<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spyware Remover Help &#187; ransomware</title>
	<atom:link href="http://spyware-remover-help.com/tag/ransomware/feed/" rel="self" type="application/rss+xml" />
	<link>http://spyware-remover-help.com</link>
	<description>Spyware removal ebook Free download</description>
	<lastBuildDate>Wed, 01 Feb 2012 16:00:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>The Rise of the Ransomware</title>
		<link>http://spyware-remover-help.com/2012/01/19/the-rise-of-the-ransomware/</link>
		<comments>http://spyware-remover-help.com/2012/01/19/the-rise-of-the-ransomware/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 04:00:22 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://spyware-remover-help.com/?p=2801</guid>
		<description><![CDATA[In the last months we have seen an increase of ransomware attacks. While the first ones we saw were posing as Microsoft to threaten the user because it had been detected a pirated version of Windows, and in case you didn&#8217;t pay the fine they would contact the local law enforcement agencies, the new ones [...]]]></description>
			<content:encoded><![CDATA[<p>In the last months we have seen an increase of ransomware attacks. While the first ones we saw were posing as Microsoft to threaten the user because it had been detected a pirated version of Windows, and in case you didn&#8217;t pay the fine they would contact the local law enforcement agencies, the new ones [...]&#8212;<br  /><a href="http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/" target="_blank">read the article <br  /></a></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2012/01/19/the-rise-of-the-ransomware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ransomware posing as Microsoft</title>
		<link>http://spyware-remover-help.com/2011/09/16/ransomware-posing-as-microsoft-2/</link>
		<comments>http://spyware-remover-help.com/2011/09/16/ransomware-posing-as-microsoft-2/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 11:00:04 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://spyware-remover-help.com/2011/09/16/ransomware-posing-as-microsoft-2/</guid>
		<description><![CDATA[We&#8217;ve found yet another malware piece, this time it is a ransomware to take some of your money. Once you get infected (you can receive it in a number of different ways, most likely via spam messages and P2P), your computer is restarted. What for? Well, the malware installs itself to run every time your [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve found yet another malware piece, this time it is a ransomware to take some of your money. Once you get infected (you can receive it in a number of different ways, most likely via spam messages and P2P), your computer is restarted. What for? Well, the malware installs itself to run every time your [...]&#8212;<br  /><a href="http://pandalabs.pandasecurity.com/ransomware-posing-as-microsoft/" target="_blank">read the article <br  /></a></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2011/09/16/ransomware-posing-as-microsoft-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ransomware posing as Microsoft</title>
		<link>http://spyware-remover-help.com/2011/09/07/ransomware-posing-as-microsoft/</link>
		<comments>http://spyware-remover-help.com/2011/09/07/ransomware-posing-as-microsoft/#comments</comments>
		<pubDate>Wed, 07 Sep 2011 11:00:05 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://spyware-remover-help.com/2011/09/07/ransomware-posing-as-microsoft/</guid>
		<description><![CDATA[We&#8217;ve found yet another malware piece, this time it is a ransomware to take some of your money. Once you get infected (you can receive it in a number of different ways, most likely via spam messages and P2P), your computer is restarted. What for? Well, the malware installs itself to run every time your [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve found yet another malware piece, this time it is a ransomware to take some of your money. Once you get infected (you can receive it in a number of different ways, most likely via spam messages and P2P), your computer is restarted. What for? Well, the malware installs itself to run every time your [...]&#8212;<br  /><a href="http://pandalabs.pandasecurity.com/ransomware-posing-as-microsoft/" target="_blank">read the article <br  /></a></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2011/09/07/ransomware-posing-as-microsoft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rogueware with new Ransomware Technology™</title>
