"Let the invasion begin" should have been the foreword-going mantra for those that made CryptoLocker. But as we know of no mantra, we assume that there is none.
The National Crime Agency has issued an alert regarding CryptoLocker: http://www.nationalcrimeagency.gov.uk/news/256-alert-mass-spamming-event-targeting-uk-computer-users
CryptoLocker has been going strong since September of this year. During that time, it seems to have mostly targeted the US, until now.
The NCA is estimating that emails with the CryptoLocker attachment may have reached the tens of millions.
An investigation
has been launched to see where the email addresses are from and where
they are being used. I personally think that the email addresses are
spoofed, therefore finding the source will not really be all that
helpful.
As of this writing, Bitcoin is valued at about $574 a
coin. Meaning that anyone forced to pay the ransom late now has to pay
the ten Bitcoins which at this point means $5,740
This is all the news that I have not said before in a blog post.
Thank you for reading. I invite readers to comment with any questions or comments.
"Education is the most powerful weapon which you can use to change the world" Nelson Mandela
Showing posts with label The CryptoLocker Saga. Show all posts
Showing posts with label The CryptoLocker Saga. Show all posts
Tuesday, November 19, 2013
Tuesday, November 12, 2013
CryptoLocker Post #10
OK, from what I have gathered, this is my 10th blog post regarding CryptoLocker. And if you are reading this, you likely already know what it is. But for those of you who have not heard any computer security news for the past two months, CryptoLocker is a piece of file encrypting ransomware that you can learn more about by looking at my other posts regarding it.
Not a whole lot more to talk about that is new. CryptoLocker is still being spread via email as an attachment. This attachment is normally a executable that is in a zip file format. This file can be unzipped to find the executable that you can then run.
But something new-ish is that the zip file is now password protected. This is a measure used to prevent mail filters that companies are setting up from blocking files with a .zip file name extension. Because these filters are not made to block password protected files.
This is both a good sign and a bad sign.
It is a bad sign because the makers of CryptoLocker are monitoring to see what methods are working to prevent infection.
It is a good sign because companies are now paying attention to CryptoLocker.
I do not see this issue with CryptoLocker going away any time soon. Granted, we may find the makers of CryptoLocker. But that will not stop other creative malware writers from making their own CryptoLocker. The cybercriminals who made this know that this makes money.
But I do know that when this method gains popularity with malware writers, they will make mistakes. Whoever made CryptoLocker did not cut any corners. We will be able to exploit mistakes in order to find a way to defeat this.
But until then, we must press on the fight against CryptoLocker.
And with that, I deliver the following sentence. A plea, a promise, a call:
We must stand united to repel CryptoLocker and other such invaders from our internet.
Thank you for reading, I invite readers to comment with any questions or comments.
Not a whole lot more to talk about that is new. CryptoLocker is still being spread via email as an attachment. This attachment is normally a executable that is in a zip file format. This file can be unzipped to find the executable that you can then run.
But something new-ish is that the zip file is now password protected. This is a measure used to prevent mail filters that companies are setting up from blocking files with a .zip file name extension. Because these filters are not made to block password protected files.
This is both a good sign and a bad sign.
It is a bad sign because the makers of CryptoLocker are monitoring to see what methods are working to prevent infection.
It is a good sign because companies are now paying attention to CryptoLocker.
I do not see this issue with CryptoLocker going away any time soon. Granted, we may find the makers of CryptoLocker. But that will not stop other creative malware writers from making their own CryptoLocker. The cybercriminals who made this know that this makes money.
But I do know that when this method gains popularity with malware writers, they will make mistakes. Whoever made CryptoLocker did not cut any corners. We will be able to exploit mistakes in order to find a way to defeat this.
But until then, we must press on the fight against CryptoLocker.
And with that, I deliver the following sentence. A plea, a promise, a call:
We must stand united to repel CryptoLocker and other such invaders from our internet.
Thank you for reading, I invite readers to comment with any questions or comments.
Wednesday, November 6, 2013
The latest and greatest ways to block CryptoLocker.
I've written quite a few blog posts about this ransomware. So by now I am just going to assume that everyone has read it. And odds are, if you are reading, you know what it is anyway.
There are now two ways that can be used to block CryptoLocker from encrypting your files. One of which I have already talked about, but for the sake of convenience, I will talk about it here as well.
The first way is a tool that blocks the execution of the ransomware. Because the ransomware executes from appdata, which is not a place where many applications execute from, this can be used against the ransomware by blocking anything from running from appdata.
This tool was made by FoolishIT and can be downloaded here: www.foolishit.com/download/cryptoprevent/
For more info on this tool, go here: http://www.foolishit.com/vb6-projects/cryptoprevent/
The second way is a way to block the ransomware from encrypting your files.
This way is part of the public beta of HitmanPro.Alert and can be used along with the first method of blocking CryptoLocker.
HitmanPro.Alert was made by SurfRight, and you can find more info and download the beta here: http://www.surfright.nl/en/cryptoguard
Please note that these tools can be used together without any conflicts arising. It is also important to note that these tools can only help you if you are not infected with CryptoLocker. They will not help you if you are already infected.
With both the anti-malware community and the mainstream media being on high alert from this ransomware, I can see a turn in the tide happening soon against this ransomware. Although I cannot forecast in what way it will take form, I know that it will happen.
Whoever made this ransomware has angered too many to continue infecting people. Sooner or later, the good guys win. This is how it has always been, and this is how it will continue.
Thank you for reading, I invite readers to comment if you have any questions or comments.
