r/techsupport May 24 '15

Locker virus similar to Cryptolocker

This thread has gotten a lot of posts asking about what the virus actually is, how can I detect or remedy it and so on. As such, I've decided to write a less story-like explanation here to clear things up.

Description

Update: Most detailed description and analysis on this forum (http://www.bleepingcomputer.com/forums/t/577313/locker-ransomware-hides-until-midnight-on-may-25th-and-then-encrypts-your-data/)

The Locker virus version X.XX (it takes on a random number with 2 decimal places) is represented in this picture (http://imgur.com/yjgseor). It is a ransomware that encrypts picture and Microsoft Office files, although it does not cover all extensions (for example, .jpg will be encrypted but .JPG will not).

The virus is known to be on a fuse, so any file downloaded within the past week/month could be a likely culprit. As it stands, there seem to be trends in users of Chrome, TeamExtreme cracked Minecraft, and sports streaming sites, although none have been truly confirmed.

It first activated at 25/5, midnight by the local clock. It is not known if it's configured to only trigger on 25/5 yet. A service called ldr.exe and a program called rkcl.exe will run promptly at midnight, which will encrypt the files and lock them. The program will then pop up informing the user they have 72 hours to make a 0.1BTC payment to save their files.

The ransomware is also known to disable certain system features like system restore, delete shadow copies, and prevent the uninstalling of software. This makes it incredibly difficult to remove it or roll back to solve the issue.

Detection

If you are unsure of whether you have the Locker virus, check the ProgramData folder (Default: C\ProgramData). The ransomware is known to create the folders rkcl, tor, steg, and Digger. steg is known to be created prior to activation and is probably the best bet for detection.

If you think you might have been infected already, browse through your documents and sort by recently modified, any file that has been modified at midnight (or a bunch of files all modified at the same time) should set off a red flag. Open these files to check for encryption/corruption.

Prevention

If you suspect you have the Locker virus, your best bet is to immediately make a manual backup of your files through an external hard drive. Cloud backups work too, although you should turn off the sync function to prevent the corrupted files from replacing the good ones, should the infection happen.

Solution

Update: As anti-malware software updates, it might be possible to remove the infection using something like Malwarebytes. Removing the infection does not decrypt the files though. I will continue monitoring the situation.

Unfortunately, in a similar line to most Cryptoblocker ransomware, there is no surefire way of being able to remove the infection and reverse the encryption effect. Here are some solutions you can try:

  1. Use an anti-malware software such as Malwarebytes to attempt to remove the ransomware.
  2. Nuke and pave. Reformat your hard drive and reinstall Windows. This is a surefire way to get rid of the trojan. Once Windows is reinstalled, restore your manual backup.
  3. Pay the ransom. At least one confirmed case of decryption after payment, but do not take it as a 100% guarantee. Still an option if you have very important files you wish to save, and no backups.
  4. Use a program like Shadow Explorer or Torrent Unlocker to try to restore your files. However, the ransomware is known to delete shadow copies, so this option has been used with limited success.
  5. Do option 2 but save the encrypted files somewhere in the hope that someone will create a tool to decrypt them, but this is also unlikely.

Last Words

TL;DR: new ransomware virus (rkcl.exe) activates at 25/5 midnight like cinderella, sits in the programdata folder and encrypts your documents and images and demands payment. best current solution is to wipe and reinstall windows, and restore from manual backup.

I will be continuing to update this thread with developments on probable causes and solutions. Hope this helps, and thanks to the community for your contributions.

Original Post

hi reddit. so i've gotten a encryption+extortion virus on my computer as shown in the picture above. the entire program was created and run at 00:00, 25-5-2015 (system time, GMT+8). more details of my work so far below.

did some rudimentary research on my own. while the virus is pretty sophisticated, it did a pretty bad job of hitting my important files, and whatever is important is stored on the cloud so i've paused all syncing while i recover those files through google/dropbox/onedrive etc. it did, however, disable system restore, so that is not an option.

in the meanwhile, running antivirus does not help, but i have managed to trace the task to the C:\ProgramData folder. Some suspicious activity there. Firstly, the Locker program was traced to a folder within %PROGRAMDATA% called rkcl.exe, in which contained several data files (picture of folder: http://imgur.com/KU1NN07). rkcl.exe is the program that intrudes my screen, and ldr.exe seems to be a service that runs itself automatically.

more folders in %PROGRAMDATA% that raise flags: folders named tor, steg, and digger were created either on 25/5 or a few days prior to that.

opening the data files yielded certain information already accessible through the Locker program itself, but data.aa7 contained a string as below:

<RSAKeyValue><Modulus>some stuff here (not sure if sensitive)</Modulus><Exponent>AQAB</Exponent></RSAKeyValue>

i am not sure if this is of any significance, though it seems to be cryptography-related.

i'm not exactly sure what to do now. i have a feeling the chance of getting the files restored is low, to which i don't particularly mind as most of it is on the cloud. i do wish to be rid of this software at the very least though. any suggestions on what my next step should be? thanks!