		<link>http://spyware-remover-help.com/2009/10/08/rogueware-with-new-ransomware-technology%e2%84%a2/</link>
		<comments>http://spyware-remover-help.com/2009/10/08/rogueware-with-new-ransomware-technology%e2%84%a2/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 19:00:01 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://spyware-remover-help.com/2009/10/08/rogueware-with-new-ransomware-technology%e2%84%a2/</guid>
		<description><![CDATA[The criminals behind Rogueware attacks are becoming increasingly aggressive in their approach to make money. We recently stumbled across a sample (Adware/TotalSecurity2009) which uses a ransomware technique to improve its sales. Once the computer becomes infected, Total Security forces the victim to purchase it before it will allow any files from being accessed on the [...]]]></description>
			<content:encoded><![CDATA[<p>The criminals behind Rogueware attacks are becoming increasingly aggressive in their approach to make money.  We recently stumbled across a sample (Adware/TotalSecurity2009) which uses a ransomware technique to improve its sales. Once the computer becomes infected, Total Security forces the victim to purchase it before it will allow any files from being accessed  on the system.  When attempting to open a file, a message pops up in the notification area claiming that the application was blocked due to infection.  The pop up recommends activating the &quot;antivirus&quot; software, which costs $79.95.     This would be a devistating blow to any user and would likely force the victim to purchase it, so we went ahead and cracked the sample to reveal all of the valid serial numbers.  We&#39;re hoping that  victims can find this blog post before shelling out any hard earned cash to these criminals. Watch the video to see it in action:  Valid serials for Adware/TotalSecurity2009:WNDS-TGN15-RFF29-AASDJ-ASD65  WNDS-U94KO-LF4G4-1V8S1-2CRFE  WNDS-6W954-FX65B-41VDF-8G4JI  WNDS-G84H6-S854F-79ZA8-W4ERS  WNDS-TTUYJ-7UO54-G561H-J1D6F  WNDS-A1SDF-6AS4D-RF5RE-79G84  WNDS-A1SDF-RY4E8-7U98D-F1GB2  WNDS-5SRTS-AEHUF-YA54S-D6F35  WNDS-P9685-4H41A-DSW3A-2R64T  WNDS-2AE32-1VFC2-B6894-G67YU  WNDS-4TS8R-D6F5D-4JH8T-U4JK5  WNDS-FGS5D-649RG-4S53D-412SF  WNDS-452S3-ER00F-TSE35-S8FSD  WNDS-SERFH-2642S-F04SD-64FG1  WNDS-F40SA-1ER5H-4FG5D-F8412  WNDS-5D1V2-XB0D5-JT1TY-97DS3  WNDS-4BGY2-JY4KO-IT98Y-7HJ43  WNDS-G8FB6-1V87S-DRT1S-63SRG  WNDS-HFVDR-9844O-U54DA-5TBSC  WNDS-89OF7-7324R-5SAD4-TG68U  WNDS-JUYH3-24GHJ-HGKSH-FKLSDYou can download a free trial to completely remove the infection once the ransomware feature is removed.Special thanks to Mikel Echevarria Lizarraga for extracting the serials. <br  /><a href="http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx" target="_blank">source</a></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2009/10/08/rogueware-with-new-ransomware-technology%e2%84%a2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ransomware Reloaded</title>
		<link>http://spyware-remover-help.com/2009/04/20/ransomware-reloaded/</link>
		<comments>http://spyware-remover-help.com/2009/04/20/ransomware-reloaded/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:00:01 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://spyware-remover-help.com/2009/04/20/ransomware-reloaded/</guid>
		<description><![CDATA[One of the latest examples of ransomware we have seen is Trj/SMSlock.AThe main aim of this malware is to make users pay ransom for their computer in order to have it completely operative.Until now some of the functionalities we had seen in ransomware were to encrypt certain documents or extensions of the computer or to [...]]]></description>
			<content:encoded><![CDATA[<p>One of the latest examples of ransomware we have seen is Trj/SMSlock.AThe main aim of this malware is to make users pay ransom for their computer in order to have it completely operative.Until now some of the functionalities we had seen in ransomware were to encrypt certain documents or extensions of the computer or to empty the emails of the user&rsquo;s inbox and the contact list, among others. However, in the case of Trj/SMSlock.A, it locks the access to the system (leaving the computer unusable), and it displays on the screen a message in Russian which contains the instructions so that users send an sms as a random for their system: Note: Below you have the transcription in English of the message displayed on the screen.To unlock you need to send an SMS with the text 4121800286 to the number 3649 Enter the resulting code:Any attempt to reinstall the system may lead to loss of important information and computer damage<br  /><a href="http://pandalabs.pandasecurity.com/archive/Ransomware-Reloaded.aspx" target="_blank">source</a></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2009/04/20/ransomware-reloaded/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Police &#8216;find&#8217; author of notorious Gpcode virus (InfoWorld)</title>
