Daedroth Posted May 3, 2012 Share Posted May 3, 2012 It appears this nasty piece of work is picking up steam, and could be especially nasty for unsuspecting users. Hiding or locking all your files doesn't appear to be enough for some trojans. Encoder encrypts all your files and tries to force you into buying an 'unlock' code. Here are links for more information and advice: http://news.drweb.co...&c=5&lng=en&p=0 http://news.drweb.co...&c=5&lng=en&p=0 https://community.mc...tart=0&tstart=0 Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/ Share on other sites More sharing options...
butilikethecookie Posted May 3, 2012 Share Posted May 3, 2012 That's crazy! They need to be shut down! Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842389 Share on other sites More sharing options...
Hum Posted May 3, 2012 Share Posted May 3, 2012 Probably written by Norton employees. :shiftyninja: xfx and THolman 2 Share Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842395 Share on other sites More sharing options...
HighwayGlider Posted May 3, 2012 Share Posted May 3, 2012 Probably written by Norton employees. :shiftyninja: LOL man, you're nasty. Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842409 Share on other sites More sharing options...
Charisma Veteran Posted May 3, 2012 Veteran Share Posted May 3, 2012 Is this for real? O_O Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842417 Share on other sites More sharing options...
ThePitt Posted May 3, 2012 Share Posted May 3, 2012 Probably written by Norton employees. :shiftyninja: wouldnt surprise me... EDIT just in case here is the decrypter: ftp://ftp.drweb.com/pub/drweb/tools/matsnu1decrypt.exe Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842423 Share on other sites More sharing options...
Dot Matrix Posted May 3, 2012 Share Posted May 3, 2012 Ok, so the image shows Windows Xp... What about Windows Vista, Windows 7, or Windows 8? Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842433 Share on other sites More sharing options...
Marshall Veteran Posted May 3, 2012 Veteran Share Posted May 3, 2012 Ok, so the image shows Windows Xp... What about Windows Vista, Windows 7, or Windows 8? A quick google and it shows this affects Vista & 7 as well, not sure about 8. Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842441 Share on other sites More sharing options...
Detection Posted May 3, 2012 Share Posted May 3, 2012 The first article suggests: "Never attempt to solve the problem by reinstallling the operating system." Why ? If I couldn't decrypt them, that's the first thing I would do. Maybe this is aimed at people who are bothered about recovering their files ? Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842459 Share on other sites More sharing options...
_neutrino Veteran Posted May 3, 2012 Veteran Share Posted May 3, 2012 makes you wonder how stupid these virus makers are. if you have to pay them then there is a money trail. Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842461 Share on other sites More sharing options...
Miuku. Posted May 3, 2012 Share Posted May 3, 2012 makes you wonder how stupid these virus makers are. if you have to pay them then there is a money trail. Fake accounts, hijacked accounts, countries where the legality of writing software such as this is not against the law and then some people are just so desperate that they will pay and not report it to anyone else. Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842469 Share on other sites More sharing options...
Max Norris Posted May 3, 2012 Share Posted May 3, 2012 makes you wonder how stupid these virus makers are. if you have to pay them then there is a money trail. It's the usual motive for malware nowadays.. money. Stealing credentials, hijacking accounts, advertisement displays, ransomware, etc etc. Don't usually see the old "I'll nuke your bootloader just because" types of malware much anymore. Agreed with MiukuMac above too; it can be traced, but depending on where it's at, it may be near impossible to punish. Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842477 Share on other sites More sharing options...
Hell-In-A-Handbasket Posted May 3, 2012 Share Posted May 3, 2012 Kaspersky put up a removal for it ( I think it's the same ) earlier RannohDecryptor http://www.kaspersky.com/virus-removal-tools Link to comment https://www.neowin.net/forum/topic/1074755-torjanencoder-in-the-wild/#findComment-594842843 Share on other sites More sharing options...
Recommended Posts