Attackers of CryptoWall Decrypter
“We had a site
today that was infected by CryptoWall which is a new variant of the
CryptoLocker virus. We find the three files that is the clue that a file has
been encrypted by the virus. The three clue files are DECRYPT_INSTRUCTION.TXT, DECRYPT_INSTRUCTION.HTML
and DECRYPT_INSTRUCTION.URL. What I am not clear on is how do I determine which
file has been encrypted?”
“Have a client
that got infected with what might possibly be a new version of a crypto style
malware. What's different about it is
that it leaves files named:
DECRYPT_INSTRUCTION
(with no suffix, with .TXT, and with .HTML) Also, the name on the web page
refers to "CryptoWall decrypter" and the ransom is $1000 USD. I can't
find a thing on this specific variant, except for 3 hits off of some German
site. ”
Recently, teesupport lab has found there
are many our clients who have been attacked by Cryptowall virus. If you are a
victim of CryptoWall Decrypter and still work hard to remove this virus, please
read more about this post to help you find an
effective way handle this problem.