		<link>http://spyware-remover-help.com/2009/01/22/police-find-author-of-notorious-gpcode-virus-infoworld/</link>
		<comments>http://spyware-remover-help.com/2009/01/22/police-find-author-of-notorious-gpcode-virus-infoworld/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 19:08:19 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Spyware in the News]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ransomware]]></category>

		<guid isPermaLink="false">http://spyware-remover-help.com/2009/01/22/police-find-author-of-notorious-gpcode-virus-infoworld/</guid>
		<description><![CDATA[The infamous Gpcode &#8216;ransomware&#8217; virus that hit computers in July was the work of a single person who is known to the authorities, a source close to the hunt for the attacker has told Techworld. The individual is believed to be a Russian national, and has been in contact with at least one anti-malware company, [...]]]></description>
			<content:encoded><![CDATA[<p>The infamous Gpcode &#8216;ransomware&#8217; virus that hit computers in July was the work of a single person who is known to the authorities, a source close to the hunt for the attacker has told Techworld. The individual is believed to be a Russian national, and has been in contact with at least one anti-malware company, Kaspersky Lab, in an attempt to sell a tool that could be used to decrypt &#8230;<br  /> <br  /> <br  />  <a href="http://us.rd.yahoo.com/dailynews/rss/search/malware/SIG=14q15dfqq/*http%3A//www.infoworld.com/cgi-bin/redirect?source=rss&#038;url=http://www.infoworld.com/article/08/09/30/Police_find_author_of_notorious_Gpcode_virus_1.html">original article</a></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2009/01/22/police-find-author-of-notorious-gpcode-virus-infoworld/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new case of RansomWare !!!</title>
		<link>http://spyware-remover-help.com/2007/07/16/a-new-case-of-ransomware/</link>
		<comments>http://spyware-remover-help.com/2007/07/16/a-new-case-of-ransomware/#comments</comments>
		<pubDate>Tue, 17 Jul 2007 06:45:00 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<P>We have detected a new case of RansomWare.</P>
<P>Once the malware infects users and encrypts their files, several â€œread_me.txtâ€ files are created in the infected system, which warn users that their data files have been encrypted and that they wonâ€™t be able to access them unless they pay a ransom of $300.</P>
<P align=center><IMG src="/blogs/images/PandaLabs/2007/07/17/Sinowal1.JPG"></P>
<P>&#160;The email addresses indicated in the message may vary:</P>
<BLOCKQUOTE dir=ltr style="MARGIN-RIGHT:0px;">
<P><A href="mailto:kiloglamour@gmail.com">kiloglamour@gmail.com</A></P>
<P><A href="mailto:tristanniglam@gmail.com">tristanniglam@gmail.com</A></P>
<P><A href="mailto:oxyglamour@gmail.com">oxyglamour@gmail.com</A></P>
<P><A href="mailto:glamourepalace@gmail.com">glamourepalace@gmail.com</A></P></BLOCKQUOTE>
<P>The â€œpersonal codeâ€ may also vary depending on the random value that is used to encrypt the data.</P>
<P>The encrypted files usually begin with the text â€œGLAMOURâ€:</P>
<P align=center><IMG src="/blogs/images/PandaLabs/2007/07/17/Sinowal2.JPG"></P>
<P>We have managed to access the data of the infected systems and there are 1,108 infected computers. </P>
<P>Besides, in 111 of those machines the port 6838 is open so that the machines act as socket servers.</P>
<P>The â€œconstruction kitâ€ of Trj/Sinowal has been used to create this Trojan.</P>
<P>We have already mentioned this malware family in the eCrime 2007</P>
<P><A href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx">http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx</A></P>
<P>According to SecureWorks, this â€œconstruction kitâ€ is sold for around $1,000.</P>
