| Windows 7: Copyright violation alert ransomware in the wild |
15 Apr 2010
|
#1 | | Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case New England |
Copyright violation alert ransomware in the wild Quote: April 12th, 2010
Copyright violation alert ransomware in the wild
Posted by Dancho Danchev @ 7:02 am
A currently ongoing ransomware campaign is using a novel approach to extort money from end users whose PCs have been locked down.
By pretending to be the fake ICPP Foundation ( icpp-online.com), the ransomware locks down the user’s desktop issuing a “ Copyright violation: copyrighted content detected” message, which lists torrent files found on the infected PC, and forces the user to pay $400 for the copyright holder’s fine, emphasizing on the fact that “the maximum penalties can be five years in prison and up to $250,000 in fines.
More details on the campaign:
Upon execution the ransomware will change the Desktop’s wallpaper to the “Warning! Piracy detected!” background. More at: Copyright violation alert ransomware in the wild | Zero Day | ZDNet.com | My System Specs |
| OS Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case CPU AMD Phenom II X4 975 Deneb 3.6ghz - 965 on new mini tower Motherboard Gigabyte GA-790XTA-UD4 Memory Kingston Hyper X DDR3 1600 1.5v 16gb - Mushkin on 2nd build Graphics Card MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower Sound Card Creative Labs X-Fi XtremeGamer - Realtek onooard 2nd case Monitor(s) Displays 2 x Acer P191W 19" widesscreen - HP 20" widescreen mini towe Screen Resolution 1440x900 native - 1600x1024 on 7 Pro x64 build Keyboard Microsoft Recusa Razor - MS Comfort 3000 on second build Mouse MS Trackball Explorer - A4TECH dual scroll wheel trackball PSU Corsair 750TX - primary / Corsair CX600 - second Case Antec 900-2 - SSD compatible / NZXT Vulcan mini tower Cooling Zalman CNPS9900A Hard Drives Primary Ultimate x64 build-
WD Black Edition 1tb Sata 6.0 = 2
WD Black Edition 1tb Sata 3.0 = 2 (OS drives)
WD 1tb Green Power sata = 2 1 external
usb flash drives = 18
Second 7 Pro x64 mini tower-
WD Caviar SE 500gb sata II single drive presen Internet Speed 30mbps upgrade - primary hard wired - mini tower usb WiFi |
15 Apr 2010
|
#2 | | Windows 7 Professional SP1 - x64 Lost In Space, Vol 9 - Chasing |
You"ll have to be dumb to pay that amount...right away.
I guess manies are knowing it is barely impossible such thing happens to force you to pay before any policemen investigations break your front door!
"Money, always that damn money!" | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number [June 2013] - Full Tower OS Windows 7 Professional SP1 - x64 CPU Ivy Bridge Core i5 K Motherboard Asus H77 Chipset (ATX) Memory G.Skill DDR3 PC3-12800 (16Gb) Graphics Card Sapphire HD 7770 Vapor-X Oc Sound Card SBXi-Fi Xtreme Audio (w/5.1 sound system) Monitor(s) Displays Asus Led 21,5" Screen Resolution 16/9 Keyboard Razer + Razer gamepad Mouse Razer PSU 700w 80+ Gold (ErP Lot6 ready) Case Thermaltake Chaser A71 Cooling Gelid Solutions (PWM Push/pull Fans) Hard Drives Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s Antivirus MSE 4.2 Browser IE10 Rtm |
15 Apr 2010
|
#3 | | WinXP / Win 7 64bit Dual Boot The Villages, Florida, USA |
Scammers First clue would be that the creators of this warning message don't know how to spell. Incorrect spelling is a pretty good clue to a scam.
