Trojan Demands Ransom from Victims
By Ed Oswald | Published April 27, 2006, 1:20 PM
A new trojan is making its rounds on the Internet, freezing up victims' computers and then demanding a ransom be paid through Western Union. Called "ransomware," the viruses have been around in Russia for several months, but the first English variants appeared in March.
Sophos discovered the trojan and has named it "Troj/Ransom-A." According to the security firm, these types of viruses are fairly new. The company said it does not know at this time how the trojan is being spread, but it is investigating.
According to the description of the virus on the Sophos Web site, when the virus is run, it displays the message "Deleted files are going to be saved into a hidden directory and replaced during uninstallation. (1) files are being deleted every 30 minutes."
The trojan will also display pornographic images on the infected computer, as well as a message saying it is moving the user's files into invisible hidden folders.
Attempting to kill the process shows a picture and the following messages: "Yeah, We don't die, We multiply! Ctrl+Alt+Del isn't quite working today, is it? I'm not the sharpest tool in the shed but Crtl+Alt+Del is everyone's S.O.S."
In order to unlock the computer, the user is asked to send $10.99 via Western Union. Instructions are provided on the message that appears on the screen. The virus writer even offers tech support if the code provided to unlock the computer does not work.
Lol...some of these viruses are so lame. What's this person gonna do? Wreck my computer..no big deal since i reformat from time to time anyways
Score: 0
|That's why people should backup regularly or just TRY not to get infected with this.
Some people are just asking to get infected.
Score: 0
|EXACTLY...oh, and having backups isn't good enough..you must also actually have to test your backups *THE HORROR!!!*.. You mean, I actually have to do maintenance to my PC? [sic]
Score: 0
|Muhahaha, we have all your base and if ytou want it back you shall payyyyyyyy
Score: 0
|Damn that is classic! Someone had a hell of a lot of time on their hands. I wonder if they made any money, if they did was it really worth it once they are caught to have to serve some jail time. Also can't forget to hank MS for this wonderful opportunity.
Score: 0
|I am sure that MS will say you are welcome Michael Moore, and yes it's everyone's fault that offers a product if that product gets in a bit of a mess just like it's GM's fault when a car crashed or Kmart's fault that some one was shot with a bullet that they sell. HMmmmmmmmmm real smart there.
Score: 0
|I think the point he was making was that KMart, a family-orientated business, shouldn't be in the business of selling ammunition for *weapons*.
Score: 0
|Dude, that is just stupid! They are a store and sell products. What you do with it after it has been bought is different. Why shouldn't they sell bullets? They are there to sell products and make money. Not even 80 years ago, if someone tried to pull a stunt like that he would have been lynched for stupidity!
Score: 0
|i think the initial point was : u can't blame a manufaturer if u screw up with his product :) , this in turn leaves some debate as in : MS shoud be a bit more carefull , but trojans are not his fault most ppl get it by visiting shady sites and being lured by fake free porn :) being a cheepskate and not wanting to spend on a girl gets u this :))
ps: akurat kmart thingy whoud be : blame kmart for chokeing on a fishbone from a fish they sold :P
Score: 0
|OSX b*tches!
Score: 0
|LOL! correct :P
Score: 0
|OSX: Is every bit as vulnerable. Morons. The only reason why there aren't more viruses for OSX is because it has a lower market share. Next ppl will say LINUX...same issue. Got news for you; the best defense is a decent Antivirus, and COMMON SENSE. "Oh, it says nude pics of Jessica Simpson,...should I open it?"... of course you should...and then spend the rest of your night wondering why your computer is FUBAR.
Score: 0
|But Linux will let you kill it, and both OSX and Linux will popup a warning before it starts. :P
Taskman lets companies "protect" their services - Norton prevents any of its services from being terminated, for example.
Process Explorer seems to ignore most protections, as does Spybot S&D. I use them both to kill naughty windows components when testing things.
Score: 0
|... and then I pop in my FU-ware (Knoppix), get the files back, and give thse people the finger.
Score: 0
|"The virus writer even offers tech support if the code provided to unlock the computer does not work."
But will he provide better tech support? If he does, people might get infected on purpose just so that someone can bail them out. :>
Actually, I doubt he'll deliver on the promise to offer tech support. People who do that to people cannot be trusted.
Score: 0
|The victims calls are actually forwarded to a call center in Bombay, India. After being read the code by tech support, victims have to ask, "What did you say, again?"
Score: 0
|AOL users stand no chance.
Score: 0
|yeah, they'll probably even pay more in hopes of not getting any more viruses in the upcoming days ....
remember, they go by the concept
"the more you pay, the more protected you are"
Score: 0
|I wouldn't be suprised if the Trojan was made by AOL to make profits for it's fledgling internet service.
Score: 0
|That would go with their new policy of "screw em, take the money". You know sell them on anti spam software and then let the spam companies pay to bypass it.
Score: 0
|Nice.
Question fo the day....
"But will it run in Linux?"
Score: 0
|hmm, good question... try installing IE under WINE, browse the net for a while, see what happens. CTRL ALT DEL might not work, but under KDE you can try CTRL ALT ESC and then click the WINE window. Hell, it sounds safe enough to do running WINE as Root ;) When you're done, just re-install WINE.
Score: 0
|"Yeah, We don't die, We multiply! Ctrl+Alt+Del isn't quite working today, is it? I'm not the sharpest tool in the shed but Crtl+Alt+Del is everyone's S.O.S."
That's priceless. I wrote a program that did that and sent it to a friend as a joke one time, barrel of laughs right there.
"The virus writer even offers tech support if the code provided to unlock the computer does not work."
LMAO! What a moron!
It won't take long to figure out where the money is being tranferred to.
Score: 0
|first english variant didn't appear in March.
1st variant appeared a few years ago. it was a trojan/virus that would rar all your documents with a long password and then create txt file on your desktop informing you of this...
Score: 0
|Yes but it didn't ask you for you money, or take the information and refuse to relinquish any of it, unless you PAID them, so how is this even remotely the same?
Score: 0
|yes it DID!
txt file on your desktop contained ransom demand and claim once they had the money they will provide password to unpack your files so it is EXACTLY the same scam.
Score: 0
|http://www.betanews.com/...Back_Pay_200/1116953344
Score: 0
|Except for the deleting part.
Score: 0
|Wow...this ransomware is making geekspeakware and frankliyware every other technoligyware very confusingware to readware aboutware.
Score: 0
|lolware
Score: 0
|Woware!
Wil' wil' west, toot tu root tu tu tu toot tu roo, wil' wil' west.......
Score: 0
|lol, sounds good anyway
Score: 0
|