This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

CryptoLocker copycat may be decryptable

1 min read

This thread's last reply is from December 13, 2013, 1:09 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hot on the tail of devilish Cryptolocker comes a copycat software nasty that holds victim's files to ransom – but the newcomer's encryption is potentially breakable, we're told.

<snip>

The Locker malware uses the TurboPower LockBox library, a cryptographic toolkit for Delphi: specifically, it uses AES-CTR for encrypting the contents of files on infected devices. But shortcomings in the programming will apparently make it possible for researchers to develop skeleton keys capable of unscrambling files on compromised kit. IntelCrawler's researchers are working on a universal antidote.


Full Story @ The Register


While this doesn't mean the infection is any easier to detect or remove, hopefully IntelCrawler will release a freeware tool for decryption of files. I will update this post when further information becomes available.

sludge
ZB