Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 14th, 2010, 17:07 GMT · By

Obscene Ukrainian Ransomware in the Wild

SHARE:

Adjust text size:


Ukrainian ransomware asks for 30 Grivna to unlock computers
Enlarge picture
A new piece of ransomware is currently circulating in the wild and prevents victims from properly using their computers. The malicious program also displays obscene messages in an attempt to force users to recharge a mobile phone account.

Ransomware is a term used to refer to computer trojans which disable critical system functionality and ask for a ransom in order to restore it. The crimeware model is seen by many security experts as the next step in the evolution of scareware, programs which scare users into paying unnecessary license fees.

“In this case, the Trojan (which we and several other AV companies call Trojan-Ransom-Krotten) thoroughly locks down the infected system then demands payment—in the form of credit paid to the Ukrainian mobile phone provider Kyivstar, which the victim then has to transfer to the malware distributor’s account,” explains Andrew Brandt, a security researcher at security vendor Webroot, who analyzed the malicious program.

According to the malware analyst the trojan installer is called chatadmin.exe and was created with Sign 0f Misery (S0M), a tool for people who lack the programming skills necessary to create applications. Once executed on the system, the installer performs several checks, drops the payload and forces a reboot.

The system is locked down by modifying around fourty registry entries, which are normally intended for system administrators. The affect the users' ability to run most applications, open many files type, close opened windows or access the Start menu. The trojan also replaces the time in the system tray with a Russian curse word and adds an obscene message to the Internet Explorer title bar.

Every time an infected computer reboots the user is prompted with instructions to send a mobile credit recharge code for 30 Grivna (close to $4) to an email address. The message claims that people who comply with the request will receive a program that can be used to release their computer.

In order to protect themselves against this threat users should run an up-to-date and capable antivirus product. According to the Webroot researcher, the trojan installer will halt the infection process and quit if a file called 290564175.txt is located in the root of the C: drive.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,239 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


More Fake AVs Adopt the Ransomware Model

Russian SMS Ransomware Packed with New Features

Ransomware Attacks Browsers

Ransomware Becoming the Next Step in Scareware Evolution

Brazilian Ransomware Blocks Access to Documents

READER COMMENTS:


Comment #1 by: Hi on 04 Sep 2011, 01:08 UTC reply to this comment

Just create a file with notepad and name it 290564175.txt on the root of C: and just fill it with a space to protect yourself.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM