Trojan Demands Ransom from Victims

By Ed Oswald | Published April 27, 2006, 1:20 PM

A new trojan is making its rounds on the Internet, freezing up victims' computers and then demanding a ransom be paid through Western Union. Called "ransomware," the viruses have been around in Russia for several months, but the first English variants appeared in March.

Sophos discovered the trojan and has named it "Troj/Ransom-A." According to the security firm, these types of viruses are fairly new. The company said it does not know at this time how the trojan is being spread, but it is investigating.

According to the description of the virus on the Sophos Web site, when the virus is run, it displays the message "Deleted files are going to be saved into a hidden directory and replaced during uninstallation. (1) files are being deleted every 30 minutes."

The trojan will also display pornographic images on the infected computer, as well as a message saying it is moving the user's files into invisible hidden folders.

Attempting to kill the process shows a picture and the following messages: "Yeah, We don't die, We multiply! Ctrl+Alt+Del isn't quite working today, is it? I'm not the sharpest tool in the shed but Crtl+Alt+Del is everyone's S.O.S."

In order to unlock the computer, the user is asked to send $10.99 via Western Union. Instructions are provided on the message that appears on the screen. The virus writer even offers tech support if the code provided to unlock the computer does not work.

Comments

View comments by with a score of at least

Lol...some of these viruses are so lame. What's this person gonna do? Wreck my computer..no big deal since i reformat from time to time anyways

Score: 0

|

That's why people should backup regularly or just TRY not to get infected with this.
Some people are just asking to get infected.

Score: 0

|

EXACTLY...oh, and having backups isn't good enough..you must also actually have to test your backups *THE HORROR!!!*.. You mean, I actually have to do maintenance to my PC? [sic]

Score: 0

|

Muhahaha, we have all your base and if ytou want it back you shall payyyyyyyy

Score: 0

|

Damn that is classic! Someone had a hell of a lot of time on their hands. I wonder if they made any money, if they did was it really worth it once they are caught to have to serve some jail time. Also can't forget to hank MS for this wonderful opportunity.

Score: 0

|

I am sure that MS will say you are welcome Michael Moore, and yes it's everyone's fault that offers a product if that product gets in a bit of a mess just like it's GM's fault when a car crashed or Kmart's fault that some one was shot with a bullet that they sell. HMmmmmmmmmm real smart there.

Score: 0

|

I think the point he was making was that KMart, a family-orientated business, shouldn't be in the business of selling ammunition for *weapons*.

Score: 0

|

Dude, that is just stupid! They are a store and sell products. What you do with it after it has been bought is different. Why shouldn't they sell bullets? They are there to sell products and make money. Not even 80 years ago, if someone tried to pull a stunt like that he would have been lynched for stupidity!

Score: 0

|

i think the initial point was : u can't blame a manufaturer if u screw up with his product :) , this in turn leaves some debate as in : MS shoud be a bit more carefull , but trojans are not his fault most ppl get it by visiting shady sites and being lured by fake free porn :) being a cheepskate and not wanting to spend on a girl gets u this :))

ps: akurat kmart thingy whoud be : blame kmart for chokeing on a fishbone from a fish they sold :P

Score: 0

|

OSX b*tches!

Score: 0

|

LOL! correct :P

Score: 0

|

OSX: Is every bit as vulnerable. Morons. The only reason why there aren't more viruses for OSX is because it has a lower market share. Next ppl will say LINUX...same issue. Got news for you; the best defense is a decent Antivirus, and COMMON SENSE. "Oh, it says nude pics of Jessica Simpson,...should I open it?"... of course you should...and then spend the rest of your night wondering why your computer is FUBAR.

Score: 0

|

But Linux will let you kill it, and both OSX and Linux will popup a warning before it starts. :P

Taskman lets companies "protect" their services - Norton prevents any of its services from being terminated, for example.

Process Explorer seems to ignore most protections, as does Spybot S&D. I use them both to kill naughty windows components when testing things.

Score: 0

|

... and then I pop in my FU-ware (Knoppix), get the files back, and give thse people the finger.

Score: 0

|

"The virus writer even offers tech support if the code provided to unlock the computer does not work."

But will he provide better tech support? If he does, people might get infected on purpose just so that someone can bail them out. :>

Actually, I doubt he'll deliver on the promise to offer tech support. People who do that to people cannot be trusted.

Score: 0

|

The victims calls are actually forwarded to a call center in Bombay, India. After being read the code by tech support, victims have to ask, "What did you say, again?"

Score: 0

|

AOL users stand no chance.

Score: 0

|

yeah, they'll probably even pay more in hopes of not getting any more viruses in the upcoming days ....
remember, they go by the concept
"the more you pay, the more protected you are"

Score: 0

|

I wouldn't be suprised if the Trojan was made by AOL to make profits for it's fledgling internet service.

Score: 0

|

That would go with their new policy of "screw em, take the money". You know sell them on anti spam software and then let the spam companies pay to bypass it.

Score: 0

|

Nice.

Question fo the day....

"But will it run in Linux?"

Score: 0

|

hmm, good question... try installing IE under WINE, browse the net for a while, see what happens. CTRL ALT DEL might not work, but under KDE you can try CTRL ALT ESC and then click the WINE window. Hell, it sounds safe enough to do running WINE as Root ;) When you're done, just re-install WINE.

Score: 0

|

"Yeah, We don't die, We multiply! Ctrl+Alt+Del isn't quite working today, is it? I'm not the sharpest tool in the shed but Crtl+Alt+Del is everyone's S.O.S."

That's priceless. I wrote a program that did that and sent it to a friend as a joke one time, barrel of laughs right there.

"The virus writer even offers tech support if the code provided to unlock the computer does not work."

LMAO! What a moron!
It won't take long to figure out where the money is being tranferred to.

Score: 0

|

first english variant didn't appear in March.
1st variant appeared a few years ago. it was a trojan/virus that would rar all your documents with a long password and then create txt file on your desktop informing you of this...

Score: 0

|

Yes but it didn't ask you for you money, or take the information and refuse to relinquish any of it, unless you PAID them, so how is this even remotely the same?

Score: 0

|

yes it DID!
txt file on your desktop contained ransom demand and claim once they had the money they will provide password to unpack your files so it is EXACTLY the same scam.

Score: 0

|

Except for the deleting part.

Score: 0

|

Wow...this ransomware is making geekspeakware and frankliyware every other technoligyware very confusingware to readware aboutware.

Score: 0

|

lolware

Score: 0

|

Woware!
Wil' wil' west, toot tu root tu tu tu toot tu roo, wil' wil' west.......

Score: 0

|

lol, sounds good anyway

Score: 0

|

Mark Russinovich on MinWin, the new core of Windows

The next version of Windows three years hence will likely build onto a significant architectural change implemented in Windows 7 and Server 2008 R2.

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

My Windows 7 confession (and why you should confess, too)

I've held back the real reason for sticking with Windows 7, even as, gulp, iLife calls me to go back to the Mac.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Google begrudgingly adjusts news crawling for paid publishers

If publishers want to make readers pay for news content, and thereby drive down its popularity and Google ranking, the company says, they can just go right on ahead.

Fee or free? Murdoch, Huffington square off over the cost of Internet news

Participants in an FTC workshop yesterday witnessed the two extremes of the Web news publishing debate, still centered on the issue of long-term profitability.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?