Jump to content

Recommended Posts

  • ExTS Admin
Posted

http://exts.org/data/MetaMirrorCache/eb43f31e67a8b267128fe77fa30dbb8a.jpg

 

Users who had the misfortune of getting infected with the Gomasom ransomware can now start sending Christmas gifts to Fabian Wosar, security researcher at Emsisoft, who has managed to create a tool for decrypting files locked by this ransomware.

 

Compared to other ransomware families, Gomasom is a relatively new face on the malware market, having reared its ugly head only in the last few weeks.

 

Gomasom, named after "GOogle MAil ranSOM," works by infecting users and then encrypting files, leaving a Gmail address in each file's name, and adding the .crypt file extension at the end.

 

Mr. Wosar created a tool that users can take advantage of to analyze encrypted files and obtain the decryption key. Once the decryption key is in the user's possession, they can use the same tool to decrypt all their files.

 

The best decryption results are achieved when the user has access to a file, in both its ransomware-encrypted and original version. If not, then don't worry, because users can take a PNG file encrypted with the ransomware, and compare it to a random PNG file from the Internet. Results may vary for this method, though, and if you have GBs of encrypted data, the decryption process may take some time, even more than a day.

 

The Gomasom decryption tool is available from Emsisoft's website, and usage instructions can be found on a Bleeping Computer forum thread.

 

http://exts.org/data/MetaMirrorCache/a06a43e755d86c3820675fa3d99793ca.gif

 

 

 

Source:

http://news.softpedia.com/news/gomasom-ransomware-decrypted-get-your-files-back-for-free-497945.shtml

Member of:

UNITE

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...