "of Windows, or a tool like Shadow Explorer .