A word on XDocCrypt Dorifel Quervar
A word on XDocCrypt Dorifel Quervar Im sure everyone has heard by now about the so called XDocCrypt/Dorifel/Quervar malware. It has mostly damaged machines in The Netherlands, but reports have come in from other countries (including the United States) as well. I myself have seen this infection on 08/08/2012, my initial thought was: ransomware. However, there isnt any message displayed, so its either a failed ransomware attempt or the malware simply wants to annoy users. This virus infects Office files, reverses the extension and adds �.scr� behind it (this is also known as the RTLO unicode hole, which makes it easy to hide the original file extensions. - I remember a blogpost from not too long, about this hole targeting users of the Arabic language, let me know if you find it - ). Renaming does not solve the issue, you cannot open the documents. Office files affected by the malware As is depicted in the figure above, Word and Excel files have their extension reversed, so now the files ...