Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

SyncCrypt Support Topic (readme.html & .kk extension)


  • Please log in to reply
1 reply to this topic

#1 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,268 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:44 PM

Posted 16 August 2017 - 10:52 AM

This topic should be used to discuss and receive support for the SyncCrypt ransomware. The SyncCrypt ransomware is currently being distributed via malspam attachmens that pretend to be court orders.

Once a computer is infected, their files will be encrypted and have the .kk extension appended to encrypted files.

ransom-note.jpg



BC AdBot (Login to Remove)

 


m

#2 here2serveu

here2serveu

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:01:44 PM

Posted 28 August 2017 - 03:46 PM

 When I have to use windows I go with PRO not home and use software restriction policies. These will block this kind of stuff. For people running home or those who prefer not to manager SRP rules use cryptoprevent or something similar.  Running a default deny with srp can keep the rules on the lite side and do a good job. Cryptoprevent and similar use paths, hashes and watch files.  Good stuff but can cause unexpected issues, slow log on times and so on.

 

So far it looks like sonicwall Gateway av can catch this one but not seeing any mention of it on my preferred AV vendor - webroot  - site.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users