Results 1 to 5 of 5
  1. #1
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755

    And Now, an MBR Ransomware

    And Now, an MBR Ransomware

    Posted by;Denis
    Kaspersky Lab Expert
    Posted November 29, 22:47 GMT

    Today my colleague Vitaly Kamluk wrote about a new GpCode-like ransomware which encrypts user’s files with RSA-1024 and AES-256 crypto-algorithms. We’re continuing to investigate this malware and will notify you about our findings.

    However, GpCode.ax is not the only piece of ransomware we found today. We’ve just discovered a malware which overwrites the master boot record (MBR) and demands a ransom to retrieve a password and restore the original MBR. This malware is detected as Trojan-Ransom.Win32.Seftad.a and Trojan-Ransom.Boot.Seftad.a.

    This ransomware is downloaded by Trojan.Win32.Oficla.cw.....
    Read more
    Roger and out

  2. #2
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Threat level 2
    Summary
    • Malware: Trojan-Ransom.Win32.Gpcode.ax
    • Status: low risk
    • Threat: Kaspersky Lab warns users about the emergence online of a new version of the Gpcode ransomware program.
    • Source: The program spreads via malicious websites and P2P networks.
    Last edited by Ceyfer √; 12-01-2010 at 06:59 PM. Reason: added some fancy kaspersky gfx alert icons
    "Stars and the Sun"


  3. #3
    Experienced User
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    3,271
    Liked
    155 times
    Points
    6,541
    Thanks leofelix and ceyfer I am keeping myself updated via reading their article/forum since yesterday evening. For MBR Ransomware, they have decoded the password of both samples to unlock machines. For Gpcode sample, they are working hard to decode its algorithm and find a way to get encrypted files of end users.
    Windows 7 SP1 Ultimate x86 + KIS 2011 (11.0.2.556 b.a.c.d) + Sandboxie Paid (3.54) + Deep Freeze Standard (7.20.020.3398)

  4. #4
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Thank you for the update guys, it's this sort of scum ware that gets my back up they should do jail time for this with some big hairy biker in a small cell, as BoyFriend mentioned it is important to be aware of what is out there...
    Stutz Bearcat

  5. #5
    Modern-day Romeo
    Overall activity: 0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,159
    Liked
    476 times
    Points
    61,007
    Question: Does MBRGuard and any other software that protects the MBR like Light Virtualization software prevent the ransomware even when it's launched with admin rights? What about ISR? I assume so it will but has there been cases for any particular ones that were 'bypassed'? Just curious...
    They call me the mysterious one...
    my motto is...when it's hot, chill baby

 

 

Similar Threads

  1. Ransomware spotted in the wild posing as Microsoft !!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 10
    Last Post: 09-12-2011, 11:17 AM
  2. New LoroBot ransomware encrypts files
    By Ceyfer √ in forum Spyware/Viruses
    Replies: 1
    Last Post: 10-29-2009, 01:18 PM

Tags for this Thread

All times are GMT +8. The time now is 09:06 AM.