NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Ransomware Becoming the Next Step in Scareware Evolution

Revamped fake antivirus variant holds systems for ransom

By Lucian Constantin, Web News Editor

13th of May 2009, 12:27 GMT

Adjust text size:


Ransomware is becoming a dangerous trend
Enlarge picture
Security researchers from antivirus vendor McAfee are warning that an older scareware application has recently mutated into ransomware and is now asking for money to unblock access to legit applications on victim computers.

Looking to increase their illegal monetary gains, the creators of "System Security 2009," a fake antivirus program, which previously relied solely on scareware tactics to trick users into acquiring useless licenses, have released a new variant that now holds systems for ransom. McAfee currently detects the new variant as FakeAlert-CO.

"As most other rogue security programs to date, FakeAlert-CO displays spurious alerts and making fraudulent claims of infections that requires the user to pay a fee to 'repair.' Following the trend of Ransom-F, we noticed 'new features' in FakeAlert-COt hat resembles some common characteristics of ransomware trojans," Avelino Rico Jr. and Geok Meng Ong, the two McAfee experts who have analyzed it, explain.

Screenshot of the System Security 2009 scareware
Enlarge picture
Ransom-F refers to an application called "FileFix Pro 2009," which was being aggressively marketed to users looking to recover personal documents encrypted by the Vundo trojan specifically to sell this product. FileFix Pro 2009 was first reported back in March and has been followed just recently by the first Brazilian ransomware, called Byte Clark.

Unlike FileFix Pro 2009, Byte Clark was just blocking access, via a malicious component, to a wide variety of documents, applications and folders, instead of encrypting the files. The new System Security 2009 variant takes a similar approach, as it prevents all programs from starting and displays an error message telling the user to buy a license in order to fix the problem.

Fake System Security 2009 error
Enlarge picture
Clicking on the error message opens a professional-looking website in the browser, where the victims can select from several subscriptions before proceeding to enter their credit card details. The website even claims to be offering a 30-day-money-back guarantee, which is, obviously, false.

"Uninstalling the System Security 'product' will not be an option for the typical user, as there is neither an uininstaller [sic.] function nor will the 'Add or Remove Programs' in the control panel be allowed to be opened via the usual means," the researchers warn. However, "If the user boots into Safe Mode, FakeAlert-CO is not started automatically and system tools and applications can be executed and accessed normally," they add.

TAGS:

ransomware | System Security 2009 | fake antivirus | scareware distribution | McAfee
Read by 1,093 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.0/5) 3 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Brazilian Ransomware Blocks Access to Documents

Interesting Anti-Emulation Programming Trick in Fake AVs

Scareware Turns Ransomware

Malware Distribution Service Gets Autorun Upgrade

Government Websites and Microsoft Help Push Scareware

Scareware Advertisers Close to Being Arrested

Google Ads Spread Scareware

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM