Page 1 of 2 12 LastLast
Results 1 to 10 of 15
  1. #1
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077

    New Vundo Warning

    From scareware to ransomware

    FireEye, a malware specialist, reports that Vundo, which makes fake antivirus programs (scareware), has now started a new scam. Vundo is no longer merely alarming users with bogus warnings that their PCs have been infected to con them into buying largely useless scanning software. Their latest attacks (ransomware) encrypt all of the files (.pdf, .doc, .jpg and others) on a user's PC and then report garbled data.

    System messages are sent to con the user into coughing up €50 for the full version of a "repair tool", FileFix Pro 2009. In contrast to scareware, which normally only pretends there's a problem, users are left little option, because all of their files have genuinely been encrypted – although only with a simple algorithm. FireEye doesn't say how the ransomware gets on to the computers, but it probably needs a little help from the user.

    FireEye has investigated the algorithm and found that the key apparently consists of only four characters, stored at the end of an encrypted file. FireEye is providing a free Perl script and a web page implementation of the script for decryption of scrambled files. This case is similar to GPCode, a Trojan that appeared in the middle of last year, encrypting files using RSA (the Rivest, Shamir and Adleman algorithm) with a 4096-bit key.

    GPCode's authors demanded that their victims shell out $300 to get their files restored. Fortunately, it was possible to reconstruct the data at a lower cost, even without the key, because GPcode wrote the encrypted version of a document into a new file and then "deleted" the original one. Since Windows only deletes a file's reference, not the actual file itself, the originals could be successfully recovered.

    -source-
    pacman -Syyu life not found in sync db

  2. #2
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    New Vundos Variant also able to self protect itself against Sandboxie -
    "Stars and the Sun"


  3. #3
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Wonderful. Now it looks like Linux has another good point to fight with Windows no Vundo

  4. #4
    Experienced User
    Overall activity: 0%

    Join Date
    Dec 2008
    Location
    Malaysia
    Posts
    1,608
    Liked
    0 times
    Points
    8,958
    Encrypting files? So, any program can't decrypt with any program?

  5. #5
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    It can be decrypted but you need to look up that Perl script. I don't have a clue where it is.

  6. #6
    Newbie
    Overall activity: 0%

    Join Date
    Feb 2009
    Location
    Canada
    Posts
    56
    Liked
    0 times
    Points
    3,977
    owned!!!
    They had to pay 300!!!
    DotA Player :P

  7. #7
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    It's not something I'd lol about myself. But that's me because I think a virus is serious.

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    Australia
    Posts
    3,884
    Liked
    0 times
    Points
    20,463
    I don't. haha I just laugh at windows users with their viruses and slowdowns and BSoDs and crashing etc. All that stuff that windows has and ubuntu doesn't.

  9. #9
    Experienced User
    Overall activity: 0%

    Join Date
    Oct 2008
    Location
    Malaysia
    Posts
    1,381
    Liked
    0 times
    Points
    14,083
    Lol. The irony, brayden. Check your siggie..

  10. #10
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    He hasn't changed it yet, since he still uses Vista. I'm stuck using it for a little bit longer... I've got to delete a few things and back up some others.

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Are KAV able to detect Vundo
    By Odie in forum Spyware/Viruses
    Replies: 25
    Last Post: 11-09-2008, 04:33 PM
  2. Phishing Warning!
    By In-f3st in forum General Forum
    Replies: 2
    Last Post: 10-15-2008, 11:23 AM
  3. Vundo Spyware (HiJackThis Log)
    By shakstang in forum Spyware/Viruses
    Replies: 12
    Last Post: 03-07-2008, 06:04 PM
All times are GMT +8. The time now is 09:35 AM.