iTnews

File-deleting Jigsaw ransomware cracked

By Juha Saarinen on Apr 14, 2016 10:57AM
File-deleting Jigsaw ransomware cracked

Decryptor found for aggressive malware.

Researchers have been quick to defeat the recently discovered Jigsaw ransomware, which will aggressively delete encrypted user files on Windows computers until payment is received from its victims.

The new decryptor comes from the same team that cracked the Petya ransomware this week - computer forensics specialist Lawrence Abrams and collaborators at the Bleeping Computer website, Michael Gillespie, as well as the Malwarehunterteam.

Jigsaw targets a large number of file types and scrambles them with the Advanced Encryption Standard (AES) Rijndael algorithm. 

The malware is very destructive and will start spreading its damage each time users log in to Windows.

Users are asked to pay ransom of US$20 to US$200 (A$26 to A$260), or 0.4 Bitcoin (A$222) depending on which variant of Jigsaw they've been attacked with. Five variants of Jigsaw have been detected by Abrams so far.

If no payment is received to a Bitcoin address within 60 minutes of Jigsaw starting up, the ransomware will delete one or more of the victim's files. The deletion of files is repeated every 60 minutes, until users give into the blackmail and pay up.

To stop files from being deleted, users are advised to terminate the two processes Jigsaw runs on Windows using Task Manager: firefox.exe and drpbx.exe.

Once the two processes have stopped, it is crucial to run the msconfig utility in Windows and remove the firefox.exe startup entry, otherwise the ransomware can restart and delete another thousand files.

After Jigsaw has been terminated, victims can run the program developed by Gillespie to decrypt their files and hard drives.

At the time of writing, it is not clear how Jigsaw spreads or who is behind the blackmailing malware.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
blackmaildecryptorjigsawransomwaresecurity

Partner Content

Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • 11th Annual Fraud Prevention Summit 2022
  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Juha Saarinen
Apr 14 2016
10:57AM
0 Comments

Related Articles

  • Tick off the ransomware bandits
  • US puts million dollar bounties on Russian hackers' heads
  • Mandatory cyber security incident reporting now in force
  • Lapsus$ hackers exploited Okta supplier's security lapses
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

What to expect from the incoming Labor government

What to expect from the incoming Labor government

Digital Nation

COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.