Jigsaw crypto-ransomware deletes more files the longer you delay paying

By April 12, 2016Bitcoin Business

The Jigsaw killer mask used as logo by the Jigsaw ransomware program. Understanding how to buy bitcoins and pay ransomware authors for decryption keys is hard enough, yet some cybercriminals now expect their victims to do it in under an hour if they want all of their files back.

A new ransomware program dubbed Jigsaw encrypts users’ files and then begins to progressively delete them until the victim pays the equivalent of $150 in bitcoin cryptocurrency.

The ransomware deletes one file after the first hour has passed and then increases the number of files it deletes in every 60-minutes cycle. If no payment has been made within 72 hours, all remaining files will be deleted.

"Try anything funny and the computer has several safety measures to delete your files," the program’s creators warn in their ransom message that’s accompanied by a picture of the Jigsaw killer’s mask from the horror film series Saw.

That’s not an idle threat. According to computer experts from tech support forum BleepingComputer.com, the ransomware program deletes 1,000 files every time the computer or its own process is restarted. BleepingComputer.com The ransom note displayed by the Jigsaw ransomware program. "This is the first time that we have seen these types of threats actually being carried out by a ransomware infection," said BleepingComputer.com founder Lawrence Abrams in a blog post .

The good news, for now, it that malware experts have devised a method to decrypt files affected by Jigsaw without paying the ransom.

The first thing that users affected by this ransomware program should do is to open the Windows Task Manager and terminate all processes named firefox.exe or drpbx.exe that were created by the ransomware, Abrams said. Then they should launch the Windows MSConfig utility and disable the startup entry that points to %UserProfile%AppDataRoamingFrfxfirefox.exe.

This will stop the file deletion process […]

Leave a Reply

All Today's Crypto News In One Place