This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

File Encryptor moves to the west...

1 min read

This thread's last reply is from February 27, 2006, 12:17 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Chachazz
File encryptor moves to the west
February 24, 2006 | 14:23 GMT

We've already written about malware which encrypts files and then demands payment for decryption on several occasions.

These Trojans were found mostly in Russia. However yesterday we came across a worm with a German (speaking) background, Email-Worm.Win32.Skowor.b.

It doesn't have true Email-Worm functionality, but as it's closely connected to Email-Worm.Win32.Skowor.a we have decided to keep it in the same class.

In contrary to programs like GPCode, Skowor is able to replicate; it tries to spread via a share that it creates.

When installed, the worm displays a message telling the user that s/he has 5 pc reboots in order to get a password which can be used to uninstall the worm. If the user doesn't do this, the worm will encrypt a number of important files and change the Administrator and current user password.

The worm also changes the IE start page to the author's website....

Source: VirusList Analysts Diary»
amateur MRU Master
:shock:

Luckily (for now) the author's website was taken down on Feb 23rd according to Viruslist.com
Chachazz
glad to see it has been read, amateur

....and final comment of the article is:

None the less it's a sign of what is to come.
:D
amateur MRU Master
Quote:
None the less it's a sign of what is to come.


How true and very scary :shock: