The first polymorphic Ransomware was released

A new step in the evolution of documented by security researchers who discovered a sample of the malware that encrypts files on the storage drive and creates unique clones of itself due to its polymorphic characteristics.2-C_scr_0

The new threat has been named VirRansom and VirLock by researchers from Sophos and ESET, respectively. This crypto-malware, unlike any of its kind, allows the files to be decrypted, but this will not stop blocking the victim's computer screen. In this way he causes the victim to pay.1-WinXP-2014-11-21-21-42-07

Just the Ransomware Run on the victim's computer is embedded in a portable executable Portable Executable (PE) and adds the EXE extension.

It is noteworthy that malware scrambles the files it affects, but also decrypts it when it is executed.

Once the user runs the infected file, the virus automatically starts spreading to the system. ESET researchers report that in two cases it landed on "% userprofile%" and "% AllUsersProfile%".

According to των ερευνητών, το VirLock μπορεί να μολύνει έγγραφα (DOC, XLS, PDF, PPT), εικόνες (PNG, GIF, BMP, PSD, JPG), αρχεία ήχου (MP3), αρχεία (MPG), but also compressed files (RAR, ZIP).Ransomware

It looks like at the moment there are at least six variants of the malware running on the Internet.

If VirLock / Ransom malware does not encrypt victim files as the other crypto-malware does, it locks the computer screen to achieve its target.

Όταν ο υπολογιστής είναι σε κατάσταση κλειδώματος, το κακόβουλο λογισμικό απενεργοποιεί το explorer.exe, εμποδίζει το άνοιγμα της Διαχείρισης αλλά και άλλες διαδικασίες που θα μπορούσαν να βοηθήσουν στην παράκαμψη του, αναφέρουν οι της ESET.

The message about the ransom threatens classically with legal consequences, for some alleged copyright violations, and asks for 216 in bitcoins.

ESET has developed one self-cleaning cleaner for this particular threat, while Sophos also provides one free tool designed for the same reason.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).