There are now two ways that can be used to block CryptoLocker from encrypting your files. One of which I have already talked about, but for the sake of convenience, I will talk about it here as well.
The first way is a tool that blocks the execution of the ransomware. Because the ransomware executes from appdata, which is not a place where many applications execute from, this can be used against the ransomware by blocking anything from running from appdata.
This tool was made by FoolishIT and can be downloaded here: www.foolishit.com/download/cryptoprevent/
For more info on this tool, go here: http://www.foolishit.com/vb6-projects/cryptoprevent/
The second way is a way to block the ransomware from encrypting your files.
This way is part of the public beta of HitmanPro.Alert and can be used along with the first method of blocking CryptoLocker.
HitmanPro.Alert was made by SurfRight, and you can find more info and download the beta here: http://www.surfright.nl/en/cryptoguard
Please note that these tools can be used together without any conflicts arising. It is also important to note that these tools can only help you if you are not infected with CryptoLocker. They will not help you if you are already infected.
With both the anti-malware community and the mainstream media being on high alert from this ransomware, I can see a turn in the tide happening soon against this ransomware. Although I cannot forecast in what way it will take form, I know that it will happen.
Whoever made this ransomware has angered too many to continue infecting people. Sooner or later, the good guys win. This is how it has always been, and this is how it will continue.
Thank you for reading, I invite readers to comment if you have any questions or comments.
Sunday, November 3, 2013
CryptoLocker as of 11/3/2013
If you have read my other posts on this, you know. But for those of you who do not, there is a piece of ransomware that has been making the rounds on the internet since September of this year. And what have given it the ability to spread for this long is the fact that it actually encrypts your files.
I'm not going to go into it all here, because that's what my other posts are for. You can just read the other posts under "The CryptoLocker Saga" label in order to find everything I know about this ransomware.
The purpose of writing this blog post is to inform users of two recent changes with CryptoLocker.
Change #1: Some of the newest variants of CryptoLocker delete all Shadow Copies of your files. This leaves your only options being to restore from backups or to pay the ransom. And attempting to pay the ransom is the perfect way to talk about the second change.
Change #2: Say you have run out of time to pay the ransom. The clock has gone down to zero, and you without any backups, have no way of recovering your files.
Those who made CryptoLocker are now operating a website which allows you to download the public and private key for your copy of the ransomware as well as a decrypter. Although there is one issue that some people might have with this. To pay the ransom before time runs out costs 2 Bitcoins or the equivalence in the form of money loaded onto a GreenDot MoneyPak card. To pay it after time runs out costs 10 Bitcoins. This converts into $2,100 US Dollars.
So, about $400 before time runs out, $2,100 after time runs out. It does not surprise me that those who make CryptoLocker are doing this. I'm sure that quite a few people are desperate to get their files back. This is somewhat smart considering that the page is completely independent of how much time the ransomware says you have.
Thank you for reading. Feel free to comment if you have any questions or comments.
---------------------------------------------------------------------------------------------------------------
Updated 11/7/2013:
The price of the "late payment" option keeps going up along with the price of Bitcoins. As the price goes up for one Bitcoin (about $300 at this point), the price of the late payment will go up (about $3,000 at this point.)
I would highly recommend that if you are infected with this, you make it your top priority to determine if you have any other options then to pay the ransom. If you find out before time is up, you can still pay the $300 flat rate via a GreenDot MoneyPak card. At this point, it will save you $2,700, but this figure can change. And if Bitcoin takes a big dive, odds are good that those that make CryptoLocker will no longer take it.
I'm not going to go into it all here, because that's what my other posts are for. You can just read the other posts under "The CryptoLocker Saga" label in order to find everything I know about this ransomware.
The purpose of writing this blog post is to inform users of two recent changes with CryptoLocker.
Change #1: Some of the newest variants of CryptoLocker delete all Shadow Copies of your files. This leaves your only options being to restore from backups or to pay the ransom. And attempting to pay the ransom is the perfect way to talk about the second change.
Change #2: Say you have run out of time to pay the ransom. The clock has gone down to zero, and you without any backups, have no way of recovering your files.
Those who made CryptoLocker are now operating a website which allows you to download the public and private key for your copy of the ransomware as well as a decrypter. Although there is one issue that some people might have with this. To pay the ransom before time runs out costs 2 Bitcoins or the equivalence in the form of money loaded onto a GreenDot MoneyPak card. To pay it after time runs out costs 10 Bitcoins. This converts into $2,100 US Dollars.
So, about $400 before time runs out, $2,100 after time runs out. It does not surprise me that those who make CryptoLocker are doing this. I'm sure that quite a few people are desperate to get their files back. This is somewhat smart considering that the page is completely independent of how much time the ransomware says you have.
Thank you for reading. Feel free to comment if you have any questions or comments.
---------------------------------------------------------------------------------------------------------------
Updated 11/7/2013:
The price of the "late payment" option keeps going up along with the price of Bitcoins. As the price goes up for one Bitcoin (about $300 at this point), the price of the late payment will go up (about $3,000 at this point.)
I would highly recommend that if you are infected with this, you make it your top priority to determine if you have any other options then to pay the ransom. If you find out before time is up, you can still pay the $300 flat rate via a GreenDot MoneyPak card. At this point, it will save you $2,700, but this figure can change. And if Bitcoin takes a big dive, odds are good that those that make CryptoLocker will no longer take it.
Wednesday, October 30, 2013
Summing Up CryptoLocker.
After a month, the news of the CryptoLocker ransomware has finally hit the mainstream media. Leaving me questioning where they have been.
I was one of the first to report on it, and as far as I can tell, the first independent blogger to report on it.
Unfortunately, along with the mainstream coverage of this ransomware comes quite a bit of dangerous misinformation. This blog post will attempt to gather the truth about what we know in order to help those infected.
Infection:
As of now, the infection seems to be spreading through email. In the office, this email may claim to have a new protocol that needs to be looked at. At home, it may claim to be from Fedex or UPS. This email claims that you have a package waiting for you and you need to print out a receipt to claim it.
In either case, the attachment is a zipped up executable that contains the ransomware. You go to unzip it and read the "document" when all of a sudden, CryptoLocker pops up.
At this point, you are now infected. There's no going back from here. Your files are encrypted.
Encryption:
CryptoLocker does not lie when it says it encrypts your files. It encrypts files with RSA 2048 bit encryption. Which is a very safe encryption that has never been broken and likely will not be for at least another 10 years.
This means that you cannot decrypt the files.
Recovery of Files:
If you do pay the ransom, the program does actually decrypt your files. And while I would not advocate paying the ransom, it may be needed if you have exhausted all other alternatives. You know you are just encouraging the writers to keep making ransomware, but your files might be worth more to you then the $300 it demands.
Another way is with a program called Shadow Explorer. This program finds Shadow Copies of your files that are saved at System Restore points.
The bad news is that it only works with Computers running Windows XP with the second service pack installed or higher. With the exception of the home oriented editions of Windows Vista. And Windows 8 does not have it enabled by default.
So, if you run Windows 8, you may want to make a change in case you do get infected.
You can find how to activate File History here:
http://windows.microsoft.com/en-us/windows-8/how-use-file-history
http://windows.microsoft.com/en-us/windows-8/set-drive-file-history
Removal:
Recovering the encrypted files may be the hard part, but removing the actual ransomware is easy. Although you should not do this unless you know you have Shadow Copies of the encrypted files that you can get. For your convenience, the guide below deals with removal including recovering your files.
Step 1: Download Shadow Explorer here: http://www.shadowexplorer.com/downloads.html
Step 2: Run the executable and install Shadow Explorer.
Step 3: Select the disk name and time you wish to restore from. This time should be before the infection took place.
Step 4: Right click on a folder and click export. You will then be asked where you want to export to. Export to a convenient location for you.
Step 5: Repeat step 4 until all folders and files have been restored.
Step 6: Download and install MalwareBytes Anti-Malware from here: http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button
Step 7: Once you have installed MalwareBytes Anti-Malware, run a full scan. This scan will take some time, most likely over an hour depending on how much you have on your computer. So I suggest you do something else while remaining in close distance to the computer to that you can check on the scan every 15 minutes.
Step 8: Once the scan is finished, you will be alerted that malware was found. Please click OK on this message box to view the infections.
Step 9: If an infection is not checked, leave it alone. These are PUPs and are not harmful.
Step 10: Click on remove selected and allow it to restart your computer when prompted.
Step 11: Your computer should now be free of the CryptoLocker ransomware.
Please note that this removal guide might not work in some cases. If this is the case, you may be forced to reinstall the ransomware via the link given on the desktop wallpaper it sets. Once you have done this, you have no option remaining but to pay the ransom via the following ways:
GreenDot MoneyPak
Bitcoin
Ukash
For info on how to prevent yourself from getting infected with CryptoLocker, please read this blog post: http://www.malwareaware.com/2013/10/cryptolocker-prevention.html
Thank you for reading. Feel free to comment if you have any questions or comments.
I was one of the first to report on it, and as far as I can tell, the first independent blogger to report on it.
Unfortunately, along with the mainstream coverage of this ransomware comes quite a bit of dangerous misinformation. This blog post will attempt to gather the truth about what we know in order to help those infected.
Infection:
As of now, the infection seems to be spreading through email. In the office, this email may claim to have a new protocol that needs to be looked at. At home, it may claim to be from Fedex or UPS. This email claims that you have a package waiting for you and you need to print out a receipt to claim it.
In either case, the attachment is a zipped up executable that contains the ransomware. You go to unzip it and read the "document" when all of a sudden, CryptoLocker pops up.
At this point, you are now infected. There's no going back from here. Your files are encrypted.
Encryption:
CryptoLocker does not lie when it says it encrypts your files. It encrypts files with RSA 2048 bit encryption. Which is a very safe encryption that has never been broken and likely will not be for at least another 10 years.
This means that you cannot decrypt the files.
Recovery of Files:
If you do pay the ransom, the program does actually decrypt your files. And while I would not advocate paying the ransom, it may be needed if you have exhausted all other alternatives. You know you are just encouraging the writers to keep making ransomware, but your files might be worth more to you then the $300 it demands.
Another way is with a program called Shadow Explorer. This program finds Shadow Copies of your files that are saved at System Restore points.
The bad news is that it only works with Computers running Windows XP with the second service pack installed or higher. With the exception of the home oriented editions of Windows Vista. And Windows 8 does not have it enabled by default.
So, if you run Windows 8, you may want to make a change in case you do get infected.
You can find how to activate File History here:
http://windows.microsoft.com/en-us/windows-8/how-use-file-history
http://windows.microsoft.com/en-us/windows-8/set-drive-file-history
Removal:
Recovering the encrypted files may be the hard part, but removing the actual ransomware is easy. Although you should not do this unless you know you have Shadow Copies of the encrypted files that you can get. For your convenience, the guide below deals with removal including recovering your files.
Step 1: Download Shadow Explorer here: http://www.shadowexplorer.com/downloads.html
Step 2: Run the executable and install Shadow Explorer.
Step 3: Select the disk name and time you wish to restore from. This time should be before the infection took place.
Step 4: Right click on a folder and click export. You will then be asked where you want to export to. Export to a convenient location for you.
Step 5: Repeat step 4 until all folders and files have been restored.
Step 6: Download and install MalwareBytes Anti-Malware from here: http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button
Step 7: Once you have installed MalwareBytes Anti-Malware, run a full scan. This scan will take some time, most likely over an hour depending on how much you have on your computer. So I suggest you do something else while remaining in close distance to the computer to that you can check on the scan every 15 minutes.
Step 8: Once the scan is finished, you will be alerted that malware was found. Please click OK on this message box to view the infections.
Step 9: If an infection is not checked, leave it alone. These are PUPs and are not harmful.
Step 10: Click on remove selected and allow it to restart your computer when prompted.
Step 11: Your computer should now be free of the CryptoLocker ransomware.
Please note that this removal guide might not work in some cases. If this is the case, you may be forced to reinstall the ransomware via the link given on the desktop wallpaper it sets. Once you have done this, you have no option remaining but to pay the ransom via the following ways:
GreenDot MoneyPak
Bitcoin
Ukash
For info on how to prevent yourself from getting infected with CryptoLocker, please read this blog post: http://www.malwareaware.com/2013/10/cryptolocker-prevention.html
Thank you for reading. Feel free to comment if you have any questions or comments.
Thursday, October 24, 2013
CryptoLocker Prevention.
It's been some time since I last wrote about the ransomware called CryptoLocker. A piece of ransomware that actually encrypts your files so that you cannot access them without paying the ransom.
Fortunately, a utility has been written by FoolishIT which will set up software restriction policies on Windows. These restriction policies will prevent the execution of CryptoLocker. And they will also prevent the execution of the now included Zbot Trojan.
What follows is a step by step guide to setting the restriction policies up using the utility.
Step #1: Download the utility here: http://www.foolishit.com/download/cryptoprevent/
Step #2: Make sure that the open with Windows Explorer option is selected and then click on the Open button.
Step #3: Somewhere at the top of the Windows Explorer window, you should see an option to extract all files. Choose that option and extract the files to the folder.
Step #4: Double click CryptoPrevent.exe to execute the utility.
Step #5: On the screen that just popped up, press OK.
Step #6: On the new screen, make sure all checkboxes are checked.
Step #7: Click on the Block button. This shall set up the restriction policies which will prevent the execution of CryptoLocker.
Step #8: To make sure it worked, click on the Test button. It will return with either success or failure. Success means that the included test executable was able to get through. Failure means that it was blocked.
If you find that the restriction causes issues with some of your applications, you can go back to the utility and click on the Undo button to remove the changes. After you are done with that application, you can go back and click on the Block button again to set up the restrictions again.
Please note that this utility merely prevents you from getting infected. It does no good if you are already infected.
For more info about the utility, please visit this website: http://www.foolishit.com/vb6-projects/cryptoprevent/
Thank you for reading. Feel free to comment if you have any questions or comments.
Fortunately, a utility has been written by FoolishIT which will set up software restriction policies on Windows. These restriction policies will prevent the execution of CryptoLocker. And they will also prevent the execution of the now included Zbot Trojan.
What follows is a step by step guide to setting the restriction policies up using the utility.
Step #1: Download the utility here: http://www.foolishit.com/download/cryptoprevent/
Step #2: Make sure that the open with Windows Explorer option is selected and then click on the Open button.
Step #3: Somewhere at the top of the Windows Explorer window, you should see an option to extract all files. Choose that option and extract the files to the folder.
Step #4: Double click CryptoPrevent.exe to execute the utility.
Step #5: On the screen that just popped up, press OK.
Step #6: On the new screen, make sure all checkboxes are checked.
Step #7: Click on the Block button. This shall set up the restriction policies which will prevent the execution of CryptoLocker.
Step #8: To make sure it worked, click on the Test button. It will return with either success or failure. Success means that the included test executable was able to get through. Failure means that it was blocked.
If you find that the restriction causes issues with some of your applications, you can go back to the utility and click on the Undo button to remove the changes. After you are done with that application, you can go back and click on the Block button again to set up the restrictions again.
Please note that this utility merely prevents you from getting infected. It does no good if you are already infected.
For more info about the utility, please visit this website: http://www.foolishit.com/vb6-projects/cryptoprevent/
Thank you for reading. Feel free to comment if you have any questions or comments.
Wednesday, September 18, 2013
Recaping CryptoLocker.
This is going to be a recap post going over some of the stuff I have covered as far as the CryptoLocker ransomware.
It seems to be spreading via social media and old school email Trojans. So, it can be avoided via email by not downloading any exe files via email. And if the file name contains .zip, walk away.
Removing it is the easy part. You can remove it with the Kickstarter program of Hitman Pro, or Malwarebytes Anti-Malware in safe mode. Both of these have been proven to work with CryptoLocker. And when I say that removing it is the easy part, I am not joking. CryptoLocker encrypts your files with RSA 2048 bit encryption. This type of encryption has never been broken before and likely will not be broken for at least 10 years. So... no decryption tool can be written in the foreseeable future.
But there is a possible way to recover your files. In select versions of Windows, (Vista and 7) you can restore your files to a previous state using Shadow Explorer. Shadow Explorer is a freeware program that you can find on the internet. It does nothing but access the file restore function of Windows which is built-in to System Restore. Be careful to restore your files to a date before the event.
