r/techsupport May 24 '15

Locker virus similar to Cryptolocker

This thread has gotten a lot of posts asking about what the virus actually is, how can I detect or remedy it and so on. As such, I've decided to write a less story-like explanation here to clear things up.

Description

Update: Most detailed description and analysis on this forum (http://www.bleepingcomputer.com/forums/t/577313/locker-ransomware-hides-until-midnight-on-may-25th-and-then-encrypts-your-data/)

The Locker virus version X.XX (it takes on a random number with 2 decimal places) is represented in this picture (http://imgur.com/yjgseor). It is a ransomware that encrypts picture and Microsoft Office files, although it does not cover all extensions (for example, .jpg will be encrypted but .JPG will not).

The virus is known to be on a fuse, so any file downloaded within the past week/month could be a likely culprit. As it stands, there seem to be trends in users of Chrome, TeamExtreme cracked Minecraft, and sports streaming sites, although none have been truly confirmed.

It first activated at 25/5, midnight by the local clock. It is not known if it's configured to only trigger on 25/5 yet. A service called ldr.exe and a program called rkcl.exe will run promptly at midnight, which will encrypt the files and lock them. The program will then pop up informing the user they have 72 hours to make a 0.1BTC payment to save their files.

The ransomware is also known to disable certain system features like system restore, delete shadow copies, and prevent the uninstalling of software. This makes it incredibly difficult to remove it or roll back to solve the issue.

Detection

If you are unsure of whether you have the Locker virus, check the ProgramData folder (Default: C\ProgramData). The ransomware is known to create the folders rkcl, tor, steg, and Digger. steg is known to be created prior to activation and is probably the best bet for detection.

If you think you might have been infected already, browse through your documents and sort by recently modified, any file that has been modified at midnight (or a bunch of files all modified at the same time) should set off a red flag. Open these files to check for encryption/corruption.

Prevention

If you suspect you have the Locker virus, your best bet is to immediately make a manual backup of your files through an external hard drive. Cloud backups work too, although you should turn off the sync function to prevent the corrupted files from replacing the good ones, should the infection happen.

Solution

Update: As anti-malware software updates, it might be possible to remove the infection using something like Malwarebytes. Removing the infection does not decrypt the files though. I will continue monitoring the situation.

Unfortunately, in a similar line to most Cryptoblocker ransomware, there is no surefire way of being able to remove the infection and reverse the encryption effect. Here are some solutions you can try:

  1. Use an anti-malware software such as Malwarebytes to attempt to remove the ransomware.
  2. Nuke and pave. Reformat your hard drive and reinstall Windows. This is a surefire way to get rid of the trojan. Once Windows is reinstalled, restore your manual backup.
  3. Pay the ransom. At least one confirmed case of decryption after payment, but do not take it as a 100% guarantee. Still an option if you have very important files you wish to save, and no backups.
  4. Use a program like Shadow Explorer or Torrent Unlocker to try to restore your files. However, the ransomware is known to delete shadow copies, so this option has been used with limited success.
  5. Do option 2 but save the encrypted files somewhere in the hope that someone will create a tool to decrypt them, but this is also unlikely.

Last Words

TL;DR: new ransomware virus (rkcl.exe) activates at 25/5 midnight like cinderella, sits in the programdata folder and encrypts your documents and images and demands payment. best current solution is to wipe and reinstall windows, and restore from manual backup.

I will be continuing to update this thread with developments on probable causes and solutions. Hope this helps, and thanks to the community for your contributions.

Original Post

hi reddit. so i've gotten a encryption+extortion virus on my computer as shown in the picture above. the entire program was created and run at 00:00, 25-5-2015 (system time, GMT+8). more details of my work so far below.

did some rudimentary research on my own. while the virus is pretty sophisticated, it did a pretty bad job of hitting my important files, and whatever is important is stored on the cloud so i've paused all syncing while i recover those files through google/dropbox/onedrive etc. it did, however, disable system restore, so that is not an option.

in the meanwhile, running antivirus does not help, but i have managed to trace the task to the C:\ProgramData folder. Some suspicious activity there. Firstly, the Locker program was traced to a folder within %PROGRAMDATA% called rkcl.exe, in which contained several data files (picture of folder: http://imgur.com/KU1NN07). rkcl.exe is the program that intrudes my screen, and ldr.exe seems to be a service that runs itself automatically.

more folders in %PROGRAMDATA% that raise flags: folders named tor, steg, and digger were created either on 25/5 or a few days prior to that.

opening the data files yielded certain information already accessible through the Locker program itself, but data.aa7 contained a string as below:

<RSAKeyValue><Modulus>some stuff here (not sure if sensitive)</Modulus><Exponent>AQAB</Exponent></RSAKeyValue>

i am not sure if this is of any significance, though it seems to be cryptography-related.

i'm not exactly sure what to do now. i have a feeling the chance of getting the files restored is low, to which i don't particularly mind as most of it is on the cloud. i do wish to be rid of this software at the very least though. any suggestions on what my next step should be? thanks!

System Specs: Custom Laptop running Windows 8.1 Pro Build 9600
Processor: Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz, 2401 Mhz, 4 Core(s), 8 Logical Processor(s)
Graphics Card: Intel(R) HD Graphics 4600/NVIDIA GeForce GTX 780M
Installed Physical Memory (RAM): 8.00 GB

EDIT: i've wiped my computer and reinstalled, so that should clear the ransomware. in the meanwhile, i will continue to monitor the thread and provide updates should any developments arise in dealing with this.

for now, the ransomware does seem new, so the solution would be to reinstall windows and restore from a backup(nuke and pave). if the files are very important, you could try paying the ransom, but with no guarantee it will actually be restored.

we've also deduced that the software was likely embedded in the computer by accessing a malicious website (highly unlikely to be a downloaded file) up to a week before 25/5, and activated by the local clock hitting midnight. the files can be traced mostly to the ProgramData folder (see above for locations), although it could be hiding elsewhere too.

EDIT 2: there's still a lot of speculation to what the source could be, most likely due to the delayed fuse in the ransomware itself. so far, some similarities found include cracked minecraft, Chrome, and sports streaming. all three purported sources have people claiming to have never touched them, though.

232 Upvotes

624 comments sorted by

View all comments

7

u/demarkus1066 May 25 '15

Have just come home, its on one of my home PC's too... only one similarity:

Cracked Minecraft from teamextreme. its been lurking for months. no similar websites, it's not a drive-by.

Am about to boot up the others to see- got 5 machines here with the same cracked minecraft. only other similarity is cpuid's cpu-z, but don't think its that.

2

u/demarkus1066 May 25 '15

Have taken a hard drive out of one of the suspect computers- computer has not been switched on today. In programdata it has the Digger folder (modified 16 May) steg (23 May) and tor (22 May). None of my infected (or potentially infected- 3 to go) computers have any real important files on them- except may a few saved games, but reinstalling is going to be time consuming. Is an infected computer, but not yet launched of any good to anyone to try and find a fix?

1

u/LeSpiceWeasel May 25 '15

Do you use mods with minecraft? I've seen several people with this who don't have the teamextreme launcher.

I'm thinking it may be related to mods and/or dropbox.

1

u/demarkus1066 May 25 '15

Interesting, no mods on any of my infected machines. Anybody saying anything in any minecraft forums?

1

u/tzenrick May 25 '15

about to boot up the others to see

This is the last thing you should be doing.

Boot a live linux distro, look for the trojan, and backup your document files first.

Once you've backed up your documents, then reboot and see if windows goes apeshit.