Ransomware squeezes users with bogus Windows activation demand

Tuesday, April 12th, 2011

A new Trojan tries to extort money from users by convincing them to dial international telephone numbers to reactive Windows, a security researcher said today. Once on a PC, the malware displays a message claiming that Windows is "locked" and must be reactivated, said Mikko Hypponen, the chief research officer of ...

Ransomware Attack Resurfaces to Hold Files Hostage

Tuesday, November 30th, 2010

Malware is all about money. Spyware stealthily captures keystrokes and sensitive data to compromise accounts. Phishing attacks lure users into unwittingly surrendering account credentials and other crucial information. Ransomware uses a much less subtle tactic of demanding the money directly in exchange for the safe return of your own data. The ...

Trojan demands money for internet access

Tuesday, December 1st, 2009

There's nothing new about Windows trojans resorting to a little blackmail, but Computer Associates has now observed a new twist; a trojan which blocks internet access until the user enters an activation code. This is activation code is obtained by sending an SMS containing a particular number to an expensive ...

New Gpcode (encryption) ransomware speading via botnet

Wednesday, August 13th, 2008

There are confirmed reports on a new version of the Gpcode ransomware being spread via a botnet.According to Vitaly Kamluk of Kaspersky Lab (my employer), the Trojan encrypts files on an infected machine (AES-256) and leaves a text file named crypted.txt with a ransom note demanding $10 to decrypt the ...

Recovering from the Encryption Virus

Tuesday, June 17th, 2008

Kaspersky Lab has published advice on recovering files encrypted by the frightening Gpcode.ak virus, but there is a big catch -- users must not have turned off their PC first. A new variant of the malware struck last week, scrambling a variety of files on victims' PCs using a very strong ...