Trojan:W32/Ransomcrypt

By | April 18, 2012

Source: F-Secure.com

In this article “We are receiving reports of a ransom trojan, it’s been circulating during the last two days.

When first run on the system, the ransomware will iterate all folders on the system. Every document, image, and shortcut (.lnk) file found will be encrypted and appended with an extension of .EnCiPhErEd. In each folder it will drop a text file called “HOW TO DECRYPT.TXT” which contains instructions on how to proceed. The bandit is demanding 50€.”

Leave a Reply