On Windows 8, if you do not already have File History enabled, it is too late if you are infected. File History is disabled by default, but you can enable it by following the guides that Microsoft provides for enabling it.
http://windows.microsoft.com/en-us/windows-8/set-drive-file-history
If you do not have System Restore or File History enabled and you are infected, there is not much you can do. If there is no system restore point, then your only viable options left are to either pay the ransom, buy a new hard drive, or restore from a backup that you would need to have ahead of time.
If given the choice, I would buy a new hard drive rather then pay the ransom. You have no idea what you are funding when you pay the people who write the ransomware. And doing this only encourages these people to keep doing what they know is working.
However, I do understand the importance of restoring your files. And depending you the variant you have and what kind of hard drive you have, it can cost more to replace the hard drive then to pay the ransom.
Offline backups are the only surefire way to get all of your files back again. If you are now planing to do that in order to prepare for if you do get infected, I recommend an external hard drive. You can find one that holds 500 GBs for somewhere in the neighborhood of $50.
Thank you for reading. I invite readers to comment with any questions or comments.
And to those of you who have read every post I have written about this, I greatly appreciate it. I hope that this series of posts has not seemed boring or annoying. I really have tried to make it all nice and informative.
Thank You.
It seems to be spreading via social media and old school email Trojans. So, it can be avoided via email by not downloading any exe files via email. And if the file name contains .zip, walk away.
Removing it is the easy part. You can remove it with the Kickstarter program of Hitman Pro, or Malwarebytes Anti-Malware in safe mode. Both of these have been proven to work with CryptoLocker. And when I say that removing it is the easy part, I am not joking. CryptoLocker encrypts your files with RSA 2048 bit encryption. This type of encryption has never been broken before and likely will not be broken for at least 10 years. So... no decryption tool can be written in the foreseeable future.
But there is a possible way to recover your files. In select versions of Windows, (Vista and 7) you can restore your files to a previous state using Shadow Explorer. Shadow Explorer is a freeware program that you can find on the internet. It does nothing but access the file restore function of Windows which is built-in to System Restore. Be careful to restore your files to a date before the event.
On Windows 8, if you do not already have File History enabled, it is too late if you are infected. File History is disabled by default, but you can enable it by following the guides that Microsoft provides for enabling it.
If you do not have System Restore or File History enabled and you are infected, there is not much you can do. If there is no system restore point, then your only viable options left are to either pay the ransom, buy a new hard drive, or restore from a backup that you would need to have ahead of time.
If given the choice, I would buy a new hard drive rather then pay the ransom. You have no idea what you are funding when you pay the people who write the ransomware. And doing this only encourages these people to keep doing what they know is working.
However, I do understand the importance of restoring your files. And depending you the variant you have and what kind of hard drive you have, it can cost more to replace the hard drive then to pay the ransom.
Offline backups are the only surefire way to get all of your files back again. If you are now planing to do that in order to prepare for if you do get infected, I recommend an external hard drive. You can find one that holds 500 GBs for somewhere in the neighborhood of $50.
Thank you for reading. I invite readers to comment with any questions or comments.
And to those of you who have read every post I have written about this, I greatly appreciate it. I hope that this series of posts has not seemed boring or annoying. I really have tried to make it all nice and informative.
Thank You.
Sunday, September 15, 2013
Info on the type of ransomware we are dealing with.
CryptoLocker is not the first piece of malware to encrypt the files of a computer. And chances are it will not be the last. This post will offer info on this type of infection as a whole.
First off, this type of malware is not new at all. The first piece of malware to encrypt files was a piece of malware which was called "PC Cyborg." Written in 1989, this malware claimed that a user's license to use a certain piece of software had expired. It then required the user to pay 189 US Dollars to unlock the system.
Ransomware that encrypts files is the new breed of moneymaker for malware writers. And considering that it has become relatively easy to encrypt files, this can now be done by an individual or a small group rather then a large company.
In the past, rogue antivirus programs were seen as the main moneymaker. But credit card merchants have caught on to this fact, which is one of the reasons why the amount of rogue antivirus software is decreasing.
Now, ransomware authors demand payment via a prepaid card such as GreenDot MoneyPak, ukash, and now BitCoins. They do this because payment via one of these methods is somewhat like cash. It's virtually untraceable and once the money is gone, it's gone.
Education is the only way to prevent infection unfortunately. Without education, users will continue to open email attachments they shouldn't, use weak passwords, and go to websites that they should not.
I suggest that no one pay the ransomware. Doing so only encourages the writer or writers to continue because the scam is working. Besides that, there is no way of knowing what you are funding when you pay. For all a user who pays knows, he or she could be funding terrorism.
But by the same token, I know that sometimes it is important for a user to get his or her files back using any means necessary.
And as for steps that a user should take to avoid having to pay, should he or she get infected, backups are the only clear way to do it. Writing decryption tools is hard work and will not always succeed.
And because of the fact that the type of encryption that is now being used by the ransomware has never been broken before, it leaves little hope that decryption tools will be a safe bet for a long time to come.
First off, this type of malware is not new at all. The first piece of malware to encrypt files was a piece of malware which was called "PC Cyborg." Written in 1989, this malware claimed that a user's license to use a certain piece of software had expired. It then required the user to pay 189 US Dollars to unlock the system.
Ransomware that encrypts files is the new breed of moneymaker for malware writers. And considering that it has become relatively easy to encrypt files, this can now be done by an individual or a small group rather then a large company.
In the past, rogue antivirus programs were seen as the main moneymaker. But credit card merchants have caught on to this fact, which is one of the reasons why the amount of rogue antivirus software is decreasing.
