Welcome Guest! To access all forums & features, please register an account or sign-in. → Why register?



Torjan.Encoder in the wild


12 replies to this topic - - - - -

#1 +Daedroth

    Resident Fanatic

  • 941 posts
  • Joined: 15-June 11
  • Location: UK

Posted 03 May 2012 - 13:59

It appears this nasty piece of work is picking up steam, and could be especially nasty for unsuspecting users.

Hiding or locking all your files doesn't appear to be enough for some trojans. Encoder encrypts all your files and tries to force you into buying an 'unlock' code.

Here are links for more information and advice:

http://news.drweb.co...&c=5&lng=en&p=0

http://news.drweb.co...&c=5&lng=en&p=0

https://community.mc...tart=0&tstart=0


#2 butilikethecookie

    Neowinian³

  • 465 posts
  • Joined: 05-March 12

Posted 03 May 2012 - 14:05

That's crazy! They need to be shut down!

#3 Hum

    totally wAcKed

  • 54,320 posts
  • Joined: 05-October 03
  • Location: Odder Space
  • OS: Windows XP, 7

Posted 03 May 2012 - 14:06

Probably written by Norton employees. :shiftyninja:

#4 HighwayGlider

    Resident Elite

  • 1,668 posts
  • Joined: 05-November 05

Posted 03 May 2012 - 14:10

View PostHum, on 03 May 2012 - 14:06, said:

Probably written by Norton employees. :shiftyninja:
LOL man, you're nasty.

#5 Charisma

    e-1337-ist

  • 3,757 posts
  • Joined: 02-May 10
  • Location: Galactic Sector ZZ9 Plural Z Alpha

Posted 03 May 2012 - 14:13

Is this for real? O_O

#6 ThePitt

    Neowinian Wise One

  • 4,808 posts
  • Joined: 14-January 06
  • Location: Hell

Posted 03 May 2012 - 14:14

View PostHum, on 03 May 2012 - 14:06, said:

Probably written by Norton employees. :shiftyninja:
wouldnt surprise me...

EDIT
just in case here is the decrypter:

ftp://ftp.drweb.com/...snu1decrypt.exe

#7 Dot Matrix

    Neowinian Wise One

  • 5,653 posts
  • Joined: 14-November 11
  • Location: USA
  • OS: Windows 8
  • Phone: Nokia Lumia 920

Posted 03 May 2012 - 14:19

Ok, so the image shows Windows Xp... What about Windows Vista, Windows 7, or Windows 8?

#8 Marshall

    Neowinian UNSTOPPABLE

  • 7,348 posts
  • Joined: 22-June 03
  • Location: USA

Posted 03 May 2012 - 14:23

View PostDot Matrix, on 03 May 2012 - 14:19, said:

Ok, so the image shows Windows Xp... What about Windows Vista, Windows 7, or Windows 8?

A quick google and it shows this affects Vista & 7 as well, not sure about 8.

#9 Detection

    Detecting stuff...

  • 8,369 posts
  • Joined: 30-October 10
  • Location: UK
  • OS: 7 SP1 x64

Posted 03 May 2012 - 14:43

The first article suggests:

"Never attempt to solve the problem by reinstallling the operating system."

Why ? If I couldn't decrypt them, that's the first thing I would do. Maybe this is aimed at people who are bothered about recovering their files ?

#10 +littleneutrino

    I am the Little Neutrino

  • 13,222 posts
  • Joined: 25-July 05
  • Location: Newark, Ohio
  • OS: Windows 8
  • Phone: GS3 CM10.1

Posted 03 May 2012 - 14:43

makes you wonder how stupid these virus makers are. if you have to pay them then there is a money trail.

#11 Miuku.

    A damned noob

  • 4,885 posts
  • Joined: 10-August 03
  • Location: Finland, EU
  • OS: :: OS X :: SLES ::

Posted 03 May 2012 - 14:47

View Postlittleneutrino, on 03 May 2012 - 14:43, said:

makes you wonder how stupid these virus makers are. if you have to pay them then there is a money trail.
Fake accounts, hijacked accounts, countries where the legality of writing software such as this is not against the law and then some people are just so desperate that they will pay and not report it to anyone else.

#12 Max Norris

    Resident Elite

  • 1,981 posts
  • Joined: 20-February 11
  • Location: Midwestern US
  • OS: Windows 8, 7, FreeBSD
  • Phone: Lumia 900

Posted 03 May 2012 - 14:48

View Postlittleneutrino, on 03 May 2012 - 14:43, said:

makes you wonder how stupid these virus makers are. if you have to pay them then there is a money trail.
It's the usual motive for malware nowadays.. money. Stealing credentials, hijacking accounts, advertisement displays, ransomware, etc etc. Don't usually see the old "I'll nuke your bootloader just because" types of malware much anymore. Agreed with MiukuMac above too; it can be traced, but depending on where it's at, it may be near impossible to punish.

#13 Hell-In-A-Handbasket

    Neowinian UNSTOPPABLE

  • 6,313 posts
  • Joined: 30-September 03
  • OS: Win 7 Ultimate, iOS5, OSX 10.6, Ubuntu, WinXP

Posted 03 May 2012 - 18:02

Kaspersky put up a removal for it ( I think it's the same ) earlier

RannohDecryptor

http://www.kaspersky...s-removal-tools