查看: 4529|回复: 11
收起左侧

[转帖] Cryptolocker Ransomware: What You Need To Know

[复制链接]
墨家小子
发表于 2013-10-11 16:40:05 | 显示全部楼层 |阅读模式
http://blog.malwarebytes.org/int ... t-you-need-to-know/

Just last month, antivirus companies  discovered a new ransomware known as Cryptolocker.

This ransomware is particularly nasty because infected users are in danger of losing their personal files forever.



Spread through infected websites, this ransomware has been targeting companies through phishing attacks.

Cryptolocker will encrypt users’ files using asymmetric encryption, which requires both a public and private key.

The public key is used to encrypt and verify data, while private key is used for decryption, each the inverse of the other.

Below is an image from Microsoft depicting the process of asymmetric encryption.



The bad news is decryption is impossible unless a user has the private key stored on the cybercriminals’ server.

Currently, infected users are instructed to pay $300 USD to receive this private key.

Infected users also have a time limit to send the payment. If this time elapses, the private key is destroyed, and your files may be lost forever.

Files targeted are those commonly found on most PCs today; a list of file extensions for targeted files include:
3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx

In some cases, it may be possible to recover previous versions of the encrypted files using System Restore or other recovery software used to obtain “shadow copies” of files. The folks at BleepingComputer have some additional insight on this found here.

Removal:

Malwarebytes detects Cryptolocker infections as Trojan.Ransom, but it cannot recover your encrypted files due to the nature of asymmetric encryption, which requires a private key to decrypt files encrypted with the public key.



In order to make removal even easier, a video was also created to guide users through the process (courtesy of Pieter Arntz).

http://www.youtube.com/watch?fea ... d&v=DMEZ4FJ7QnM

While Malwarebytes cannot recover your encrypted files post-infection, we do have options to prevent infections before they start.

Users of Malwarebytes Anti-Malware Pro are protected by malware execution prevention and blocking of malware sites and servers.

To learn more on how Malwarebytes stops malware at its source, check out this blog.

Free users will still be able to detect the malware if present on a PC, but will need to upgrade to Pro in order to access these additional protection options.



Backup:

Also, the existence of malware such as Cryptolocker reinforces the need to back up your personal files.

However, a local backup may not be enough in some instances, as Cryptolocker may even go after backups located on a network drive connected to an infected PC.

Cloud-based backup solutions are advisable for business professionals and consumers alike. Malwarebytes offers Malwarebytes Secure Backup, which offers an added layer of protection by scanning every file before it is stored within the cloud in an encrypted format (don’t worry, you can decrypt these).



To find out more on remove Cryptolocker, check out the official removal guide from Malwarebytes.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
墨家小子
 楼主| 发表于 2013-10-11 16:47:01 | 显示全部楼层
狴犴睚眦
发表于 2013-10-11 16:54:23 | 显示全部楼层
墨家小子 发表于 2013-10-11 16:47
应对Cryptolocker之类敲诈者的办法  -- 转自 瑞星卡卡安全论坛 作者:baohe
海量岛国爱情动作片爱好者必看 ...

方法太麻烦了
旋风游侠
发表于 2013-10-11 16:59:01 | 显示全部楼层
墨家小子 发表于 2013-10-11 16:47
应对Cryptolocker之类敲诈者的办法  -- 转自 瑞星卡卡安全论坛 作者:baohe
海量岛国爱情动作片爱好者必看 ...

这是我打开的方式不对么~~~~

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
墨家小子
 楼主| 发表于 2013-10-11 17:04:06 | 显示全部楼层
旋风游侠 发表于 2013-10-11 16:59
这是我打开的方式不对么~~~~

你有几个G的种子啊?交换一下好不?
墨家小子
 楼主| 发表于 2013-10-11 17:05:00 | 显示全部楼层
狴犴睚眦 发表于 2013-10-11 16:54
方法太麻烦了

确实
旋风游侠
发表于 2013-10-11 17:13:10 | 显示全部楼层
墨家小子 发表于 2013-10-11 17:04
你有几个G的种子啊?交换一下好不?

不知种子为何物~
jefffire
头像被屏蔽
发表于 2013-10-11 19:13:53 | 显示全部楼层
类似加密打劫的木马早就有了吧,这次有什么不同?
墨家小子
 楼主| 发表于 2013-10-11 19:31:46 | 显示全部楼层
jefffire 发表于 2013-10-11 19:13
类似加密打劫的木马早就有了吧,这次有什么不同?

据说这个不好解密
zhou0197
发表于 2013-10-11 19:38:56 | 显示全部楼层
jefffire 发表于 2013-10-11 19:13
类似加密打劫的木马早就有了吧,这次有什么不同?

据说这次玩的是RSA公钥加密…………
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-18 02:53 , Processed in 0.115586 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表