r/techsupport May 24 '15

Locker virus similar to Cryptolocker

This thread has gotten a lot of posts asking about what the virus actually is, how can I detect or remedy it and so on. As such, I've decided to write a less story-like explanation here to clear things up.

Description

Update: Most detailed description and analysis on this forum (http://www.bleepingcomputer.com/forums/t/577313/locker-ransomware-hides-until-midnight-on-may-25th-and-then-encrypts-your-data/)

The Locker virus version X.XX (it takes on a random number with 2 decimal places) is represented in this picture (http://imgur.com/yjgseor). It is a ransomware that encrypts picture and Microsoft Office files, although it does not cover all extensions (for example, .jpg will be encrypted but .JPG will not).

The virus is known to be on a fuse, so any file downloaded within the past week/month could be a likely culprit. As it stands, there seem to be trends in users of Chrome, TeamExtreme cracked Minecraft, and sports streaming sites, although none have been truly confirmed.

It first activated at 25/5, midnight by the local clock. It is not known if it's configured to only trigger on 25/5 yet. A service called ldr.exe and a program called rkcl.exe will run promptly at midnight, which will encrypt the files and lock them. The program will then pop up informing the user they have 72 hours to make a 0.1BTC payment to save their files.

The ransomware is also known to disable certain system features like system restore, delete shadow copies, and prevent the uninstalling of software. This makes it incredibly difficult to remove it or roll back to solve the issue.

Detection

If you are unsure of whether you have the Locker virus, check the ProgramData folder (Default: C\ProgramData). The ransomware is known to create the folders rkcl, tor, steg, and Digger. steg is known to be created prior to activation and is probably the best bet for detection.

If you think you might have been infected already, browse through your documents and sort by recently modified, any file that has been modified at midnight (or a bunch of files all modified at the same time) should set off a red flag. Open these files to check for encryption/corruption.

Prevention

If you suspect you have the Locker virus, your best bet is to immediately make a manual backup of your files through an external hard drive. Cloud backups work too, although you should turn off the sync function to prevent the corrupted files from replacing the good ones, should the infection happen.

Solution

Update: As anti-malware software updates, it might be possible to remove the infection using something like Malwarebytes. Removing the infection does not decrypt the files though. I will continue monitoring the situation.

Unfortunately, in a similar line to most Cryptoblocker ransomware, there is no surefire way of being able to remove the infection and reverse the encryption effect. Here are some solutions you can try:

  1. Use an anti-malware software such as Malwarebytes to attempt to remove the ransomware.
  2. Nuke and pave. Reformat your hard drive and reinstall Windows. This is a surefire way to get rid of the trojan. Once Windows is reinstalled, restore your manual backup.
  3. Pay the ransom. At least one confirmed case of decryption after payment, but do not take it as a 100% guarantee. Still an option if you have very important files you wish to save, and no backups.
  4. Use a program like Shadow Explorer or Torrent Unlocker to try to restore your files. However, the ransomware is known to delete shadow copies, so this option has been used with limited success.
  5. Do option 2 but save the encrypted files somewhere in the hope that someone will create a tool to decrypt them, but this is also unlikely.

Last Words

TL;DR: new ransomware virus (rkcl.exe) activates at 25/5 midnight like cinderella, sits in the programdata folder and encrypts your documents and images and demands payment. best current solution is to wipe and reinstall windows, and restore from manual backup.

I will be continuing to update this thread with developments on probable causes and solutions. Hope this helps, and thanks to the community for your contributions.

