Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Trojan Freezes Computer, Demands Ransom
yahoo news ^ | 4/28/06 | Jeremy Kirk

Posted on 04/28/2006 12:40:23 PM PDT by Former Fetus

A new kind of malware circulating on the Internet freezes a computer and then asks for a ransom paid through the Western Union Holdings money transfer service.

A sample of the Trojan horse virus was sent to Sophos, a security vendor, said Graham Cluley, senior technology consultant. The malware, which Sophos named Troj/Ransom-A, is one of only a few viruses so far that have asked for a ransom in exchange for releasing control of a computer, Cluley said.

The new Trojan falls into a class of viruses described as "ransomware." The schemes had been seen in Russia, but the first one appeared in English just last month.

"It is a new kind of malware with a particularly nasty payload," Cluley said.

It's unclear how the Trojan is being spread, although Sophos is investigating, Cluley said. Viruses can be spread in several ways, including through spam or a so-called drive-by download that exploits a browser vulnerability when a user visits a malicious Web site.

PC Frozen, Files at Risk.

Once run, the Trojan freezes the computer, displaying a message saying files are being deleted every 30 minutes. It then gives instructions on how to send $10.99 via Western Union to free the computer.

Hitting the control, alt, and delete keys will not affect the bug, the virus writer warns. Sophos provides further details at its Web site.

The virus writer even offers tech support, Cluley said. If the method of unlocking the computer doesn't work after the money is sent, the virus writer promises to research the problem and includes an e-mail address.

Last month, a Trojan emerged that encrypts a user's documents and then leaves a file demanding $300 in exchange for the password to access the information. Victims were instructed to send money to one of 99 accounts run by e-gold, a company that runs a money transfer site.

The password, however, was contained on the infected computer. Sophos cracked it and publicly released it.


TOPICS: Miscellaneous
KEYWORDS: hatewhenthathappens; malware; ransom; ransomware; spyware; trojan; virus
Navigation: use the links below to view more comments.
first 1-5051-55 next last
Please, someone tell me this is not for real. How could it work? I mean, can you wire money to an unknown person at an unknown address? OTOH my antivirus just stopped a trojan earlier today. A coincidence?
1 posted on 04/28/2006 12:40:26 PM PDT by Former Fetus
[ Post Reply | Private Reply | View Replies]

To: Former Fetus

NOD32 just updated a few minutes ago and will put an end to ANY trojan BS.

I'm Lovin' It™ :)


2 posted on 04/28/2006 12:45:04 PM PDT by John Williams ( "Che Guevara -- Gives new meaning to the term 'Banana Republic'")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Former Fetus

using common sense and patching your box can help


3 posted on 04/28/2006 12:45:51 PM PDT by kinoxi
[ Post Reply | Private Reply | To 1 | View Replies]

To: Former Fetus
Once run, the Trojan freezes the computer, displaying a message saying files are being deleted every 30 minutes.

LOL!! Knock yourself out, Sport. My files are on my server...and back up is run nightly..

4 posted on 04/28/2006 12:46:09 PM PDT by TomServo
[ Post Reply | Private Reply | To 1 | View Replies]

To: Former Fetus
Viruses can be spread in several ways, including through spam or a so-called drive-by download that exploits a browser vulnerability when a user visits a malicious Web site.

Don't open any un-solicited emails, and stay away from porn and warez sites. An ounce of prevention is worth a pound of cure.

5 posted on 04/28/2006 12:47:57 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

"Don't open any un-solicited emails, and stay away from porn and warez sites. "




There you go. Keep your pc updated, too, and you won't have any problems.

I've always thought it was funny that so much malware seems to get installed at porn and warez sites. I've never been able to feel too sorry for folks who get infected at such sites, somehow.


6 posted on 04/28/2006 12:52:30 PM PDT by MineralMan (non-evangelical atheist)
[ Post Reply | Private Reply | To 5 | View Replies]

To: TomServo

"LOL!! Knock yourself out, Sport. My files are on my server...and back up is run nightly.."

