New kidnapper malware asks for $300 ransom

Softarea51.com is your source for all the latest computer technology and software related press releases.
Browse our archive for more press releases!

Released on: 16, August 2007
, Author: MicroWorld Technologies Inc.
, Audience: Internet related

Recommended: System Errors? Click here to Fix your PC »


The malware comes into computers through Internet downloads andas a part of dubious programs and utilities. Named as 'GPcode.ai', the Malwareraises the current user rights to a higher level in order to modify files and tomake changes in the Windows registry. GPcode.ai also injects itself into alegitimate Windows process to remain in the memory and avoid detection.

The ransomware then searches for more than 200 file types and encrypts them all! Italso tries to send the stolen data to the remote attacker. What the victim of theattack is left with is hordes of garbage files, and a text file that reads asfollows:

Hello, your files are encrypted with RSA-4096 algorithm(http://en.wikipedia .org/wiki/RSA).

You will need at least few years to decrypt these files without our software. All your private information for last 3 months were collected and sent to us.

To decrypt your files you need to buy our software. The price is $300.To buy our software please contact us at ------------- and provide us your personal code ----------- . After successful purchase we will send your decrypting tool, and your private information will be deleted from our system.

"The claim about RSA-4096 is a bogus one as the encryption is done with a muchsimpler technology," points out Vikas Vishwasrao, Assistant Manager - R&D,MicroWorld Technologies. "But the false claim and the link to the RSA page onWikipedia is clever Social Engineering, to make you part with your money at theearliest. Like most malware gangs today, the one behind this too is looking for somequick dollars".

Though a few cases of ransomware infections were reported last year, this is thefirst such significant incident in 2007. MayArchive.a was one such malware whichdirected users to buy pharmaceuticals worth $75 from a Russian website at virtualgunpoint. Another one named GpCode.af used an actual RSA algorithm for encryptingfiles.

Security experts are keeping a close watch on this tribe of malware. CEO ofMicroWorld, Govind Rammurthy, says: "While one branch of malware programs is movingtowards stealthier varieties and camouflaged techniques, this offshoot is a ratherbrazen variety which shows that cyber criminals can go to any levels in stealingyour money. Surely, it also points to the need of backing up your data regularly andprotecting your computer with a proactive, real-time Antivirus solution".

MicroWorld

MicroWorld Technologies is the developer of the world's most advanced AntiVirus,Content Security and Firewall software eScan, MailScan, and eConceal. MicroWorldWinsock Layer (MWL) is the revolutionary technology that powers most of MicroWorldproducts enabling them to achieve several certifications and awards by some of themost prestigious testing bodies, notable among them being Virus Bulletin, Checkmark,TUCOWS, Red Hat Ready and Novell Ready.

To learn more, kindly visit http://www.mwti.net.

FromMicroWorld


Source: Express-Press-Release.com
Related downloads


Prevx CSI - FREE Malware Scanner – fast, effective scanning and real-time checking against the most comprehensive malware database in the world. Prevx CSI is click-and-go and requires no installation or reboot, which makes it quick and easy to use.

MoSo Anti-Malware 2008 is an advanced but easy-to-use anti malware tool that removes spyware,adware,trojan,virus,worm,now we can remove and block over 730000 known malwares and internet threats, before them get on to your computer.

Now your favorite polar bear is even more animated - sometimes when music is too cool (this version has music!) he starts to dance and this is fantastic. When the beer is over the bear asks you to buy more. Will you refuse such nice creation?

Malwarebytes' Anti-Malware removes and protects you from malware.

Malware Defender is a HIPS (Host Intrusion Prevention System) with firewall. It is also an advanced rootkit detector.

Protect your PC against Spyware, Malware and other unwanted software. SPYWAREfighter is a user-friendly anti spyware program that is easy to install and use. SPYWAREfighter is your protection against spyware, adware and other unwanted software.

Spyware24x7 provide around the clock protection from spyware, adware and malware. Powered by Lavasoft's antispyware software solution, Spyware 24x7 Pro offers advanced real-time protection while protecting your computer and your indentity.

Metascan is an application with a programming interface that enables IT professionals and software engineers to integrate multiple anti-malware scanning technologies into their proprietary solutions.

Protect your PC against viruses, worms, Trojans, and other Internet threats. With real-time protection and hourly updates, iolo AntiVirus blocks malware, removes malicious code, shields your files from theft and damage, and guards your privacy.

Zemana AntiLogger has a new,powerful way to protect your PC from malware attacks.We don't rely on virus signature updates like the traditional antivirus programs do. Our unique technology detects when malware runs on your computer,and we shut it down
Softarea51.com RSS Feed

Get RSS updates on latest computer technology and software related press releases Subscribe to Latest Press Releases RSS feed    Subscribe



You are welcome to include these headlines in your own pages. If you want to find out how to parse this RSS file please read our tutorial How to parse RSS feeds with PHP.