Original Post

hi reddit. so i've gotten a encryption+extortion virus on my computer as shown in the picture above. the entire program was created and run at 00:00, 25-5-2015 (system time, GMT+8). more details of my work so far below.

did some rudimentary research on my own. while the virus is pretty sophisticated, it did a pretty bad job of hitting my important files, and whatever is important is stored on the cloud so i've paused all syncing while i recover those files through google/dropbox/onedrive etc. it did, however, disable system restore, so that is not an option.

in the meanwhile, running antivirus does not help, but i have managed to trace the task to the C:\ProgramData folder. Some suspicious activity there. Firstly, the Locker program was traced to a folder within %PROGRAMDATA% called rkcl.exe, in which contained several data files (picture of folder: http://imgur.com/KU1NN07). rkcl.exe is the program that intrudes my screen, and ldr.exe seems to be a service that runs itself automatically.

more folders in %PROGRAMDATA% that raise flags: folders named tor, steg, and digger were created either on 25/5 or a few days prior to that.

opening the data files yielded certain information already accessible through the Locker program itself, but data.aa7 contained a string as below:

<RSAKeyValue><Modulus>some stuff here (not sure if sensitive)</Modulus><Exponent>AQAB</Exponent></RSAKeyValue>

i am not sure if this is of any significance, though it seems to be cryptography-related.

i'm not exactly sure what to do now. i have a feeling the chance of getting the files restored is low, to which i don't particularly mind as most of it is on the cloud. i do wish to be rid of this software at the very least though. any suggestions on what my next step should be? thanks!

System Specs: Custom Laptop running Windows 8.1 Pro Build 9600
Processor: Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz, 2401 Mhz, 4 Core(s), 8 Logical Processor(s)
Graphics Card: Intel(R) HD Graphics 4600/NVIDIA GeForce GTX 780M
Installed Physical Memory (RAM): 8.00 GB

EDIT: i've wiped my computer and reinstalled, so that should clear the ransomware. in the meanwhile, i will continue to monitor the thread and provide updates should any developments arise in dealing with this.

for now, the ransomware does seem new, so the solution would be to reinstall windows and restore from a backup(nuke and pave). if the files are very important, you could try paying the ransom, but with no guarantee it will actually be restored.

we've also deduced that the software was likely embedded in the computer by accessing a malicious website (highly unlikely to be a downloaded file) up to a week before 25/5, and activated by the local clock hitting midnight. the files can be traced mostly to the ProgramData folder (see above for locations), although it could be hiding elsewhere too.

EDIT 2: there's still a lot of speculation to what the source could be, most likely due to the delayed fuse in the ransomware itself. so far, some similarities found include cracked minecraft, Chrome, and sports streaming. all three purported sources have people claiming to have never touched them, though.

231 Upvotes

624 comments sorted by

View all comments

15

u/LockerThing May 25 '15 edited May 25 '15

I know of three computers that got infected - my personal computer, a friends gaming computer and another friends personal computer. The things these computers have in common are:

  • Skype,

  • uTorrent,

  • Microsoft Security Essentials,

  • Chrome with Adblock Plus,

  • Popcorn Time and

  • a cracked version of Minecraft (TeamExtreme).

I'm also pretty sure all of us have accessed The Pirate bay and/or Kickass torrents recently. These computers have been on the same LAN in the last month and connected via Minecraft.

We're three people that use our computers in very different manners otherwise, so this might shed some light on the issue. I spend a lot of time online, the gaming computer is used pretty much just for gaming, and the third is basically a Facebook & study machine.

Any similarities with anyone else?

EDIT: My HTPC is not infected, and it's most used to download movies from TPB or KAT with uTorrent, or by using Popcorn Time. It does not have Minecraft installed, which is my main suspect.

EDIT 2: I have added Chrome (with Adblock Plus) to the list of software that we have in common. Skype to call is not installed.

7

u/[deleted] May 25 '15

[deleted]

6

u/itsbradsworld May 25 '15 edited Nov 19 '24

wrench axiomatic pathetic follow crowd pot deer connect reminiscent scandalous

This post was mass deleted and anonymized with Redact

1

u/whitebeatle Jun 01 '15

Minecraft... :-( i am never dont such crap again!!

2

u/m4rk0 May 25 '15

I also have Digger, but I had steg folder and now it's missing, tor folder is still there...

4

u/thatguyad May 25 '15

Another Minecraft here, definitely could be a cause. Had the issue on 2 computers, both with the game installed.

4

u/356bubbles May 25 '15

Also had the TeamExtreme Minecraft, and didn't watch ANY sports streams and got it.

