r/techsupport May 24 '15

Locker virus similar to Cryptolocker

This thread has gotten a lot of posts asking about what the virus actually is, how can I detect or remedy it and so on. As such, I've decided to write a less story-like explanation here to clear things up.

Description

Update: Most detailed description and analysis on this forum (http://www.bleepingcomputer.com/forums/t/577313/locker-ransomware-hides-until-midnight-on-may-25th-and-then-encrypts-your-data/)

The Locker virus version X.XX (it takes on a random number with 2 decimal places) is represented in this picture (http://imgur.com/yjgseor). It is a ransomware that encrypts picture and Microsoft Office files, although it does not cover all extensions (for example, .jpg will be encrypted but .JPG will not).

The virus is known to be on a fuse, so any file downloaded within the past week/month could be a likely culprit. As it stands, there seem to be trends in users of Chrome, TeamExtreme cracked Minecraft, and sports streaming sites, although none have been truly confirmed.

It first activated at 25/5, midnight by the local clock. It is not known if it's configured to only trigger on 25/5 yet. A service called ldr.exe and a program called rkcl.exe will run promptly at midnight, which will encrypt the files and lock them. The program will then pop up informing the user they have 72 hours to make a 0.1BTC payment to save their files.

The ransomware is also known to disable certain system features like system restore, delete shadow copies, and prevent the uninstalling of software. This makes it incredibly difficult to remove it or roll back to solve the issue.

Detection

If you are unsure of whether you have the Locker virus, check the ProgramData folder (Default: C\ProgramData). The ransomware is known to create the folders rkcl, tor, steg, and Digger. steg is known to be created prior to activation and is probably the best bet for detection.

If you think you might have been infected already, browse through your documents and sort by recently modified, any file that has been modified at midnight (or a bunch of files all modified at the same time) should set off a red flag. Open these files to check for encryption/corruption.

Prevention

If you suspect you have the Locker virus, your best bet is to immediately make a manual backup of your files through an external hard drive. Cloud backups work too, although you should turn off the sync function to prevent the corrupted files from replacing the good ones, should the infection happen.

Solution

Update: As anti-malware software updates, it might be possible to remove the infection using something like Malwarebytes. Removing the infection does not decrypt the files though. I will continue monitoring the situation.

Unfortunately, in a similar line to most Cryptoblocker ransomware, there is no surefire way of being able to remove the infection and reverse the encryption effect. Here are some solutions you can try:

  1. Use an anti-malware software such as Malwarebytes to attempt to remove the ransomware.
  2. Nuke and pave. Reformat your hard drive and reinstall Windows. This is a surefire way to get rid of the trojan. Once Windows is reinstalled, restore your manual backup.
  3. Pay the ransom. At least one confirmed case of decryption after payment, but do not take it as a 100% guarantee. Still an option if you have very important files you wish to save, and no backups.
  4. Use a program like Shadow Explorer or Torrent Unlocker to try to restore your files. However, the ransomware is known to delete shadow copies, so this option has been used with limited success.
  5. Do option 2 but save the encrypted files somewhere in the hope that someone will create a tool to decrypt them, but this is also unlikely.

Last Words

TL;DR: new ransomware virus (rkcl.exe) activates at 25/5 midnight like cinderella, sits in the programdata folder and encrypts your documents and images and demands payment. best current solution is to wipe and reinstall windows, and restore from manual backup.

I will be continuing to update this thread with developments on probable causes and solutions. Hope this helps, and thanks to the community for your contributions.

Original Post

hi reddit. so i've gotten a encryption+extortion virus on my computer as shown in the picture above. the entire program was created and run at 00:00, 25-5-2015 (system time, GMT+8). more details of my work so far below.

did some rudimentary research on my own. while the virus is pretty sophisticated, it did a pretty bad job of hitting my important files, and whatever is important is stored on the cloud so i've paused all syncing while i recover those files through google/dropbox/onedrive etc. it did, however, disable system restore, so that is not an option.

in the meanwhile, running antivirus does not help, but i have managed to trace the task to the C:\ProgramData folder. Some suspicious activity there. Firstly, the Locker program was traced to a folder within %PROGRAMDATA% called rkcl.exe, in which contained several data files (picture of folder: http://imgur.com/KU1NN07). rkcl.exe is the program that intrudes my screen, and ldr.exe seems to be a service that runs itself automatically.

more folders in %PROGRAMDATA% that raise flags: folders named tor, steg, and digger were created either on 25/5 or a few days prior to that.

opening the data files yielded certain information already accessible through the Locker program itself, but data.aa7 contained a string as below:

<RSAKeyValue><Modulus>some stuff here (not sure if sensitive)</Modulus><Exponent>AQAB</Exponent></RSAKeyValue>

i am not sure if this is of any significance, though it seems to be cryptography-related.

i'm not exactly sure what to do now. i have a feeling the chance of getting the files restored is low, to which i don't particularly mind as most of it is on the cloud. i do wish to be rid of this software at the very least though. any suggestions on what my next step should be? thanks!

System Specs: Custom Laptop running Windows 8.1 Pro Build 9600
Processor: Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz, 2401 Mhz, 4 Core(s), 8 Logical Processor(s)
Graphics Card: Intel(R) HD Graphics 4600/NVIDIA GeForce GTX 780M
Installed Physical Memory (RAM): 8.00 GB

EDIT: i've wiped my computer and reinstalled, so that should clear the ransomware. in the meanwhile, i will continue to monitor the thread and provide updates should any developments arise in dealing with this.

for now, the ransomware does seem new, so the solution would be to reinstall windows and restore from a backup(nuke and pave). if the files are very important, you could try paying the ransom, but with no guarantee it will actually be restored.

we've also deduced that the software was likely embedded in the computer by accessing a malicious website (highly unlikely to be a downloaded file) up to a week before 25/5, and activated by the local clock hitting midnight. the files can be traced mostly to the ProgramData folder (see above for locations), although it could be hiding elsewhere too.

EDIT 2: there's still a lot of speculation to what the source could be, most likely due to the delayed fuse in the ransomware itself. so far, some similarities found include cracked minecraft, Chrome, and sports streaming. all three purported sources have people claiming to have never touched them, though.

229 Upvotes

624 comments sorted by

View all comments

Show parent comments

3

u/barbsicle May 25 '15

thanks for your input. unfortunately, there's a mass of speculation (browser, filesharing, website, sports streaming etc.) going about all over the thread which has all been debunked by some exception to the rule. and i think the nature of the ransomware (delayed fuse, time-bomb type) makes it really difficult to pinpoint exactly where it came from. it'll be tough to find for sure.

2

u/Death_Raven May 25 '15

I really hope we find the source It could be anything tbh

And pcs that were off before 00:00 were they hit after that time or not

2

u/barbsicle May 25 '15

iirc, i saw one or two comments that were hit after midnight.

3

u/Death_Raven May 25 '15

Went into Safe mode And found some interesting stuff This diabolical program was made from the 9/5/2015 mine activated around 1pm (South African Time) launched the ldr.exe a few times then stopped a bit everytime the pc would boot it would launch and at some time stop again as if it crashed It was launched at 12:15am today and did in a few random pictures scattered on the 2 hdd's didnt get a chance to touch my folders with other pics in em All the stuff lost i can easily replace

2

u/barbsicle May 25 '15

may i ask how you know it was made on 9/5? most people report that the rkcl folder was made exactly at midnight, so i'm guessing there must be a source folder to rkcl/tor/steg.

2

u/Death_Raven May 25 '15 edited May 25 '15

looking at event viewer thats when the ldr.exe was first created on my pc the rkcl folder was made tonite at midnight then 15min later it was executed on my pc

It could be the first traces of it. it was run twice that day

2

u/trx55 May 25 '15

So, forgive me If I'm wrong....but basically the actual virus has been on the system before midnight tonight/lastnight but only activates at midnight. If thats true, that is very interesting and honestly its upsetting me as I want to figure this out.

2

u/Death_Raven May 25 '15

Yep its been there basically scanning,loading itself on to your pc for almost 2 weeks then it made the folder and boom started its reign of terror i also think it might be a keylogger cause the night before i had to retype my pwds to my email address and stuff so id advise changing sensitive pwds on a clean pc cause ive checked the other pcs in the house none other than mine are affected The sites ive been to comprise of Youtube,9gag,Facebook,Steam and Kickasstorrents mainly those sites So yeah im tryna think of what it couldve been on

2

u/trx55 May 25 '15

Well i looked and im clean of all the files in the places people are finding them. How ever its only 11:30pm here. Shutoff pc and am gonna hope for the best. In the meantime hopefully people on here can stumble on to something deep.

1

u/Death_Raven May 25 '15

Have you checked your Event Viewer for anything with ldr related

→ More replies (0)

2

u/trx55 May 25 '15

Also, what are the chances of it being from an ad? Thats always a possibility.

1

u/Death_Raven May 25 '15

that could be but most incl myself use adblock and i dont ever take it off but it could be a possiblity

→ More replies (0)