Security Bytes

Nov 2 2009   4:09PM GMT

New ransomware Trojan tricks victims to buy software fix



Posted by: Robert Westervelt
ransomeware, Ramvicrype Trojan

Trojan Horse doesn’t ask for money, but sends victims to software that can eliminate malware file extension, according to Symantec Security Response

Symantec has posted an interesting blog post about a new ransomware Trojan with a twist. Instead of asking for cash to unlock the files, the Ramvicrype Trojan encrypts files on victim computers and then sends victims seeking help via a search engine to a website where they can buy software that supposedly fixes the problem and decrypts the files. Older ransomware would push the the victim buy the keys outright.

Symantec virus researcher Shunichi Imano said in a blog entry that Ramvicrype victims will see some files on the computer with a vicrypt extension.

Entering the term ‘vicrypt’ into a search engine leads us to a company offering a fix, which of course is a charged service. So, there was a reason for that file extension after all.

The security vendor has developed a Symantec Ramvicrype removal tool for victims to decrypt the files.

Ransomware is not new. In fact, security expert Mike Chapple points out that it could be over a decade old. In an expert tip on what to do if you’re infected with ransomware, Chapple says you could reimage the drive and/or restore from backup. Check the Internet for the keys first. In many cases Chapple says others have been infected and security researchers likely have made the keys available.

Whether ransomware affects your organization directly or not, use the painful experiences of your peers to learn a lesson: install current antivirus software on all enterprise systems (especially the CEO’s laptop!). Make sure to also run regular backups and check firewall configurations.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Rgmoon  |   Jan 4 2011   6:38AM GMT

Software fix is used to fix problems or update programe or its supporting data. . So, it is good to have info related to it. Thanks for this info and provide more info related to this topic in the next post. as well.
columbia sc newspaper


 

Rgmoon  |   Apr 23 2011   8:38AM GMT

These types of tools must be used in order to update the software. These features will help to make the working easy and reliable. Thanks for providing such nice post.
Craigslist Buffalo