跳到主体内容

No Ransom: The National High Tech Crime Unit of the Netherlands’ police and Kaspersky Lab help victims to escape from CoinVault ransomware

2015年4月14日

From today, victims of CoinVault ransomware have a chance to retrieve their data without paying the criminals

From today, victims of CoinVault ransomware have a chance to retrieve their data without paying the criminals, thanks to a repository of decryption keys and a decryption application made available online by Kaspersky Lab and the National High Tech Crime Unit (NHTCU) of the Netherlands’ police. The keys and the tool can be found on noransom.kaspersky.com, together with clear instructions on how to implement them.

CoinVault ransomware has been around for a while, encrypting victims’ files and demanding Bitcoins to unlock them. In order to help victims recover from an attack, the NHTCU and the Netherlands’ National Prosecutors Office obtained a database from a CoinVault command & control sever. This server contained Initialization Vectors (IVs), Keys and private Bitcoin wallets and helped Kaspersky Lab and the NHTCU to create the special repository of decryption keys. As the investigation is ongoing, new keys will be added when available.

“If you get infected with the CoinVault ransomware, please check noransom.kaspersky.com. We have uploaded a huge number of keys onto the site. If we do not currently have records for a particular Bitcoin wallet, you can check again in the near future, because together with the National High Tech Crime Unit of the Netherlands’ police we are continuously updating the information,” - says Jornt van der Wiel, Security Researcher at Global Research and Analysis Team, Kaspersky Lab.

CoinVault has infected more than 1,000 Windows-based machines in over 20 countries, with the majority of victims in the Netherlands, Germany, the USA, France and the UK. Victims have also been registered in Belgium, Austria, Switzerland, Norway, Sweden, Luxemburg, Denmark, Slovakia, Slovenia, Spain, Italy, Hungary, Ireland, Croatia, Russia, Canada, Israel, the United Arab Emirates, China, Indonesia, Thailand, South Africa, Australia, New Zealand, Panama, the Dominican Republic, and Mexico.

“Nowadays, many believe that combatting cybercrime requires public-private partnerships. We do it. Just talk to your partners, identify how you can help each other achieve a mutual aim: helping cybersecurity.” - explains Marijn Schuurbiers from the High Tech Crime Team of the Dutch Police.

Kaspersky Lab’s security experts also analyzed the malware samples and designed and built a decryption tool that can unlock files and delete the CoinVault malicious program from infected computers.

If a PC has been infected with CoinVault, an image such as the following will appear on the screen:

To discover how to remove the CoinVault ransomware from your computer and restore your files, please visit https://noransom.kaspersky.com/.

How to avoid being infected? Keep your anti-malware suite updated and make a habit of backing up your most important files.

Kaspersky detects this family as 'Trojan-Ransom.Win32.Crypmodadv.cj'.

No Ransom: The National High Tech Crime Unit of the Netherlands’ police and Kaspersky Lab help victims to escape from CoinVault ransomware

From today, victims of CoinVault ransomware have a chance to retrieve their data without paying the criminals
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