My stuff is backed up too on an external hard drive that is off and disconnected most of the time. Common sense to back up your stuff if you care about it.


7 posted on 04/28/2006 12:52:47 PM PDT by Names Ash Housewares
[ Post Reply | Private Reply | To 4 | View Replies]

To: Former Fetus

What a coincidence. There's another thread about a sports representative demanding a ransom from a Trojan.


8 posted on 04/28/2006 12:54:10 PM PDT by Richard Kimball (I like to make everyone's day a little more surreal)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

what's warez?


9 posted on 04/28/2006 12:54:55 PM PDT by Flavius Josephus (Nationalism is not a crime.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Former Fetus

Use Linux.

I've not had a single problem with this laptop since I made the switch.

Regards, Ivan


10 posted on 04/28/2006 12:55:10 PM PDT by MadIvan (I aim to misbehave.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MineralMan

Boy, will you be sorry when I'm making big money helping a Nigerian prince get his inheritance into the country from the comfort of my refinanced home while sporting a bigger penis.


11 posted on 04/28/2006 12:56:50 PM PDT by Richard Kimball (I like to make everyone's day a little more surreal)
[ Post Reply | Private Reply | To 6 | View Replies]

To: MineralMan
Keep your pc updated, too, and you won't have any problems.

This is an example of a good Trojan/virus/spyware/whatever. If you do what you are supposed to do, you will not be bothered. If you can't be bothered to do what you are supposed to do...oh well.
12 posted on 04/28/2006 12:57:49 PM PDT by P-40 (http://www.590klbj.com/forum/index.php?referrerid=1854)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Names Ash Housewares

Yup - combined with hardening your system(s).


13 posted on 04/28/2006 12:58:39 PM PDT by TomServo
[ Post Reply | Private Reply | To 7 | View Replies]

To: Flavius Josephus
what's warez?

Pirated software - games and applications

14 posted on 04/28/2006 12:59:26 PM PDT by RabidBartender
[ Post Reply | Private Reply | To 9 | View Replies]

To: MadIvan

Because so few use that software that even hackers don't want to bother with it.


15 posted on 04/28/2006 12:59:39 PM PDT by A CA Guy (God Bless America, God bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: MineralMan

What's a "warez" site?


16 posted on 04/28/2006 1:01:29 PM PDT by ASA Vet (Those who know don't talk. Those who talk don't know.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Former Fetus
Get Root !
17 posted on 04/28/2006 1:02:29 PM PDT by XeniaSt (Hosea 6:6 For I desire mercy, not sacrifice, and acknowledgment of God rather than burnt offerings)
[ Post Reply | Private Reply | To 1 | View Replies]

To: P-40

I've had to fix my brother's computer multiple times because he doesn't update regularly...I had to tell him "One more time, then you're on your own."


18 posted on 04/28/2006 1:06:34 PM PDT by Andonius_99 (They [liberals] aren't humans, but rather a species of hairless retarded ape.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Flavius Josephus
what's warez?

Pirated software.

19 posted on 04/28/2006 1:06:55 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 9 | View Replies]

To: TomServo

"Yup - combined with hardening your system(s)."

I run router with firewall, zone alarm firewall, symantec anti-virus, A2 trojan scanner, spybot or ad aware, Run windows updates regularly. Always ran windows but I never used Outlook for email. I go to Shields Up page now and then to do a scan.

Been heavy internet high bandwidth user for 10 years now.
Only a couple minor viruses ever got through and usually because I did something stupid. Nothing at all has caused me any grief in many years now using the above methods.


20 posted on 04/28/2006 1:07:16 PM PDT by Names Ash Housewares
[ Post Reply | Private Reply | To 13 | View Replies]

To: Richard Kimball
Boy, will you be sorry...

I haven't even taken advantage of all of those things yet and my e-mail is full of more women trying to meet me than I can keep up with. I think I'll take it slow and try to develop a long term relationship with one or two of them. Maybe I'll need protection from another kind of virus.

