Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

DecryptorMax Ransomware Decrypted, No Need to Pay the Ransom
Softpedia ^ | 28 Nov 2015, 10:31 GMT | Catalin Cimpanu

Posted on 11/28/2015 6:55:45 PM PST by Utilizer

...

Fabian Wosar of Emisoft has created a tool capable of decoding files encrypted by the DecryptorMax ransomware, also known as CryptInfinite.

The ransomware gets its name from the fact that the "DecryptorMax" string is found in multiple places inside its source code. Additionally, the CryptInfinite moniker is also used by some researchers because the ransomware adds the CryptInfinite key to the Windows registry, using it to store a list of all encrypted files and their location on disk.

According to Bleeping Computer's Lawrence Abrams, the ransomware is spread via Word documents attached to spam email. These files pose as resumes. Users get infected via weaponized Word documents

Infection occurs when users open the document and enable Word Macros so that they can view the "proper" file. Word Macros are a known security vulnerability used by many malware developers to spread Web-hosted malware to Windows computers.

(Excerpt) Read more at news.softpedia.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: computer; malware; microsoft; ransom; ransomware; windows; windowspinglist
Ransomware fix found!
1 posted on 11/28/2015 6:55:45 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: dayglored

FYI...


2 posted on 11/28/2015 6:56:08 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
"Ransonware fix found!"

... At your nearest Apple Store.

3 posted on 11/29/2015 1:28:55 AM PST by The KG9 Kid
[ Post Reply | Private Reply | To 1 | View Replies]

To: The KG9 Kid

Or for free at the LinuxMart.


4 posted on 11/29/2015 1:35:02 AM PST by Fresh Wind (Falcon 105)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Fresh Wind

I agree, but Linux is for those who really need to understand what they’re about to inflict upon themselves.


5 posted on 11/29/2015 1:46:49 AM PST by The KG9 Kid
[ Post Reply | Private Reply | To 4 | View Replies]

To: The KG9 Kid

Linus is wonderful.

And free.

Only slightly challenging. It is well worth the trouble.


6 posted on 11/29/2015 1:59:43 AM PST by Cringing Negativism Network (http://www.census.gov/foreign-trade/balance/c5700.html)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Cringing Negativism Network

Linux.

(der)


7 posted on 11/29/2015 2:00:06 AM PST by Cringing Negativism Network (http://www.census.gov/foreign-trade/balance/c5700.html)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Cringing Negativism Network

Okay.


8 posted on 11/29/2015 2:08:48 AM PST by The KG9 Kid
[ Post Reply | Private Reply | To 6 | View Replies]

To: Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Sounds pretty useful to the victims!

Handy info if you get hit by DecryptorMax ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to Utilizer for the ping!!

9 posted on 11/29/2015 6:55:46 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer
The fact that word documents are still a security threat boggles the mind. Isn't at almost 2016? Microsoft:the hacker's wet dream.
10 posted on 11/29/2015 8:01:36 PM PST by zeugma (http://xkcd.com/1608/)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson