The first polymorphic Ransomware was released

A new step in the evolution of ransomware has been documented by security researchers who have discovered a sample of malware that encrypts files in the storage drive and creates unique strands of itself because of its polymorphic features.2-C_scr_0

The new threat has been named VirRansom and VirLock by its researchers and ESET, respectively. This particular crypto-malware unlike others of its kind allows files to be decrypted, but this will not stop it from being locked to him of the victim. In this way he forces the victim to pay.1-WinXP-2014-11-21-21-42-07

Just the Ransomware τρέξει στον υπολογιστή του θύματος ενσωματώνεται σε ένα φορητό εκτελέσιμο Portable Executable (PE) και πρόσθετει την επέκταση .

It is noteworthy that malware scrambles the files it affects, but also decrypts it when it is executed.

Once the user runs the infected file, the virus automatically starts spreading in the system. ESET researchers report that in cases landed on “%userprofile%” and “%AllUsersProfile%”.

According to the researchers' analysis, VirLock can infect documents (DOC, XLS, PDF, PPT), images (PNG, GIF, BMP, PSD, JPG), audio files (MP3), MPG compressed files (RAR, ZIP).Ransomware

It appears that there are currently at least six variants of the malware circulating on the .

If the VirLock malware / it does not encrypt the victim's files like other crypto-malware do it locks the computer screen to achieve its goal.

When the computer is in a locked state, malware shuts down explorer.exe, prevents opening of Task Manager, and other procedures that could help to bypass it, according to ESET.

The message about the ransom threatens classically with legal consequences, for some alleged copyright violations, and asks for 216 in bitcoins.

ESET has developed one self-cleaning cleaner for this particular threat, while Sophos also provides one free tool designed for the same reason.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.100 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).