21 posted on 04/28/2006 1:09:11 PM PDT by FreePaul
[ Post Reply | Private Reply | To 11 | View Replies]

To: John Williams

Is NOD32 as good as I've heard? Granted, you're only the 3rd person I've heard about using it, but all 3 of you seem to like it.


22 posted on 04/28/2006 1:09:53 PM PDT by Andonius_99 (They [liberals] aren't humans, but rather a species of hairless retarded ape.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Former Fetus; All
Time to dust this off, I guess:

PC security-related links.   All software is freeware/open source.

Last Update: 03/04/2005
Anti-Virus:

Antidote SuperLite
On-demand virus checker. Detects, doesn't clean. Huge virus database (excellent back-up scanner).

AntiVir® Personal Edition

AVG Anti-Virus

BitDefender Free Edition v7
On-demand anti-virus program

F-Prot Antivirus
The MS-DOS version is free

McAfee Stinger
On-demand scanner. Detects & cleans a small number of virii/trojans (around 50). Fits on a 3.5" floppy.
Alternatives to MSIE, Outlook & Outlook Express:

Mozilla.org
Mozilla Suite (browser, email & usenet client), Firefox browser, Thunderbird E-mail client

Off By One
The world's smallest and fastest web browser

Pegasus Mail
E-Mail client

Popcorn E-Mail
E-Mail client

Xnews
Usenet client
Anti-Adware/Spyware:

Ad-Aware SE
On-demand scanner

Spybot - Search and Destroy
Offers on-demand scanning and full-time protection
Firewall:

Tiny Personal Firewall 2
(Last freeware version)

ZoneAlarm Free Download
Technical Help:

CastleCops Security Forums

Cyber Tech Help Support Forum

SpywareWarrior.com Forum

VirtualDr Forums

How To Ask Questions The Smart Way
This guide will teach you how to ask questions in a way that is likely to get you a satisfactory answer.
How-to and Tutorial:

PCWorld: How to Install a Firewall

Using Ad-Aware SE

Using Spybot - Search and Destroy
Useful sites, articles, etc.:

Firewall Test, Security Test and Security Scan

Leak Test
Test your firewall against internal extrusions (leaks)

Shields Up
Firewall Test

Spyware/Adware/Malware FAQ and Removal Guide

SpwyareWarrior.com
Waging the war against spyware

U.S. Computer Emergency Readiness Team

Miscellaneous:

Netscape Browser Archive

OldVersion.com
Because newer is not always better

Ping Plotter
Internet diagnostic tool

TinyApps.Org

WinPatrol
Combats adware, spyware, trojans, etc.

23 posted on 04/28/2006 1:14:15 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Andonius_99

It's good, and very comprehensive.

Internet monitor, MS Office and Outlook file monitor, it even monitors your system file for trojans and it also has an on-demand scanner.

First day of installing it, it caught things that my two next-best pieces of anti-virus software, Spybot S&D and Ad-Aware, didn't catch.


24 posted on 04/28/2006 1:16:48 PM PDT by John Williams ( "Che Guevara -- Gives new meaning to the term 'Banana Republic'")
[ Post Reply | Private Reply | To 22 | View Replies]

To: Richard Kimball

"Boy, will you be sorry when I'm making big money helping a Nigerian prince get his inheritance into the country from the comfort of my refinanced home while sporting a bigger penis.

"

I have to tell ya' that I'm not particularly interested in your penis, bigger or not. It's just not my thing. As for the Nigerian prince, I have some bad news for you. He's already in touch with me, and the check is coming soon. He expresses his regret that he will not be able to complete the arrangements with you.


25 posted on 04/28/2006 1:19:45 PM PDT by MineralMan (non-evangelical atheist)
[ Post Reply | Private Reply | To 11 | View Replies]

To: holymoly

bump


26 posted on 04/28/2006 1:26:11 PM PDT by jonno
[ Post Reply | Private Reply | To 23 | View Replies]

To: holymoly

bump.


