Nytro Posted August 31, 2014 Report Posted August 31, 2014 HOW (AND WHY) WEDEFEATED DIRCRYPTDirCrypt is a particularly nasty variant of ransomware. In addition to encrypting mostof the user’s files and demanding ransom for their decryption, the malware staysresident in the system, and immediately encrypts any new file which is created orsaved. Therefore, the user is completely prevented from using the computer normally.The normal advice to victims of ransomware is to recover files from some previousbackup. If there isn’t a backup, the victims are given the option of either accepting theloss of their data—or paying the attacker. However, Check Point’s Malware ResearchTeam has found that in the case of DirCrypt, victims of the malware can recover almostall of their data, due to several weaknesses in the way the malware implements itscrypto functionality.Download: http://www.checkpoint.com/download/public-files/TCC_WP_Hacking_The_Hacker.pdf Quote