Receive and Received is misspelled.
my .02 worth | My System Specs | | System Manufacturer/Model Number DYI Water Cooled OS WinXP / Win 7 64bit Dual Boot CPU Q6600 Motherboard Asus P5K Deluxe WIFI/AP Edition Memory 4 Gb Crucial Ballistix Tracer Graphics Card EVGA e-GeForce 8800 GT 512MB Sound Card On Board Soundmax HD Monitor(s) Displays Dell 19" Flat Panel Screen Resolution 1280x1024 Keyboard Microsoft Wireless Mouse Microsoft Wireless PSU Thermaltake Toughpower 750 Case Thermaltake Black Armor Cooling Water Hard Drives WD1001 Caviar Win 7 Boot
WD500 Caviar Win XP Boot
2xWD500 Caviar (Raid 0)
WD750 Caviar (Backup) Internet Speed Cable Other Info LiteOn Lightscribe DVD Burner |
15 Apr 2010
|
#4 | | Windows 7 Pro 64 SP1 East Bay Area, CA |

Quote: Originally Posted by hoganth First clue would be that the creators of this warning message don't know how to spell. Incorrect spelling is a pretty good clue to a scam.
Receive and Received is misspelled.
my .02 worth  Good eye hoganth, Good point too.
I certainly wouldn't give up any money that easy either. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Compaq sr5410f case OS Windows 7 Pro 64 SP1 CPU AMD X2 4450E @ 2.3 ghz Motherboard Biostar MCP6P M2+ Memory 4.0 g Graphics Card Nvidia GeForce 9600 GT , 512mb Sound Card onboard Monitor(s) Displays auria eq2367 Screen Resolution 1920 x 1080 Keyboard logitech wave cordless Mouse logitech LX8 cordless laser mouse PSU 250 watts Case Compaq Cooling couple fans Hard Drives 1 tb Hitachi HDT721010SLA scsi, 500 gb external Internet Speed comcast hi speed 19 dn 8 up Antivirus Microsoft Security Essentials Browser IE10 Other Info Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Microsoft Windows 7 Professional 64-bit 7601 Multiprocessor Free Service Pack 1 |
15 Apr 2010
|
#5 | | Windows 7 Home Premium 64-bit |
makes note to ban my kid off computer... | My System Specs | | System Manufacturer/Model Number Toshiba Satellite OS Windows 7 Home Premium 64-bit CPU Pentium(R) Dual-Core T4300 @ 2.10GHz Motherboard Toshiba Model KSWAA - Chipset Intel GL40 Rev 07 Memory 3 GB DDR2 PC2-6400 (400 MHz) Samsung M4 70T2864Q23-CF7 Graphics Card Mobile Intel GMA4500M 32bit OS (64bit OS) dynamically Sound Card Realtek ALC272-GR Software Sound Monitor(s) Displays 16.0" HD TFT with TrueBrite Matrix colour LCD display Screen Resolution 1366 x 768 Keyboard Canadian Bilingual Keyboard 105 keys with 13 Function keys Mouse Touchpad Point device & Lexma USB Mouse Hard Drives FUJITSU MJA2320BH G2-(S2) 320GB (5400RPM) Serial-ATA Internet Speed Walking is Faster Other Info Wireless LAN Realtek RTL89191SE 802.11n PCI-E NIC + a
LAN Realek PCIe FE Family Controller and
TOSHIBA Software Modem |
16 Apr 2010
|
#6 | | Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case New England |
A friend just asked for help when some bogus av program locked him out of the desktop and actually created a new admin account on the older XP build. I;ve tried getting him to watch the things he clicks on to no avail. A separate system rescue program had to downloaded to a flash drive and copied onto the infected system with that booted in safe mode just to copy the file over to the main drive.
The bogus av claimed all things were infected and he had to buy the full version of ... what? No trial was on and no program in the add/remove either. Fortunately he was able to get the rescue program running when rebooting with a normal startup and saw the I-Worm type hoax removed! The new admin account vanished as well once the bug was off.
