RansomWare Disassembly Reveals Evolutionary Path
flaws writes "The guys at Secure Science Corporation have written a revealing article demonstrating the relationship with the most recent Ransom-based Trojan (known as Glamour) and some previous data stealing trojans. They include an open source decrypting utility for unlocking your files if infected, and some stats that are a bit disturbing. According to their report, in the past 8 months, 152,000 victims have been infected, and over 14.5 million records were discovered to be logged by the trojan."
"Dear User: We are currently holding your pornography hostage. Unless you send us $300, you will never see Jenna Jameson and that beer can again."
Sure baby, I'll give you my phone number...in Hex
. . .Trojan brand shown to BLOCK Evolutionary Path!
The entry should be a REG_DWORD named WinCode in the HKLM\SOFTWARE\Microsft\Windows NT\CurrentVersion location, and should have the value 31337
Call me old fashioned, but I like a dump to be as memorable as it is devastating - Bender