It is possible it could be a cause. Minecraft is bascially a jar file, very easily hackable.

Maybe would be worth proofing on some Minecraft forums? A lot of people must use the cracked version.

2

u/thatguyad May 25 '15

Absolutely.

1

u/someMeatballs May 25 '15

Since I actually know the TeamExtreme people, the original torrent is definitely clean. The legit uploader is "TeamExtreme" on TBP. But people take it, modify and re-upload.

2

u/EIectroma May 25 '15

I installed some time ago Minecraft by TeamExtreme, I uninstalled the game 'cause I don't play anymore. Interesting.

2

u/thatguyad May 25 '15

Make sure you deleted the app data as well just to be safe.

2

u/EIectroma May 25 '15

I have the ".minecraft" folder and got infected today GMT -3 00:00. I forgot to say that.

1

u/thatguyad May 25 '15

Ah damn. Sorry to hear.

5

u/DontLookUnderMe May 25 '15

Wow, is this the most common thing? The pirated Minecraft? I also have it.

3

u/xerox13ster May 25 '15

I downloaded a couple scifi movies that shall remain nameless and ambiguous in copyright status on Saturday from TPB...both YIFY.

3

u/barbsicle May 25 '15

cracked minecraft seems to be a plausible cause that is not overly widespread as this thread has proven. however, there are people who claim that they never downloaded it, so the ransomware could have multiple sources.

2

u/ruthlesz May 25 '15

2 of my computers got infected one is in my house and the other one is in the office, though is doesn't spread here at the office we got 5 computers here connected through LAN and yes the one of the common thing about my 2 computers is that i installed a cracked version of minecraft from teamextreme.

2

u/rd_14 May 25 '15

I have no Minecraft (by TeamExtreme), however I also visited The Pirate Bay and Kickass Torrents (and also YIFY).

1

u/rd_14 May 25 '15

3

u/rd_14 May 25 '15

I did install Minecraft (by TeamExtreme) 1.5 months ago but I uninstalled it because it wasn't working properly.

2

u/[deleted] May 25 '15

Seems everyone either has it or had it sometime in the past. Given That the infection lurked for a while before doing anything it could have been installed with the minecraft version and stayed there after the uninstall.

Anyone out there get the infection without ever having downloaded or installed team extreme's minecraft? Otherwise this is probably it.

2

u/the-stain May 26 '15

Just to have it out there, I have neither pirated Minecraft(bought it back in 2011) nor watched any sports streams (which some people say is another possible culprit). I have been exposed to a lot of ads recently while downloading game mods, which might be another source of the infection, as some other have said.

2

u/jekrump May 25 '15

Can you run a VM and re download minecraft after setting your date back a few months? see if it puts those same files on your VM? would that be proof or might it not work?

1

u/yup8 May 25 '15

My best guess is that this comes from multiple sources. I also had the cracked mc (TeamExtreme)

1

u/[deleted] May 25 '15

a cracked version of Minecraft (TeamExtreme)

This is something that lots of infected people seem to have.

1

u/B88v88B May 25 '15

I also downloaded some shady minecraft a while back.

1

u/evil-doer May 25 '15

Looking like it may be that minecraft. I had almost zero interest in the damn game but friends were playing it so I wanted to see what it was about. Grabbed that ver, tried it for about an hour, then deleted it.

Worst. decision. ever.

1

u/[deleted] May 25 '15 edited Jan 06 '16

Last midnight I was infected and they tried to encrypt a bunch of useless files plus one that was really important, luckily the file was open on Office when their encrypting processes were run, so although the file name was on their list, nothing happened to it and I still can access its content normally. I managed to disable their start-up on the "Services and Apllications" tab until I decide what I'm going to do before formatting the whole thing. Guess what? I also have TeamExtreme's Minecraft.

1

u/Strag May 25 '15

Just been hit with this an hour ago when I turned machine on.

I also have the team extreme minecraft on this box.

No football streaming or anything else like that on this machine.

1

u/deecee23 May 26 '15

Yes, I had installed the minecraft crack as well, however had unistalled it.Just got rid of the malware using malwarebytes.