ZeroLocker ransomware "helps" you get your files back
Posted on 15.08.2014
In early June, the FBI has lead a rather successful multi-national effort to disrupt the GameOver Zeus botnet which was also responsible for delivering Cryptolocker. Unfortunately, that doesn't mean that users are now completely safe from that and other ransomware.

Tyler Moffitt, a member of Webroot's Threat Team, is warning about the appearance of yet another encrypting ransomware: ZeroLocker.

ZeroLocker encrypts the files itself, but the message it shows to the user makes it sound as another malicious software did it, and these people are simply trying to help by offering a decryption tool:


"This variant doesnít show the GUI untill all encryption is completed and the computer is suddenly restarted. Upon restart this window is presented and threatens that you will lose all your files if you close or remove it," explains Moffitt.

But there is also some (temporary) good news for ZeroLock victims.

"This specific variant we analyzed does not delete the VSS (Volume Shadow Service) and you can get all your files back by using programs like Shadow Explorer," says Moffitt, but believes that this particular issue will be fixes in later variants.

While security solutions can catch most malware, the best protection against ransomware is to back up your files regularly, he concluded.









Spotlight

USBdriveby: Compromising computers with a $20 microcontroller

Posted on 19 December 2014.  |  Security researcher Samy Kamkar has devised a fast and easy way to compromise an unlocked computer and open a backdoor on it: a simple and cheap ($20) pre-programmed Teensy microcontroller.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Fri, Dec 19th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //