$120 Ransomware

Try this beauty on your PC

 

 http://nakedsecurity.sophos.com/2010/11/26/drive-by-ransomware-attack-demands-120/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+nakedsecurity+(Naked+Security+-+Sophos)

 

Quads

There is another Ransomware out that overwrites your MBR with it's own version of MBR,  When the PC gets turned on  and goes though the boot process the PC stops at the Black Screen with White writing like when using the recovery console, or when Windows has a missing or corrupt file needed to boot Windows.

 

The Message reads:-

 

 

Your PC is blocked.. 
All the hard drives were encrypted..
Browse www.[Removed by Quads] to get an access to your system and files...
Any attempt to restore the drives using other way will..
lead to inevitable data loss!!!..
Please remember Your ID: 77 [Removed by Quads]
with its help your sign- on password will be generated. Enter password:..

 

 

I have one variant of this and it's not as easy as just Fixmbr.

 

http://www.threatexpert.com/report.aspx?md5=1e7a4a518c91432c816917bd14ab323b

 

ADDED:

 

http://www.symantec.com/security_response/writeup.jsp?docid=2010-120103-1558-99&tabid=2

 

Quads

Curious to hear why Symantec has it on Security level : Low

 


Stu wrote:

Curious to hear why Symantec has it on Security level : Low


I would agree,cant understand why Symantec has classed this as a low threat?

 

It would depend on What is the "Threat Level" is graded on.  I can see what looks like you 2 are thinking the Threat Level means, but what if it's not that?? :smileywink:

 

Quads

Hmmm.  Perhaps the answer can be found here:

 

http://www.symantec.com/security_response/severityassessment.jsp   :smileyhappy:

Bingo

 

Most people just read "Threat Level" as 

 

1.2 Damage

The damage component measures the amount of damage that a given infection could inflict. Information in this metric includes:

  • Triggered events
  • Deleted/modified files
  • Release of confidential information
  • Performance degradation
  • Buggy routines that cause unintended loss of productivity
  • Compromised security settings
  • Ease of fixing damage
With  Difficulty to remove/repair" added from 1.3  
Forgetting about the rest.
Quads

Yeah, I have noticed that the assigned threat levels never seem too impressive unless the infection is spreading like a wildfire, which doesn't happen much anymore, as it once did back in the days of weekly definitions updates.

The Ransoms don't seem to be spreading around much at all, In comparsion to what Conficker, TDL (TDSS), etc have done over the last couple of years.

 

If Threat Levels were just on what they did to a PC (poor user) then the likes of the fake Stuxnet Cleaner that deletes everything on C:\ has to be at the top group in terms of everything gone.  But have yet to come across someone who accidentally  used it.  In comparison to the users on the net over the couple of years who were infected with TDL (1, 2, 2+, 3, 3+, 4)

 

Quads

Norton / Symantec detects the GP code encrypting ransomware as http://www.symantec.com/security_response/writeup.jsp?docid=2010-112517-0111-99

 

Quads

The "Ransom" to be paid in the new variant is now up to $125

 

Quads

Here's a cute new bit of ransomeware:

 

http://www.f-secure.com/weblog/archives/00002139.html

 

 

A new variant of the Winlock group of Ransomware, which like some others pretends to be a form of Windows Activation, when it's not.

There are also BSOD variants and Pornblock variants ...............................

 

Still better than the GPcode ransomware, because once you break the Winlock Ransomware to get Windows back the personal files are OK.

But the GPcode ransomware, personal files are not OK but encrypted, and would take years to break each encryption.

 

For this Winlock try unlock code 1351236

 

Quads

In testing this Winlock, Norton detects it.

 

Quads

Years to break each encrytion???????

 

So does that mean use of applicaion to break?

 

 

No Expert can help to decrypt the files?

 

 

Why has symantec then assigned the damage level

 

as   Damage Level: Medium

Does this tool from kaspersky help ?

 

 

http://support.kaspersky.com/viruses/solutions?qid=208282275

Just shows that people who are not in the Malware field and don't know what they are looking at should not attempt Malware removal because of a major possible balls up, not knowing what you are looking at, pulling the wrong thing, and screwing a PC using a wrong tool.

 

What do you not understand when it is stated that no one has decrpted it.

 

Your tool, why don't you just try it on Ramnit, a FakeAV, Zbot or Mebroot instead.

 

Quads

Try this beauty on your PC

 

 http://nakedsecurity.sophos.com/2010/11/26/drive-by-ransomware-attack-demands-120/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+nakedsecurity+(Naked+Security+-+Sophos)

 

Quads