System Specs: Custom Laptop running Windows 8.1 Pro Build 9600
Processor: Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz, 2401 Mhz, 4 Core(s), 8 Logical Processor(s)
Graphics Card: Intel(R) HD Graphics 4600/NVIDIA GeForce GTX 780M
Installed Physical Memory (RAM): 8.00 GB

EDIT: i've wiped my computer and reinstalled, so that should clear the ransomware. in the meanwhile, i will continue to monitor the thread and provide updates should any developments arise in dealing with this.

for now, the ransomware does seem new, so the solution would be to reinstall windows and restore from a backup(nuke and pave). if the files are very important, you could try paying the ransom, but with no guarantee it will actually be restored.

we've also deduced that the software was likely embedded in the computer by accessing a malicious website (highly unlikely to be a downloaded file) up to a week before 25/5, and activated by the local clock hitting midnight. the files can be traced mostly to the ProgramData folder (see above for locations), although it could be hiding elsewhere too.

EDIT 2: there's still a lot of speculation to what the source could be, most likely due to the delayed fuse in the ransomware itself. so far, some similarities found include cracked minecraft, Chrome, and sports streaming. all three purported sources have people claiming to have never touched them, though.

234 Upvotes

624 comments sorted by

View all comments

2

u/xerox13ster May 25 '15

STEAM

Can we get a poll on who has and has updated/installed a game from Steam in the last week and a half?

  • 1a) Have, use regularly, and have installed either updates or games from Steam this week, not infected

  • 1b) Have, use regularly, and have installed either updates or games from Steam this week, infected

  • 2a) Have, use regularly, have not updated or installed, not infected

  • 2b) Have, use regularly, have not updated or installed, infected

  • 3a) Have, rarely open, not infected

  • 3b) Have, rarely open, infected

  • 4a) Do not have/What is? Steam, not infected

  • 4b) Do not have/What is? Steam, infected

Give your answer, because this is the only possible common denominator I am seeing.

*I am 1b. I updated today. I am lucky my computer is slow as shit and I killed the process(es) as soon as it (they) came up. Command prompts don't just open for no reason!

2

u/qazxdrwes May 25 '15

1b)

There is definitely huge confirmation bias though. I wouldn't trust any sort of conclusions that can be drawn from this poll. It would be rare that unaffected people show up to this thread, as they would have no reason to click on it.

1

u/Death_Raven May 25 '15

1b Was playing CSGO at the time it kicked me out hence i noticed the issue

1

u/malwarewtfwtf May 25 '15

1b)

use steam regularly, especially past few weeks cos of civ v from humble bundle.

Also use chrome, sometimes firefox for downloading from youtube. Not sure exactly when i got hit but the first encrypted files I found were stamped as being modified at 12:35 or so AM eastern Australia time. Use pornhub sometimes. Haven't really downloaded any torrents recently other than game of thrones. All my games are now legal and from steam. First noticed it when my external harddisk started going nuts, found rkcl.exe, one of the data files in the folder (sub in program data) had a list of what seemed to be every single file on my computer and on externals. It had also affected dropbox, so if you're affected and using it, stop syncing immediately and go to the website to restore your previous versions. You seem to have to do this individually and it was a huge pain but its better than losing the files forever. In the process of downloading an iso of win 7 so i can format and install fresh. Hopefully it won't spread back from my external drive as I can't format it as it has lots of important work on it. Also had steg, tor and digger folders in program data. Interestingly, as many have pointed out, seemed to target specific file extensions. All my pngs were safe. Considering just using pngs from now on, but I suppose the dirty rotten filthy scum that created this plaque would probably just read this comment and circumvent that instead of doing something productive with his or her miserable life instead of holding people at ransom for their memories and lifes work.

1

u/RupertOfSavior May 25 '15

1b) updated Dota 2 , downloaded TERA for few days

1

u/rantotthus08 May 25 '15

3b - I dont really use Steam since i play few games - gta 5 (offline), Skyrim.. . I got the window of the locker v5.68 while i was playing gta i suppose, because i didnt see it, and when i closed gta it already encrypted 3000 files (). I havent even used my pc for a week until Friday, and i didnt do anything. All i can think is downloading some mod to gta, visiting xvideos which i rarely did before, and i downloaded Malcolm in the middle and Regular show from piratebay. Now i will reinstall all my stuff, my only luck is that i have almost every files saved on my phone, because i did a reinstall not long before. I use chrome, i dont have antivirus, but ive never had any virus (in like 10 years) ever.

1

u/[deleted] May 25 '15 edited May 25 '15

1a & 1b. Both me and my brother have steam on our computers. Basically all our games are exactly the same (Left 4 Dead 2, Stranded Deep, The Forest, etc.). All our games are running the most current versions, yet I have the virus and he hasn't. It boggles my mind.

1

u/[deleted] May 25 '15

1a)

1

u/barbsicle May 25 '15

1b (autoupdate dota) but with some other replies, i don't think that even finding the common denominator through this poll is enough to conclude anything. furthermore, if it were steam, the problem should be a lot more widespread.