ZeroLocker ransomware "helps" you get your files back
Posted on 15.08.2014
In early June, the FBI has lead a rather successful multi-national effort to disrupt the GameOver Zeus botnet which was also responsible for delivering Cryptolocker. Unfortunately, that doesn't mean that users are now completely safe from that and other ransomware.

Tyler Moffitt, a member of Webroot's Threat Team, is warning about the appearance of yet another encrypting ransomware: ZeroLocker.

ZeroLocker encrypts the files itself, but the message it shows to the user makes it sound as another malicious software did it, and these people are simply trying to help by offering a decryption tool:

"This variant doesn’t show the GUI untill all encryption is completed and the computer is suddenly restarted. Upon restart this window is presented and threatens that you will lose all your files if you close or remove it," explains Moffitt.

But there is also some (temporary) good news for ZeroLock victims.

"This specific variant we analyzed does not delete the VSS (Volume Shadow Service) and you can get all your files back by using programs like Shadow Explorer," says Moffitt, but believes that this particular issue will be fixes in later variants.

While security solutions can catch most malware, the best protection against ransomware is to back up your files regularly, he concluded.


101,000 US taxpayers affected by automated attack on IRS app

The IRS has revealed more details about an attack it suffered last month, mounted by unknown individuals with the aim to file fraudulent tax returns and funnel the returned money to their own bank accounts.

Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.

Daily digest

Receive a daily digest of the latest security news.

Wed, Feb 10th