27 posted on 04/28/2006 1:27:27 PM PDT by WakeUpAndVote (Member of the Vast Right Wing Conspiracy since 1992!)
[ Post Reply | Private Reply | To 23 | View Replies]

To: MadIvan

I back up all my files weekly. If this were to get past my virus scans, spybots, and firewalls. Then I would fdisk my system and rebuild it making sure to scan the backups with the latests definitions I could find.


28 posted on 04/28/2006 1:29:06 PM PDT by TXBSAFH (Proud Dad of Twins, What Does Not Kill You Makes You Stronger!!!!!!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: holymoly; All
I need to update that list.

Here's a few more useful items:

Opera Free browser (tabbed browing, etc.)

Javacoolsoftware.com
Home of Spywareblaster and Spywareguard (Both excellent, and both FREE).

29 posted on 04/28/2006 1:34:31 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 23 | View Replies]

To: MadIvan

"Use Linux.

I've not had a single problem with this laptop since I made the switch.

Regards, Ivan"

Good for you, Ivan! Which distro are you running and how long have you been running it?

I just made the switch to PCLOS v0.92 about 6 weeks ago. I absolutely love it and I'm really having fun learning Linux.


30 posted on 04/28/2006 1:36:29 PM PDT by Shadow Deamon
[ Post Reply | Private Reply | To 10 | View Replies]

To: holymoly

That's an impressive list. I'd add Kerio as a firewall. I use it. Very light on resources. Excellent!


31 posted on 04/28/2006 1:54:01 PM PDT by upchuck (Wikipedia.com - the most unbelievable web site in the world.)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Shadow Deamon
FYI, my son runs PCLOS v0.92 with absolutely no problems (he's 14). I run Fedora Core 5, same deal. As to the comment that no one targets Linux because so few people use it, exactly how is that supposed to be a bad thing? (Even if it were true.)

As Ivan said, use Linux. Problem solved.

32 posted on 04/28/2006 2:26:17 PM PDT by Doug Loss
[ Post Reply | Private Reply | To 30 | View Replies]

To: upchuck
I'd add Kerio as a firewall.

Done.

For those interested, they can find the last freeware version here (third item on the page):
Kerio Personal Firewall 2.1.5

33 posted on 04/28/2006 2:37:07 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 31 | View Replies]

To: Former Fetus
this doesn't happen to be named after my ex-wife does it?
34 posted on 04/28/2006 2:40:29 PM PDT by kinoxi
[ Post Reply | Private Reply | To 1 | View Replies]

To: A CA Guy
Because so few use that software that even hackers don't want to bother with it.

Checking Linux firewall logs reveals all the probing being done by the trojaned windows zombies.

35 posted on 04/28/2006 2:43:54 PM PDT by Stentor
[ Post Reply | Private Reply | To 15 | View Replies]

To: holymoly

thanks for the listings!


36 posted on 04/28/2006 2:47:28 PM PDT by VOA
[ Post Reply | Private Reply | To 23 | View Replies]

To: Former Fetus
and then asks for a ransom paid through the Western Union Holdings money transfer service.

Unless Western Union Holdings employees are complicit in the crime, I refuse to believe that this is possible...

37 posted on 04/28/2006 2:52:31 PM PDT by Publius6961 (Multiculturalism is the white flag of a dying country)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Flavius Josephus

Pirated Software.


38 posted on 04/28/2006 2:55:23 PM PDT by rattrap
[ Post Reply | Private Reply | To 9 | View Replies]

To: Former Fetus
Once run, the Trojan freezes the computer, displaying a message saying files are being deleted every 30 minutes. It then gives instructions on how to send $10.99 via Western Union to free the computer.

That's when you unplug the computer and reboot on a knoppix CD and blasst the old operating system away.

Anyone with a brain is also using a second physical disk that can be removed until you have a good OS running.

39 posted on 04/28/2006 2:56:03 PM PDT by Centurion2000 (Every man must be tempted, sometimes,to hoist the black flag, and begin slitting throats.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Publius6961

They should call it the "Undocumented Immigrant Worker Virus". Breaks in past my firewall border, uninvited, then demands things while wreaking destruction. Maybe Monday it will take a day off! :)~


40 posted on 04/28/2006 2:56:22 PM PDT by LittleBillyInfidel ("Hello Mullah. Hello Fatwa. Little Billy. Not Sinatra." (Extreme Apologies to Mr. K and Mr. Sherman))
[ Post Reply | Private Reply | To 37 | View Replies]

To: holymoly
Opera Free browser (tabbed browing, etc.)

Add Slimbrowser to it as well. SlimBrowser

It works REALLY well and is only a 4MB download.

41 posted on 04/28/2006 2:58:55 PM PDT by Centurion2000 (Every man must be tempted, sometimes,to hoist the black flag, and begin slitting throats.)
[ Post Reply | Private Reply | To 29 | View Replies]

To: Names Ash Housewares
I bought a 160 Gb Western Digital external HDD, USB, from Best Buy this week for $99.00. I was totally amazed. I plugged it in and I was up and running almost instantly. I did format it into 4 partitions, which was totally easy to do, however it took several hours to complete running in the background.
42 posted on 04/28/2006 3:29:44 PM PDT by joem15 (If less is more, then what is plenty?)
[ Post Reply | Private Reply | To 7 | View Replies]

To: holymoly
Thanks for adding Kerio.

The 2.1.5 version is very stable. Never had any trouble with it.

And, unlike the Win XP SP2 firewall, Kerio protects against outgoing packets.

43 posted on 04/28/2006 3:32:58 PM PDT by upchuck (Wikipedia.com - the most unbelievable web site in the world.)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Doug Loss

"FYI, my son runs PCLOS v0.92 with absolutely no problems (he's 14). I run Fedora Core 5, same deal. As to the comment that no one targets Linux because so few people use it, exactly how is that supposed to be a bad thing? (Even if it were true.)"

That's cool, and I agree, I don't see it as a bad thing whatever reason hackers aren't targeting the OS. I'm still on a bit of a learning curve, but I'm loving the power of Linux.


44 posted on 04/28/2006 4:33:05 PM PDT by Shadow Deamon
[ Post Reply | Private Reply | To 32 | View Replies]

To: holymoly

Thanks

That will be helpful since I wanted to unload Norton from an older PC I have.


45 posted on 04/28/2006 4:36:38 PM PDT by freedumb2003 (Don't call them "Illegal Aliens." Call them what they are: CRIMINAL INVADERS!)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Centurion2000
Add Slimbrowser to it as well. SlimBrowser

It's hard to tell from their site, but SlimBrowser appears to use the IE engine, and so would suffer from the same vulnerabilities.

I.E.: System Requirements: Win95+IE4 is the minimum requirement. Win98+IE5 is recommended.

46 posted on 04/28/2006 5:14:04 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 41 | View Replies]

To: Former Fetus
If the method of unlocking the computer doesn't work after the money is sent, the virus writer promises to research the problem and includes an e-mail address.

You have to admire a feller who stands behind his product.

47 posted on 04/28/2006 5:17:39 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies]

To: VOA

You're welcome.


48 posted on 04/28/2006 5:31:29 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 36 | View Replies]

To: Former Fetus

What an interesting headline.


49 posted on 04/28/2006 5:32:13 PM PDT by SuzyQue
[ Post Reply | Private Reply | To 1 | View Replies]

To: freedumb2003
That will be helpful since I wanted to unload Norton from an older PC I have.

There's one other free anti-virus I don't have on the list:

avast! Home Edition

I haven't added to the list because, although it's free, it requires registration, which must be renewed every 14 months.

However, it does seem to be easy on resources, and might be an acceptable full-time AV for people running older systems, and/or who cannot run AVG (which some people report doesn't like Win9x).

50 posted on 04/28/2006 5:36:02 PM PDT by holymoly (Dick DeVos for MI Governor: http://www.devosforgovernor.com/)
[ Post Reply | Private Reply | To 45 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-55 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson