UIWIX – a ransomware which exploits the same Windows vulnerability as WannaCry

UIWIX is a ransomware-type[1] cyber infection that spreads using flaws in Windows SMBv1 and SMBv2.[2] It is believed to be even more dangerous than WannaCry. Malware uses AES-256 encryption cipher to corrupt files on the affected computer and appends .UIWIX or ._[victim’s id].uiwix file extensions to each of them.
Following data encryption, ransomware drops a ransom note called _DECODE_FILES.txt. Here cyber criminals provide a unique victim’s ID and give a link to the payment website. On the site, people have to enter their ID and captcha to get instructions how to obtain and use a decryptor.
The ransom-demanding message informs that victims need to transfer 0.12261 Bitcoins to the provided address. Once the payment is transferred, people are supposed to give a chance to use a decryption software. However, it may not happen. Cyber criminals are not the ones you can trust.
Thus, they may take your money and leave you with encrypted files. In case of the attack, you should remove ransomware immediately. It won’t recover your files, but it protects your device from other cyber infections. Therefore, run a full system scan with professional malware removal program, for instance, SpyHunterCombo Cleaner and get rid of this cyber infection. It is also recommended to use a complentary tool FortectIntego to fix virus damage on the device.
Security researchers notice that UIWIX uses the similar Windows vulnerabilities as WannaCrypt0r (or WannaCry) ransomware. Malware can infect all devices that are connected to the same network and have a self-replicating capability. However, malware does not have a kill switch domain that makes it even more dangerous than other ransomware viruses.
If the kill switch domain is blocked, ransomware distribution is stopped.[3] Thus, this cyber infection is unstoppable unless the operating system is patched. Furthermore, malware behaves like an ordinary file-encrypting virus. It aims at home computer users, as well as small businesses.
Once it gets on the computer, it starts system scan and looks for targeted files. What makes this virus a particularly malicious infection is the fact that it targets files, their backup copies, and even backup systems [4], leaving virtually no way for the victims to recover their damaged files.
When data encryption is over, malware connects to Command and Control server. It sends a PC identification number and a private decryption key. Once all targeted files are destroyed, UIWIX ransomware drops a ransom note:
>>> ALL YOUR PERSONAL FILES ARE DECODED <<<
Your personal code: XXX
To decrypt your files, you need to buy special software.
Do not attempt to decode or modify files, it may be broken.
To restore data, follow the instructions!
You can learn more at this site:
hxxps://4ujngbdqqm6t2c53[.]onion.to
hxxps://4ujngbdqqm6t2c53[.]onion.cab
hxxps://4ujngbdqqm6t2c53[.]onion.nu
If a resource is unavailable for a long time to install and use the tor browser.
After you start the Tor browser you need to open this link hxxp://4ujngbdqqm6t2c53[.]onion
Following the instructions and transferring a little bit more than $200 is not recommended. If you ever find yourself in such a situation – don’t take things for granted. Remember that there are alternative ways you can try to recover your files, besides, it is not uncommon for malware experts to come up with decryption software that helps ransomware victims restore their encrypted data for free. So, we suggest you carry out UIWIX removal and look for other recovery solutions instead.

Methods of distribution
Developers of the this virus took advantage of vulnerabilities in Windows SMBv1 and SMBv2. Just like WannaCry ransomware, this one is also employing the EternalBlue exploit that has been leaked by a group of hackers called “Shadow Brokers.”
This exploit has been stolen from National Security Agency (NSA)[5] on March 14, 2017. Thus, in order to protect from ransomware users should patch Windows operating system and software. Microsoft released updates even for Windows XP, Windows 8, and Windows Server 2003 that are no longer supported.
Additionally, malware might also attack the device via compromised remote desktop connections. Some researchers suspect that malware might also be distributed via malicious email attachments. Thus, we highly recommend taking all necessary precautions to avoid ransomware and creating data backups.
Terminate malware automatically
UIWIX removal is necessary if you want to continue using your device normally, but several things can help facilitate the removal. For instance, booting the computer in Safe Mode before running the system scan will suppress some malicious virus functionalities and prevent it from blocking your antivirus.
Consequently, you should be able to remove the virus without any difficulty using malware removal programs, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Also, it is important to fix Windows system files after a malware attack – FortectIntego can be used as an automatic repair option. For more detailed instructions on how to enable the Safe Mode, please follow the guidelines below the article.
Did this guide help?
Be the first to comment