Archive for the ‘virus’ Category

CryptoLocker virus/ransomeware

Tuesday, December 10th, 2013

Just to make people aware, there is a new virus (technically ransomware (http://www.microsoft.com/security/resources/ransomware-whatis.aspx) ) that is doing the rounds. It’s been in the wild for a while, but seems to be getting more media attention these days.

Basically once you click on a e-mailed link it will encrypt files it can access on your hard drive. The engineering beauty of this virus is that it encrypts your files, and then contacts you to demand a ransom in the form of bit coins (http://bitcoin.org/en/) to decrypt your drive. So it becomes a case of pay up or your data is gone, if you have backups on another drive you should be able to restore to that drive, however if your do not have backups your data is basically gone as the encryption is uncrackable at the moment.

The above has a less chance of happening if you are running non system administrative privileges, You can read more about how a US police force had to pay to get there data back on the link below, it’s a pity they didn’t have backups. http://www.theguardian.com/technology/2013/nov/21/us-police-force-pay-bitcoin-ransom-in-cryptolocker-malware-scam

You can read more on: http://www.f-secure.com/weblog/archives/00002640.html

Remove An Garda Síochána Ireland’s National Police Service Virus

Saturday, January 5th, 2013

Our friend the National Police Service Virus/Ransomware seems to have mutated, and removing it using the usual removal option listed below, seems to fail.

http://www.f-secure.com/en/web/labs_global/removal/removing-ransomware

One successful way of dealing with it is to use Kaspersky Rescue Disk 10 (https://support.kaspersky.com/4131) as running Malwarebytes or F-Secure in Safe mode fails to work, there is no changes to the registry or the Start-up folders do not have the .ink files in there. Probably the best prevention technique for virsus is to run the systems in non administrative mode, preventing rouge installs of viruses.