Now, ransomware authors demand payment via a prepaid card such as GreenDot MoneyPak, ukash, and now BitCoins. They do this because payment via one of these methods is somewhat like cash. It's virtually untraceable and once the money is gone, it's gone.
Education is the only way to prevent infection unfortunately. Without education, users will continue to open email attachments they shouldn't, use weak passwords, and go to websites that they should not.
I suggest that no one pay the ransomware. Doing so only encourages the writer or writers to continue because the scam is working. Besides that, there is no way of knowing what you are funding when you pay. For all a user who pays knows, he or she could be funding terrorism.
But by the same token, I know that sometimes it is important for a user to get his or her files back using any means necessary.
And as for steps that a user should take to avoid having to pay, should he or she get infected, backups are the only clear way to do it. Writing decryption tools is hard work and will not always succeed.
And because of the fact that the type of encryption that is now being used by the ransomware has never been broken before, it leaves little hope that decryption tools will be a safe bet for a long time to come.
Four Questions about CryptoLocker.
For this blog post, I would like to take the time to answer some questions posed by some readers of my blog who wanted to know more about CryptoLocker. And these were such good questions that I decided to make a blog post out of them. In order to respect the privacy of others, I will not publish names or email addresses.
Question #1: "If someone paid the ransom, would they send you the key?"
Answer: The way CryptoLocker does it is automatic once your payment has been processed. No need to enter in a key. Please note that there will most likely be copycats of this ransomware that will be less honest. Like not decrypting the files when you pay.
Question #2: "Would using a sandboxed browser prevent the infection?"
Answer: A sandboxed browser would protect users from some vectors of attack. There are two main methods that CryptoLocker is spreading.
1. Old school email attachment Trojans, which trick you into opening an email attachment.
2. Botnets. Which are computers that have been hijacked by the malware writers and have unwittingly become vectors of infection.
Neither of these methods would be effected by a sandboxed browser, at least in the short run. A sandboxed browser might prevent some botnets from coming in. But if you already have the botnet, it is too late unless you remove the botnets first.
Question #3: " Is any antivirus software able to block CryptoLocker?"
Answer: Some can catch it before it gets on your computer. And as time goes on, antivirus software will be better at catching this. Right now, quite a few pieces of antivirus software can only detect the ransomware AFTER you are infected and your files have been encrypted.
That said, the goal of any malware is to go unnoticed by antivirus software for as long as possible. And it really does not take the much of a modification to the code to ensure that it is not detected by antivirus software.
Question #4: Do you know if the NSA has a backdoor to whoever wrote CryptoLocker? If they have a backdoor, then surely they would be able to retrieve the key that CryptoLocker uses, right?
Answer: Before I get on with my answer, I would like to thank the person who asked the question. If you are reading, thanks for thinking out of the box.
I really do not know if the NSA has a backdoor to whoever wrote it. If they do, they will likely not release the backdoor to the public.
But I do know that the US Government is at least looking into this. It seems that CryptoLocker has hit some of the FBI's servers. And it would be wise of any government to investigate a cybersecurity issue if it starts knocking on the door loudly like CryptoLocker has.
Thank you for reading. And if you have any comments or questions about CryptoLocker, comment below. I just might use your question in a future blog post.
Question #1: "If someone paid the ransom, would they send you the key?"
Answer: The way CryptoLocker does it is automatic once your payment has been processed. No need to enter in a key. Please note that there will most likely be copycats of this ransomware that will be less honest. Like not decrypting the files when you pay.
Question #2: "Would using a sandboxed browser prevent the infection?"
Answer: A sandboxed browser would protect users from some vectors of attack. There are two main methods that CryptoLocker is spreading.
1. Old school email attachment Trojans, which trick you into opening an email attachment.
2. Botnets. Which are computers that have been hijacked by the malware writers and have unwittingly become vectors of infection.
Neither of these methods would be effected by a sandboxed browser, at least in the short run. A sandboxed browser might prevent some botnets from coming in. But if you already have the botnet, it is too late unless you remove the botnets first.
Question #3: " Is any antivirus software able to block CryptoLocker?"
Answer: Some can catch it before it gets on your computer. And as time goes on, antivirus software will be better at catching this. Right now, quite a few pieces of antivirus software can only detect the ransomware AFTER you are infected and your files have been encrypted.
That said, the goal of any malware is to go unnoticed by antivirus software for as long as possible. And it really does not take the much of a modification to the code to ensure that it is not detected by antivirus software.
Question #4: Do you know if the NSA has a backdoor to whoever wrote CryptoLocker? If they have a backdoor, then surely they would be able to retrieve the key that CryptoLocker uses, right?
Answer: Before I get on with my answer, I would like to thank the person who asked the question. If you are reading, thanks for thinking out of the box.
I really do not know if the NSA has a backdoor to whoever wrote it. If they do, they will likely not release the backdoor to the public.
But I do know that the US Government is at least looking into this. It seems that CryptoLocker has hit some of the FBI's servers. And it would be wise of any government to investigate a cybersecurity issue if it starts knocking on the door loudly like CryptoLocker has.
Thank you for reading. And if you have any comments or questions about CryptoLocker, comment below. I just might use your question in a future blog post.
Friday, September 13, 2013
More info on CryptoLocker Ransomware.
If you or someone you know has been infected with this, you might
already know. But there is a new piece of ransomware making the rounds
on the internet. It is called CryptoLocker.
To remove it is simple. Simply follow the removal guide that is in the last blog post. But the hard part is figuring out how to decrypt the files that it actually does encrypt. So, actual removal of the malicious files and registry entries is only half of the battle.
Before we go into the possibilities for decryption, the main thing to take from this blog post is that the ransomware seems to be spreading via an email attachment. Look out for files in emails that have file name extensions such as .doc.exe or .doc.scr. If there is something more then .doc, (or whatever the file is) it is possible that it may be the ransomware.
My advice is that you do not download attachments coming from an email that match the criteria above. Especially if the file name includes .zip. And if the file comes from FedEx, UPS, or any agency that claims you have a package waiting, delete the email without downloading the attachment. If you are actually expecting a package, call the agency and ask. Do not trust an email.
Now, as for decryption: The ransomware uses 2048-bit RSA encryption and a public and private AES 256 key to encrypt your files. Translation: Whoever wrote this ransomware did not cut any corners when it came to decryption. He or she wanted to make it extremely difficult to decrypt the files affected. These files include documents, excel spreadsheets, powerpoint presentations, PDF files, and photos.
The best way to combat this is offline backups of the affected files which you needed to make prior to infection. But there has been limited success with using System Restore and File Restore on newer versions of Windows (Newer then XP.)
And please note that as a very last resort only, paying the ransom does seem to work.
Never thought that I would say that paying is a viable option? Well sometimes the malware wins. Sometimes the writer is clever enough so that he wins a round. And I only recommend paying the ransom as a last resort when all other possibilities have been exhausted. And then only when you absolutely need the files. Because if you pay, you can't really know just what it is you are funding.
I recommend that whoever has exhausted all other options hold off on paying the ransom as long as possible.
Other then the above, there is no currently known way as of this writing to get the files back. However, TrendMicro says that they are currently working on a decryption tool, so we will see where that goes.
As the ransomware needs to be downloaded and executed for the effect to take place, I recommend not opening any files downloaded from the internet (including email) until said file has been scanned with your antivirus software. As most antivirus software have definitions for the ransomware, it should give you a reasonable chance of avoiding this ransomware.
I predict that this type of ransomware is the new breed of moneymaker for malware writers. And because making decryption tools takes some time, (at least a few days after discovery) it is not wise to count on ways of decryption.
I recommend offline backups of your important files to ensure that you are prepared should you ever be hit with encrypting ransomware. You can create offline backups without any special software. All you really need is a flash drive which can store a sizable amount of files, or if you work with a very large volume of files, an external hard drive.
These options are not expensive. You can get a Terabyte of storage for for somewhere in the neighborhood of $50.
Thank you for reading. I invite readers to comment with any questions or comments.
----------------------------------------------------------------------------------------------------------------------------------------------------
Update: Friday, 13 September 2013 21:00 CST.
A way to restore files to previous versions has been uncovered. This helps for the following versions of Windows:
Windows Vista Business Edition.
Windows Vista Ultimate Edition.
All Editions of Windows 7.
These versions of Windows have a feature which allows you to restore previous versions of files. This is enabled by default. Microsoft just does not provide an interface for it. A freeware program called Shadow Explorer allows you to restore these previous versions of the affected files. I'm not going to put a link up, but you can Google it and it will be easy to find.
In Windows 8, the feature is called File History. It is disabled by default, which means that if you are not infected with this, you need to enable it.
Follow the following guides on setting up File History:
http://windows.microsoft.com/en-us/windows-8/how-use-file-history
http://windows.microsoft.com/en-us/windows-8/set-drive-file-history
Stay tuned to this blog for further breaking news on the CryptoLocker ransomware. If this works in all cases, we might have won.
To remove it is simple. Simply follow the removal guide that is in the last blog post. But the hard part is figuring out how to decrypt the files that it actually does encrypt. So, actual removal of the malicious files and registry entries is only half of the battle.
Before we go into the possibilities for decryption, the main thing to take from this blog post is that the ransomware seems to be spreading via an email attachment. Look out for files in emails that have file name extensions such as .doc.exe or .doc.scr. If there is something more then .doc, (or whatever the file is) it is possible that it may be the ransomware.
My advice is that you do not download attachments coming from an email that match the criteria above. Especially if the file name includes .zip. And if the file comes from FedEx, UPS, or any agency that claims you have a package waiting, delete the email without downloading the attachment. If you are actually expecting a package, call the agency and ask. Do not trust an email.
Now, as for decryption: The ransomware uses 2048-bit RSA encryption and a public and private AES 256 key to encrypt your files. Translation: Whoever wrote this ransomware did not cut any corners when it came to decryption. He or she wanted to make it extremely difficult to decrypt the files affected. These files include documents, excel spreadsheets, powerpoint presentations, PDF files, and photos.
The best way to combat this is offline backups of the affected files which you needed to make prior to infection. But there has been limited success with using System Restore and File Restore on newer versions of Windows (Newer then XP.)
And please note that as a very last resort only, paying the ransom does seem to work.
Never thought that I would say that paying is a viable option? Well sometimes the malware wins. Sometimes the writer is clever enough so that he wins a round. And I only recommend paying the ransom as a last resort when all other possibilities have been exhausted. And then only when you absolutely need the files. Because if you pay, you can't really know just what it is you are funding.
I recommend that whoever has exhausted all other options hold off on paying the ransom as long as possible.
Other then the above, there is no currently known way as of this writing to get the files back. However, TrendMicro says that they are currently working on a decryption tool, so we will see where that goes.
As the ransomware needs to be downloaded and executed for the effect to take place, I recommend not opening any files downloaded from the internet (including email) until said file has been scanned with your antivirus software. As most antivirus software have definitions for the ransomware, it should give you a reasonable chance of avoiding this ransomware.
I predict that this type of ransomware is the new breed of moneymaker for malware writers. And because making decryption tools takes some time, (at least a few days after discovery) it is not wise to count on ways of decryption.
