Trend Micro discovers new ransomware

reghakr

New member
Local time
5:01 AM
Messages
1,614
Location
Pennsylvania
According to Trend Micro security researchers, they have detected a new ransomware that proliferates through an e-mail on the internet. Trend
Micro have called the malware WORM_RANSOM.FD that seems as a mass mailing computer worm, but a detailed analysis of it has revealed that it contains a deadly payload. It has been discovered that
WORM_RANSOM.FD downloads from remote websites when visitors access those sites or it may download secretly by other malware on the targeted system. While the deadly payload does not affect some files with
extensions such as .dry, .rwg, .vxd, .dll, .inl and .exe, the malware is
capable of encrypting all files stored in the targeted computers using Blowfish algorithm. Hence, the malware makes the files useless. Moreover, the worm makes a registry entry (ies) that allows it to do automatic execution whenever the system startup. Interestingly, the new ransomware WORM_RANSOM.FD does not follow the function of a typical
ransomware which demands money for restoring encrypted files. Instead it gives a user three options to choose from to restore the affected files.

More....
 

My Computer My Computer

Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
Among the three options, first tells the affected user to consult a reputed antivirus company that may help him to decrypt the files. The second suggestion says to the user that he could send an e-mail at [email protected] for a decryptor application to restore the affected files, while the third option includes recommendation of migrating from Windows Operating System (OS) to Linux to overcome the attack.
Besides, it has been found that the ransomware WORM_RANSOM.FD alters the filenames after encryption by adding .RWG extension. For example - if the name of an original file is DOCUMENT.TXT, then after encryption its name changes to DOCUMENT.TXT.RWG.
Security experts at Trend Micro have rated the ransonware as high-risk/moderate reward business model. This is primarily because it violates one of the main features many cyber criminals are using to develop malware. In addition, the payload could be easily seen and users are told that their files are made hostage.
With cyber criminals giving

Thanks for the information.

Probably a Linux Fanboy created this virus. Note how they asked to switch to Linux. Why would they want to do that?
 

My Computer My Computer

Computer Manufacturer/Model Number
Apple Inc.
OS
Windows 7
CPU
Intel(R) Core 2 Duo CPU T8100 @ 2.10GHz
Motherboard
MB41.88Z.00C1.B00.0802091535
Memory
1.00GB
Graphics Card(s)
Mobile Intel 965 Express Chipset Family
Sound Card
Apple Sound Card
Monitor(s) Displays
Apple Display
Screen Resolution
1280 X 800
Hard Drives
Fujitsu MHY2120BH ATA Device 110GB
PSU
The Apple PSU
Case
The Apple Case
Cooling
The Apple Cooling Fan
Keyboard
Apple Keyboard
Mouse
IBM Mouse Model MO32BO
Internet Speed
10MBPS
Yeah,

I particularly like that 3rd option
 

My Computer My Computer

Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
Back
Top