Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Users hit by extortion Trojan

Encrypts files, demands money.

Article comments

Anti-virus experts have discovered a new file encryption Trojan that zips up its victim’s files before demanding $300 to have them unscrambled.

Variously identified as “Zippo” and Cryzip” by anti-virus companies, the Trojan is believed to be infecting PCs either via infected websites, or as an email attachment.

Once infected, it encrypts all data files it can find using a long list of file extensions to guide it, storing them in a password-protected zip directory. Clicking on these files brings up a poorly-written message demanding that $300 be paid to a named e-gold account in return for the passphrase to unlock the files.

Although the Trojan was only publicised yesterday, Techworld was contacted last week by one UK user who was struggling with what turns out to be have been this Trojan, so this is no theoretical “lab” attack.

Unable to identify what it was, not only had it encrypted his data files, it had been on his system long enough to carry out the same actions on his backups. This would suggest the Trojan has been spreading for some weeks, and is designed to hide itself until even backups became unusable.

The password to unscramble files turns out to be a directory path, probably to make it hard to detect by researchers reverse engineering its inner workings: “C:\Program Files\Microsoft Visual Studio\VC98” (typed without quotation marks).

The file encryption Trojan is not a new phenomenon, with a small number of Russian-based examples turning up last Spring. Going back further in time, the AIDS Trojan disk of the mid-1990s, which spread by floppy disk, did much the same thing as Zippo, although its spread would be glacial by comparison.

The fact that it has been in the wild and infecting real victims for some days or weeks, raises several issues.

First, the use of encryption presents potential troubles for anti-virus firms. Although programmed encryption of this type is not as difficult to decode as static encryption, it could be difficult to quickly reverse engineer if it evolves much further from its relatively basic Zippo/Cryzip incarnation.

It already looks as if this particular piece of malware has crept under the radar of the major anti-virus firms, as none of them had heard of it until yesterday, days after Techworld was first contacted by the distressed member of the public.

Second - as pointed out by Graham Cluley of security firm Sophos - the fact that a legitimate company, e-gold, is being used in the scam should mean that the account holders are traceable. At the very least, the accounts should be frozen, he suggested.

E-gold was contacted for comment, but had not replied at the time of going to press.


More from Techworld

More relevant IT news


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *