Auteur Sujet: Jigsaw Ransomware  (Lu 8336 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Jigsaw Ransomware
« le: avril 21, 2016, 08:24:12 »
Bonjour,

Une fiche BleepingComputer sur le ransomware Jigsaw

Jigsaw Ransomware Decrypted: Will delete your files until you pay the Ransom

Citer
A new ransomware has been released that not only encrypts your files, but also deletes them if you take too long to make the ransom payment of $150 USD.  The Jigsaw Ransomware, named after the iconic character that appears in the ransom note, will delete files every hour and each time the infection starts until you pay the ransom.  At this time is currently unknown how this ransomware is distributed.

This is the first time that we have seen these types of threats actually being carried out by a ransomware infection. The good news is that a method has been discovered that allows victims to decrypt their files for free.



Citer
How to decrypt and remove the Jigsaw Ransomware

Thankfully, through the analysis of MalwareHunterTeam​, DemonSlay335​, and myself it was discovered that it is possible to decrypt this ransomware for free.  Using this information, Demonslay335 has released a decryptor that can decrypt files encrypted by the Jigsaw Ransomware.  To decrypt your files, the first thing that you should do is terminate the firefox.exe and drpbx.exe processes in Task Manager to prevent any further files from being deleted.  You should then run MSConfig and disable the startup entry called firefox.exe that points to the %UserProfile%\AppData\Roaming\Frfx\firefox.exe executable.

Once you have terminated the ransomware and disabled its startup, let's proceed with decrypting the files.  The first step is to download and extract the Jigsaw Decryptor from the following URL:

https://download.bleepingcomputer.com/demonslay335/JigSawDecrypter.zip
 

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Re : Jigsaw Ransomware
« Réponse #1 le: avril 21, 2016, 08:26:50 »
Citer
Jigsaw : une solution contre ce ransomware sadique

Dans la famille des ransomwares, Jigsaw s'adonne à un jeu pervers. Un outil gratuit de déchiffrement a vu le jour.
http://www.generation-nt.com/jigsaw-ransomware-chiffrement-outil-dechiffrement-actualite-1927764.html




Citer
Jigsaw – Le ransomware le plus sadique du monde

Ça n'arrête pas en ce moment. Attention, un nouveau ransomware pour Windows vient d'arriver dans la place, mais celui-ci est encore plus cruel que les autres. Son petit nom ? Jigsaw inspiré du personnage du film d'horreur Saw.

En effet, après avoir chiffré tous vos documents, photos, vidéos...etc., Jigsaw s'amuse sadiquement à supprimer vos fichiers toutes les heures. Il commence avec un fichier, puis d'heure en heure, il en supprime de plus en plus. Ainsi, si vous tardez trop à payer les 150 $ réclamés (soit 0,4 Bitcoins), 48h plus tard vous n'aurez plus aucun fichier à sauver.
http://korben.info/jigsaw-ransomware.html
 

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Re : Jigsaw Ransomware
« Réponse #2 le: mai 22, 2016, 08:35:38 »
Bonjour,

Une fiche BleepingComputer sur le ransomware Jigsaw / CryptoHitman

Jigsaw Ransomware becomes CryptoHitman with Porno Extension

Citer
The only major differences is the new pornographic locker screen, the use of the Hitman character, the new .porno or .pornoransom extension that is added to all encrypted files, and new filenames for the ransomware executables. Otherwise, this ransomware performs the same as the original Jigsaw Ransomware.


How to decrypt and remove the Jigsaw Ransomware

Thankfully, DemonSlay335was able to modify his existing Jigsaw Ransomware decryptor to also decrypt files encrypted by CryptoHitman. To decrypt your files, the first thing that you should do is terminate the %LocalAppData%\Suerdf\suerdf.exe
and %AppData%\Mogfh\mogfh.exe processes in Task Manager to prevent any further files from being deleted.  You should then run MSConfig and disable the startup entry related to these executables.

Once you have terminated the ransomware and disabled its startup, let's proceed with decrypting the files.  The first step is to download and extract the Jigsaw Decryptor from the following URL:

//download.bleepingcomputer.com/demonslay335/JigSawDecrypter.zip
 

Hors ligne chantal11

  • Admin Formation
  • Mega Power Members
  • ****
  • Messages: 25131
    • Windows 10 - Windows 8 - Windows 7 - Windows Vista
Re : Jigsaw Ransomware
« Réponse #3 le: juin 13, 2016, 18:07:54 »
Bonjour,

Une fiche BleepingComputer sur le ransomware Jigsaw

New Jigsaw Ransomware variant with the .PAYMS Extension

Citer
A new Jigsaw Ransomware variant was discovered today by security researcher Michael Gillespie that encrypts a victim's data and then appends the .payms extension to them. The ransomware then requires a ransom payment of $150 USD in the form of bitcoins to decrypt your files. Thankfully, Michael was able to update his Jigsaw decryptor to handle this variant.

Citer
Jigsaw Decryptor -> http://download.bleepingcomputer.com/demonslay335/JigSawDecrypter.zip
 

Tags: