Showing posts with label cryptolocker. Show all posts
Showing posts with label cryptolocker. Show all posts

Tuesday, March 3, 2015

Security Update: New malware and threats to PC security

Destroying your hard drive is the only way to stop this super-advanced malware

"Kaspersky published a detailed report Monday about Equation, which it considers the most advanced group of attackers to date and whose activity spans back to 2001 and possibly even to 1996. Even though the company stopped short of directly linking the group to the U.S. National Security Agency, there are significant details that point to such links."  PCWorld

A couple of years ago I published a blog post about the Stuxnet worm which infected and wreaked havoc to the Iranian centrifuges that were attempting to develop nuclear fissionable material for Iran's nuclear program.  Groups studying the code for the worm attributed the code writers to clandestine players, the CIA or NSA.  The problem was the code escaped and was utilized by crime groups to infiltrate the general PC population. Today there is a new threat that delivers it's threat by modifying the firmware of your hard drive.  Firmware is the low level code that acts as the interface between the software and hardware.  It is contained in the chips solder into the hard drive's interface board.  Once installed it is impossible to remove.  Formatting and re-installing the operating system has no affect and the malware remains in the chip ready to deliver it's payload.




Help for the Cryptolocker (FBI) virus

The Cryptolocker virus made the news last year.  It is a particularly destructive malware program that encrypts, Word, Excel, PDFs and JPEG files to name a few and tries to force you to pay a ransom for the key to unlock your files.  Without the encryption key there is no way to recover your files without a good backup.

A client of mine was attacked last year, it occurred over a weekend so by Monday all of her documents, spreadsheets and pictures were locked and unusable.  I was able to remove the malware but it was too late for her files.  At that time I noticed that she had Carbonite and it was in the process of backing up the encrypted (changed) files.  I stopped Carbonite and she was able to contact Carbonite tech support and recover her files by restoring a back up that occurred prior to the date of infection.

The good news about Cryptolocker is that a group has somehow acquired the ransom keys used to unlock the files.  If you are attacked, submit to them a file that is encrypted and they will provide you with the key needed to unlock your files.  Be alert and please have a good backup.


Google Chrome browser targeted

Recently I have seen an uptick in malware targeting Google's Chrome browser.  In each case the malware was delivered while the user was attempting to download a program they had Googled searched for. The delivery method for a lot of the new malware is distribution via junk email attachments, malicious torrents and particularly free applications. When searching for software using a search engine, the first listings in the search will be ads or sites that purport to be a download site for the desired software.  In most cases the listings are either scam sites which attempt to direct trick you to download alternative software/malware, or they deliver malware in addition to the desired program. Always carefully check the link provided if you click the link to ensure that the address is the website of the developer or manufacturer of the download you desire.

2 new Intel K CPUs, Gamer Desktops, high end components, DF Core i5-4690K, 3.5 GHz and Core i7, 4790K 4.0 GHZ

http://drivingforce.net/Blog/Q1030315.htm

Monday, March 3, 2014

Warning FBI Cryptolocker virus and Fake Funeral Notice. The depths Malware Authors will sink to in order to Infect your Computer.

FTC, FBI Warn Consumers About ‘Cryptolocker,’ A New Breed of Computer Malware

I previously warned you about the FBI Cryptolocker virus in the November 14, 2013 post.  I have had a couple of clients who dodged any problems by shutting off their computer as soon as they saw the warning and contacting me.  We were able to successfully remove the virus before it was able to do it's damage.  It's payload if left alone is to encrypt your Word, Excel, Photos, PowerPoint, videos and PDFs files.  The intent of the virus is not to so much spread but require the infected user to pay a ransom (about $300)  for a key to unlock your files.  The following info is from the FTC.gov website

Cryptolocker is spread mostly through email and “drive-by” downloads. The email might look like a routine message from a legitimate company, like a tracking notice from a shipping company. If you click on the hyperlink in the email, Cryptolocker encrypts everything on your hard drive and in your shared folders. When the job is done, you get a “ransom note” demanding payment via Bitcoin or some other anonymous payment method. The criminals behind this malware say they’ll give you the encryption key if you pay, but they’re hardly trustworthy. And there’s no other way to unlock your files.