I recommend offline backups of your important files to ensure that you are prepared should you ever be hit with encrypting ransomware. You can create offline backups without any special software. All you really need is a flash drive which can store a sizable amount of files, or if you work with a very large volume of files, an external hard drive.
These options are not expensive. You can get a Terabyte of storage for for somewhere in the neighborhood of $50.
Thank you for reading. I invite readers to comment with any questions or comments.
----------------------------------------------------------------------------------------------------------------------------------------------------
Update: Friday, 13 September 2013 21:00 CST.
A way to restore files to previous versions has been uncovered. This helps for the following versions of Windows:
Windows Vista Business Edition.
Windows Vista Ultimate Edition.
All Editions of Windows 7.
These versions of Windows have a feature which allows you to restore previous versions of files. This is enabled by default. Microsoft just does not provide an interface for it. A freeware program called Shadow Explorer allows you to restore these previous versions of the affected files. I'm not going to put a link up, but you can Google it and it will be easy to find.
In Windows 8, the feature is called File History. It is disabled by default, which means that if you are not infected with this, you need to enable it.
Follow the following guides on setting up File History:
http://windows.microsoft.com/en-us/windows-8/how-use-file-history
http://windows.microsoft.com/en-us/windows-8/set-drive-file-history
Stay tuned to this blog for further breaking news on the CryptoLocker ransomware. If this works in all cases, we might have won.
How to remove the CryptoLocker Ransomware.
There is a new piece of ransomware making the rounds on the internet. It is called CryptoLocker.
For those of you who do not know, ransomware blocks you from using your computer in some way. It then demands payment for the unlocking of your computer.
I have posted the steps for removal below.
Step 1: Get a flash drive that can store at least 32 MB
Step 2: On an uninfected computer, go to http://www.bleepingcomputer.com/download/hitmanpro/ and download the bit version corresponding to the bit type of the uninfected computer.
Step 3: Once the file has been downloaded, insert the flash drive you are going to use.
Step 4: Run the downloaded file.
Step 5: Once you see the start screen of Hitman Pro, click on the little picture of a person preforming a kick at the bottom of the window.
Step 6: You will now see instructions on how to create the Kickstarter Live USB. Click on the flash drive you will be using, then press install kickstart. You will then be presented with a warning that the flash drive will be erased. Click on yes to continue.
Step 7: Once the files have been downloaded and installed onto the flash drive, click the close button and take out the flash drive.
Step 8: Insert the flash drive into the infected computer with the computer turned off. Turn it on and then look for info on how to access the boot menu. If you cannot see any info, keys commonly used for the boot menu are F8, F11, or F12.
Step 9: Restart your computer and start tapping the indicated key. If one key does not work restart the computer and try another key on the above list.
Step 10: Now, select the flash drive with the Kickstart program installed and press enter. Once you see the new screen, press 1.
Step 11: Windows will load normally. After you log in, you will see the ransomware. Wait 15-20 seconds and you will see the Hitman Pro start screen. Click next to start the scanning process.
Step 12: Click No, I only want to perform a one-time scan to check this computer. Then click next.
Step 13: Once Hitman Pro has finished scanning, it will display a list of malware that it found. Click next, and if prompted, choose the 30 day free trial. Hitman Pro will now reboot your computer. When it is rebooted it should be free of the ransomware.
Thank you for reading. I invite readers to comment with any questions or comments.
Please read the companion to this blog post here: http://malwareaware.blogspot.com/2013/09/more-info-on-cryptolocker-ransomware.html
For those of you who do not know, ransomware blocks you from using your computer in some way. It then demands payment for the unlocking of your computer.
I have posted the steps for removal below.
Step 1: Get a flash drive that can store at least 32 MB
Step 2: On an uninfected computer, go to http://www.bleepingcomputer.com/download/hitmanpro/ and download the bit version corresponding to the bit type of the uninfected computer.
Step 3: Once the file has been downloaded, insert the flash drive you are going to use.
Step 4: Run the downloaded file.
Step 5: Once you see the start screen of Hitman Pro, click on the little picture of a person preforming a kick at the bottom of the window.
Step 6: You will now see instructions on how to create the Kickstarter Live USB. Click on the flash drive you will be using, then press install kickstart. You will then be presented with a warning that the flash drive will be erased. Click on yes to continue.
Step 7: Once the files have been downloaded and installed onto the flash drive, click the close button and take out the flash drive.
Step 8: Insert the flash drive into the infected computer with the computer turned off. Turn it on and then look for info on how to access the boot menu. If you cannot see any info, keys commonly used for the boot menu are F8, F11, or F12.
Step 9: Restart your computer and start tapping the indicated key. If one key does not work restart the computer and try another key on the above list.
Step 10: Now, select the flash drive with the Kickstart program installed and press enter. Once you see the new screen, press 1.
Step 11: Windows will load normally. After you log in, you will see the ransomware. Wait 15-20 seconds and you will see the Hitman Pro start screen. Click next to start the scanning process.
Step 12: Click No, I only want to perform a one-time scan to check this computer. Then click next.
Step 13: Once Hitman Pro has finished scanning, it will display a list of malware that it found. Click next, and if prompted, choose the 30 day free trial. Hitman Pro will now reboot your computer. When it is rebooted it should be free of the ransomware.
Thank you for reading. I invite readers to comment with any questions or comments.
Please read the companion to this blog post here: http://malwareaware.blogspot.com/2013/09/more-info-on-cryptolocker-ransomware.html
Subscribe to:
Posts (Atom)