Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Tuesday, December 18, 2012

Ransomware Variant Wants You to Take Surveys to "Unlock" Your PC

Warning!Typically when ransomware takes hold of a computer, it prevents users from accessing their files and demands a couple hundred dollars to regain access.

It seems as though cybercriminals are shaking things up a bit, as GFI Labs researchers recently discovered a new ransomware variant that locks users out of their systems & demands that they complete (an unknown number of) online surveys to unlock it.

Although the researchers didn’t disclose where the ransomware sample came from, they did warn that the threat comes disguised as a filed named “svchost.exe,” although there’s no telling why a user would willingly execute said file.

Either way, should a user make the mistake of running it, they will be locked out of their desktop and presented with the following popup window:

Ransomware Demands You Take SurveysScreenshot Credit: GFI Labs



Unlock this Page to Continue!

This page will immediately unlock and restore normal access upon your participation in an offer below. Please use valid information!

Completions      Reload Offers    My History

Your desktop was locked. Complete an offer below to unlock your desktop!

Your desktop was locked. Complete an offer below to unlock your desktop!

Mystery Shoppers Needed! Earn a £100 ASDA Voucher!
Win a brand new iPhone 4S! Choose Your Colour!
Chance to WIN a £500 Amazon Voucher!
Testers Needed for the iPhone 5!
Win an Apple Macbook Pro + iPhone 4s or iMac + the new iPad!
WIN an iPhone 5 or iPad 3!

Complete an offer to continue »

Fortunately, users don’t have to adhere to the demands of the ransomware or take their PC in for servicing to escape the evil clutches of this particular ransomware. All they have to do is hit Ctrl + Alt + Del and end the mysterious “Locker” process in Task Manager and voila! You can go about your business, which hopefully involves running a full system scan using your antivirus software to remove the infection.

GFI’s security solution, VIPRE Antivirus detects the malicious files associated with this threat as Trojan.Win32.Generic!BT; however, as the name implies, this name covers a wide variety of malicious apps so other antivirus programs may detect it under a different name.

Of course, the best way to deal with ransomware – or any other malware for that matter – is to do all you can to prevent your system from getting infected in the first place. With that, here are some tips to help keep your PC safe:

  • Do not click on links or download files attached to unsolicited emails.

  • Exercise caution when following suspicious links or shortened URLs (always use a URL expander to check the destination URL first).

  • Keep your operating system and third-party software fully patched and up-to-date.

  • Always run antivirus/anti-malware software, keep the virus definitions current and scan your system on a regular basis.

  • Use a Windows user account that has limited privileges (unable to install software).


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Wednesday, October 10, 2012

New Ransomware Variants Are Vocal About Their Demands

Ransomware!! Ahhh!!You know what would really suck?

If your computer was infected with ransomware that not only locked you out of your machine, but repeatedly blasted an audio file that states the reason why you’re locked out is because you violated some copyright laws & you’ll have to fork over some cash to regain access to your files.

Oh, wait.... that could totally happen.

For the past few months, cybercriminals have begun increasingly using ransomware to extort money out of unwitting end-users. Typically the user is just shown a message accusing them of anything from illegal file-sharing to viewing child pornography, denied access to use their computer for anything more than an oversized paperweight and instructed to pay a hefty “fine” to regain access.

According to TrendMicro researchers, new variants of ransomware add a “non-malicious” .MP3 file to the mix, which will undoubtedly drive users even more insane as it repeatedly informs them that their system is blocked because they violated federal laws and that they’ll have to pay a $200 fine to make it all go away.

TrendMicro detects the new threats as TROJ_RANSOM.CXB and TROJ_RANSOM.AAF. The message displayed to the end user is shown below:

.mp3-loaded ransomware messageScreenshot Credit: TrendMicro


Removing ransomware varies from infection to infection; it all depends on how the author configured the malware to lock you out.

Regardless how the ransomware operates, users are urged not to pay the cybercrook to have their PC “unlocked.” There’s no guarantee that the cybercriminal will follow through with their promise to unlock your machine, and 9/10 the payment method used eliminates any possibility of retrieving your funds in the event that they don’t keep their word.

Instead, do what you can to prevent the infection in the first place, and if your PC does wind up getting infected, you can either research the removal steps for the specific piece of ransomware on your machine, or take your computer to be repaired by a professional.

How to Keep Your PC Safe from Ransomware



  • Keep your operating system and installed third-party software patched and up-to-date.

  • Always run antivirus software that offers real-time scanning features, and be sure to keep the virus definitions current.

  • If you don’t need or use it, consider removing Java from your computer.

  • Do not download files attached to emails from unknown or untrusted sources.

  • Always remain vigilant and investigate suspicious website links before clicking on them.


Photo Credit: Don Hankins

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Thursday, May 31, 2012

FBI Warns Users Not to Fall for Reveton Ransomware Scam

Warning! The FBI's Internet Crime Control Center (IC3) has joined Trusteer in warning users about an ongoing malware attack that plants ransomware on the target PC, rendering the system useless until the user pays a $100 fine to unlock it.

The attack starts when the user visits a malicious website that infects their computer with the Citadel Trojan via drive-by-download. The Citadel Trojan then connects to its command & control server to download the Reveton ransomware.

Upon execution, Reveton locks the infected system and displays a fake warning message from the US Department of Justice claiming that the user’s IP address was used to view disturbing content, including child pornography, and that a $100 fine must be paid to unlock the system.

Reveton Malware Message
Attention!

This operating system is locked due to the violation of the federal laws of the United States of America! Following violations were detected

Your IP address is [YOUR IP]. This IP address was used to visit websites containing pornography, child pornography, zoophilia, and child abuse. Your computer also contains video with pornographic content, elements of violent and child pornography! Spam-messages with terrorist motives were also sent from your computer.

This computer lock is aimed to stop your illegal activity.

It is important to note that even if the user makes the mistake of paying off the “fine” cooked up by the Reveton ransomware, they’re still not off the hook.

The Citadel Trojan continues to work independently of the Reveton ransomware, harvesting personal and financial information that will be used by cybercriminals to commit identity theft and credit card fraud. The infected machine may also be recruited to participate in DDoS attacks and spam campaigns.

Protecting Your PC From Citadel & Reveton Malware


Since the Citadel Trojan is delivered via drive-by-download attacks, users can minimize their chances of infection by:

  • Keeping your operating system patched and up-to-date.

  • Installing updates for any software on your machine, especially Adobe Flash, Adobe Acrobat and Java since they are commonly exploited in drive-by-download attacks. You may also want to consider disabling Java if it’s not needed.

  • Always run antivirus software and make sure the virus definitions are current.

  • Remain vigilant and use common sense. Don’t visit sites that are suspicious, but keep in mind that cybercriminals often use compromised sites to conduct drive-by-downloads.


[via IC3 & Trusteer]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+