All this shows people have to stay onguard for all types of gimics to infect pcs or scam people out of their incomes! The opportunists lurk in the shadows or under false guises to beware of! | My System Specs | | OS Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case CPU AMD Phenom II X4 975 Deneb 3.6ghz - 965 on new mini tower Motherboard Gigabyte GA-790XTA-UD4 Memory Kingston Hyper X DDR3 1600 1.5v 16gb - Mushkin on 2nd build Graphics Card MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower Sound Card Creative Labs X-Fi XtremeGamer - Realtek onooard 2nd case Monitor(s) Displays 2 x Acer P191W 19" widesscreen - HP 20" widescreen mini towe Screen Resolution 1440x900 native - 1600x1024 on 7 Pro x64 build Keyboard Microsoft Recusa Razor - MS Comfort 3000 on second build Mouse MS Trackball Explorer - A4TECH dual scroll wheel trackball PSU Corsair 750TX - primary / Corsair CX600 - second Case Antec 900-2 - SSD compatible / NZXT Vulcan mini tower Cooling Zalman CNPS9900A Hard Drives Primary Ultimate x64 build-
WD Black Edition 1tb Sata 6.0 = 2
WD Black Edition 1tb Sata 3.0 = 2 (OS drives)
WD 1tb Green Power sata = 2 1 external
usb flash drives = 18
Second 7 Pro x64 mini tower-
WD Caviar SE 500gb sata II single drive presen Internet Speed 30mbps upgrade - primary hard wired - mini tower usb WiFi |
16 Apr 2010
|
#7 | | Windows 7 Ultimate 32 bit Orlando, Florida |
I hope he learned from this. | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 Ultimate 32 bit CPU Intel(R) Pentium(R) 4 CPU 3.00GHz Motherboard ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5 Memory 2.50 GB RAM Graphics Card NVIDIA GeForce 7600 GS Sound Card SoundMax Integrated Digital Audio (Chip) Monitor(s) Displays ViewSonic VX 1962 wm Screen Resolution 1680 X 1050 Keyboard Microsoft Comfort Curve Keyboard 2000 v10 USB Mouse Logitec optic USB Cooling Fan based Hard Drives Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB Internet Speed 3.01 Mb/s download 0.64 Mb/s upload |
16 Apr 2010
|
#8 | | Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case New England |
Maybe? Most likely not however! At first a drive wipe was being pondered due to the volume of bugs thought to be on the 4yr. old installation. Surprizingly the rescue program cleaned not only the bogus av program but numerous other adbots and whatever as it ran.
A few years back if I recall there was some bogus virus alert that claimed your hard drive would be ruined if it got on making the drive useless. Obviously another form of scam being seen then to get people to buy some software! This is why you always double check any offers and look for a main home site before even pressing any upgrade to buy option to avoid being taken in! | My System Specs | | OS Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case CPU AMD Phenom II X4 975 Deneb 3.6ghz - 965 on new mini tower Motherboard Gigabyte GA-790XTA-UD4 Memory Kingston Hyper X DDR3 1600 1.5v 16gb - Mushkin on 2nd build Graphics Card MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower Sound Card Creative Labs X-Fi XtremeGamer - Realtek onooard 2nd case Monitor(s) Displays 2 x Acer P191W 19" widesscreen - HP 20" widescreen mini towe Screen Resolution 1440x900 native - 1600x1024 on 7 Pro x64 build Keyboard Microsoft Recusa Razor - MS Comfort 3000 on second build Mouse MS Trackball Explorer - A4TECH dual scroll wheel trackball PSU Corsair 750TX - primary / Corsair CX600 - second Case Antec 900-2 - SSD compatible / NZXT Vulcan mini tower Cooling Zalman CNPS9900A Hard Drives Primary Ultimate x64 build-
WD Black Edition 1tb Sata 6.0 = 2
WD Black Edition 1tb Sata 3.0 = 2 (OS drives)
WD 1tb Green Power sata = 2 1 external
usb flash drives = 18
Second 7 Pro x64 mini tower-
WD Caviar SE 500gb sata II single drive presen Internet Speed 30mbps upgrade - primary hard wired - mini tower usb WiFi |
16 Apr 2010
|
#9 | | Windows 7 Professional SP1 - x64 Lost In Space, Vol 9 - Chasing |

Quote: Originally Posted by Night Hawk A friend just asked for help when some bogus av program locked him out of the desktop and actually created a new admin account on the older XP build. I;ve tried getting him to watch the things he clicks on to no avail. A separate system rescue program had to downloaded to a flash drive and copied onto the infected system with that booted in safe mode just to copy the file over to the main drive.
The bogus av claimed all things were infected and he had to buy the full version of ... what? No trial was on and no program in the add/remove either. Fortunately he was able to get the rescue program running when rebooting with a normal startup and saw the I-Worm type hoax removed! The new admin account vanished as well once the bug was off.
All this shows people have to stay onguard for all types of gimics to infect pcs or scam people out of their incomes! The opportunists lurk in the shadows or under false guises to beware of! He he he...that's is not a new one from hoax...it happens once to me back in the early XP and i had hard time as the seller repair shop had too...he had to change me the infected machine after six month to a new one. It has cost them a fortune during all the warranty time and luckily they couldn't blame me as i had paid the Norton Software pre-installed for the year warranty. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number [June 2013] - Full Tower OS Windows 7 Professional SP1 - x64 CPU Ivy Bridge Core i5 K Motherboard Asus H77 Chipset (ATX) Memory G.Skill DDR3 PC3-12800 (16Gb) Graphics Card Sapphire HD 7770 Vapor-X Oc Sound Card SBXi-Fi Xtreme Audio (w/5.1 sound system) Monitor(s) Displays Asus Led 21,5" Screen Resolution 16/9 Keyboard Razer + Razer gamepad Mouse Razer PSU 700w 80+ Gold (ErP Lot6 ready) Case Thermaltake Chaser A71 Cooling Gelid Solutions (PWM Push/pull Fans) Hard Drives Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s Antivirus MSE 4.2 Browser IE10 Rtm |
16 Apr 2010
|
#10 | | Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case New England |
When you looked at the name of the phony program it was newer then the PCVirus2009 hoax now being called System Protect trying trick people by borrowing the name of an actuall freeware program by the same name. Only the real program is seen in the Control Panel and offers the uninstall option as well.
Wait a few more months and some other name will appear!  This is why playing it smart by first looking anything new first to get the facts before installing it can save you a world of hurt later! | My System Specs | | OS Windows 7 Ultimate x64, XP Mode, W8 RP VM, Linux Mint Debian 2nd OS HD- 7 Pro x64 second case CPU AMD Phenom II X4 975 Deneb 3.6ghz - 965 on new mini tower Motherboard Gigabyte GA-790XTA-UD4 Memory Kingston Hyper X DDR3 1600 1.5v 16gb - Mushkin on 2nd build Graphics Card MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower Sound Card Creative Labs X-Fi XtremeGamer - Realtek onooard 2nd case Monitor(s) Displays 2 x Acer P191W 19" widesscreen - HP 20" widescreen mini towe Screen Resolution 1440x900 native - 1600x1024 on 7 Pro x64 build Keyboard Microsoft Recusa Razor - MS Comfort 3000 on second build Mouse MS Trackball Explorer - A4TECH dual scroll wheel trackball PSU Corsair 750TX - primary / Corsair CX600 - second Case Antec 900-2 - SSD compatible / NZXT Vulcan mini tower Cooling Zalman CNPS9900A Hard Drives Primary Ultimate x64 build-
WD Black Edition 1tb Sata 6.0 = 2
WD Black Edition 1tb Sata 3.0 = 2 (OS drives)
WD 1tb Green Power sata = 2 1 external
usb flash drives = 18
Second 7 Pro x64 mini tower-
WD Caviar SE 500gb sata II single drive presen Internet Speed 30mbps upgrade - primary hard wired - mini tower usb WiFi Copyright violation alert ransomware in the wild problems? All times are GMT -5. The time now is 08:41 PM. | |