http://www.ftc.gov/news-events/press-releases/2014/02/ftc-fbi-warn-consumers-about-cryptolocker-new-breed-computer

Recently I received a 7 a.m. call from a branch office of an Atlanta client who had been infected.  I instructed the client on how to update and scan using Malwarebytes and they were able to successfully remove the malicious code.  However the damage was done.  I received a call later indicating that the user could not open any Excel or Word documents.  I remote accessed the infected computer and found that the infection had occurred around Midnight and in the 7 ensuing hours the virus had time to work it's destructive payload and encrypt all of her files.  I removed over 800 text files related to the virus and a message file from the Start up folders of the Office products.  The text file contained the following instructions,

"All files including videos, photos and documents on your computer are encrypted."

"Encryption was produced using a unique public key generated for this computer. To decrypt files, you need to obtain the private key."

"The single copy of the private key, which will allow you to decrypt the files, located on a secret server on the Internet; the server will destroy the key after a time specified in this window. After that, nobody and never will be able to restore files."

"In order to decrypt the files, open site 4sfxctgp53imlvzk.onion.to/index.php and follow the instructions."

"If 4sfxctgp53imlvzk.onion.to/index.php is not opening, please follow the steps below: "

1. You must download and install this browser http://www.torproject.org/projects/torbrowser.html.en
"2. After installation, run the browser and enter the address: 4sfxctgp53imlvzk.onion/index.php"
"3. Follow the instructions on the web-site. We remind you that the sooner you do, the more chances are left to recover the files."

IMPORTANT INFORMATION:

Your Personal CODE: 00000001-E87E0C01

The client had Carbonite backup installed so I opened the program but found that the Carbonite was set to sync new and changed files and since all of her important files had been encrypted and changed Carbonite was backing up the encrypted files.  I froze the backup to stop the service.  Fortunately Carbonite keeps historical backups but this requires you to contact Carbonite for assistance which was free since she had the pay for service. However it took over 30 hours to restore her files to a date prior to the infection via internet download.  Also, any changes or new documents/files that occurred after this backup were lost.

The bottom line is this, if you are not backing up your data you need to find a plan.  Sync programs work well but you need to have historical backups as well.  If the client had only the latest backup of her data she would have been stuck with a backup of files in a non-usable format.


Fake funeral notice can be deadly — for your computer

How Low will Criminals and Malcontents (ne'er do wells) go to Infect your Computer?

Get this, yesterday I received the following email containing a link:


Suspicious I performed a simple Google search and found out this is a relatively new attempt to infect your computers.  This too is on the FTC.gov website.


Be careful people.  Take the necessary steps to protect your data and remember when you are on the internet it's just like strolling down the street, criminals are behind every corner.

DForce Performance Workstations



Thursday, November 14, 2013

CryptoLocker Virus-Beware links in emails promising Holiday Deals and Savings

I first heard of this virus from Kaspersky support when renewing a client’s contract recently.  The support tech told me this malware is particularly nasty since it encrypts (locks) your files and demands a ransom to unencrypt (release) them.  Some people/businesses have actually paid the ransom.

I am warning my client base now because it has made the local news this a.m., it hit some users in Douglas County and the local ABC affiliate carried the story.

This virus once on a computer travels to other computers in a network environment so be careful.

It uses phishing emails to entice the recipient to open and click on a link.  The Kaspersky tech told me not to open anything from UPS, USPS, FedX and from what I have read the criminals are now attempting to trick victims with emails containing links to great deals/promises for the holidays.

Yes, of course, it looks like a great deal—and who isn’t trying to save money this holiday shopping season?—but if you click on a scam, it could cost you big. It may even ruin your computer.
That’s because scammers are using phishing emails that look like they’re coming from Amazon, Best Buy and Wal-Mart, among others, but really contain the CryptoLocker PC virus.


Backup and be careful!

TEST