<P><A href="http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&#38;NewsId=3740">http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&#38;NewsId=3740</A></P>
<P>This variant has been detected as Trj/Sinowal.FY in the signature file. </P><img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=224" width="1" height="1">]]></description>
			<content:encoded><![CDATA[<p><P>We have detected a new case of RansomWare.</P><br />
<P>Once the malware infects users and encrypts their files, several â€œread_me.txtâ€ files are created in the infected system, which warn users that their data files have been encrypted and that they wonâ€™t be able to access them unless they pay a ransom of $300.</P><br />
<P align=center><IMG src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2007/07/17/Sinowal1.JPG"></P><br />
<P>&nbsp;The email addresses indicated in the message may vary:</P><br />
<BLOCKQUOTE dir=ltr ><br />
<P><A href="mailto:kiloglamour@gmail.com">kiloglamour@gmail.com</A></P><br />
<P><A href="mailto:tristanniglam@gmail.com">tristanniglam@gmail.com</A></P><br />
<P><A href="mailto:oxyglamour@gmail.com">oxyglamour@gmail.com</A></P><br />
<P><A href="mailto:glamourepalace@gmail.com">glamourepalace@gmail.com</A></P></BLOCKQUOTE><br />
<P>The â€œpersonal codeâ€ may also vary depending on the random value that is used to encrypt the data.</P><br />
<P>The encrypted files usually begin with the text â€œGLAMOURâ€:</P><br />
<P align=center><IMG src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2007/07/17/Sinowal2.JPG"></P><br />
<P>We have managed to access the data of the infected systems and there are 1,108 infected computers. </P><br />
<P>Besides, in 111 of those machines the port 6838 is open so that the machines act as socket servers.</P><br />
<P>The â€œconstruction kitâ€ of Trj/Sinowal has been used to create this Trojan.</P><br />
<P>We have already mentioned this malware family in the eCrime 2007</P><br />
<P><A href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx">http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx</A></P><br />
<P>According to SecureWorks, this â€œconstruction kitâ€ is sold for around $1,000.</P><br />
<P><A href="http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&amp;NewsId=3740">http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&amp;NewsId=3740</A></P><br />
<P>This variant has been detected as Trj/Sinowal.FY in the signature file. </P><img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=224" width="1" height="1"></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2007/07/16/a-new-case-of-ransomware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new case of RansomWare !!!</title>
		<link>http://spyware-remover-help.com/2007/07/16/a-new-case-of-ransomware/</link>
		<comments>http://spyware-remover-help.com/2007/07/16/a-new-case-of-ransomware/#comments</comments>
		<pubDate>Tue, 17 Jul 2007 06:45:00 +0000</pubDate>
		<dc:creator>Ted</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<P>We have detected a new case of RansomWare.</P>
<P>Once the malware infects users and encrypts their files, several â€œread_me.txtâ€ files are created in the infected system, which warn users that their data files have been encrypted and that they wonâ€™t be able to access them unless they pay a ransom of $300.</P>
<P align=center><IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/17/Sinowal1.JPG"></P>
<P>&#160;The email addresses indicated in the message may vary:</P>
<BLOCKQUOTE dir=ltr style="MARGIN-RIGHT:0px;">
<P><A href="mailto:kiloglamour@gmail.com">kiloglamour@gmail.com</A></P>
<P><A href="mailto:tristanniglam@gmail.com">tristanniglam@gmail.com</A></P>
<P><A href="mailto:oxyglamour@gmail.com">oxyglamour@gmail.com</A></P>
<P><A href="mailto:glamourepalace@gmail.com">glamourepalace@gmail.com</A></P></BLOCKQUOTE>
<P>The â€œpersonal codeâ€ may also vary depending on the random value that is used to encrypt the data.</P>
<P>The encrypted files usually begin with the text â€œGLAMOURâ€:</P>
<P align=center><IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/17/Sinowal2.JPG"></P>
<P>We have managed to access the data of the infected systems and there are 1,108 infected computers. </P>
<P>Besides, in 111 of those machines the port 6838 is open so that the machines act as socket servers.</P>
<P>The â€œconstruction kitâ€ of Trj/Sinowal has been used to create this Trojan.</P>
<P>We have already mentioned this malware family in the eCrime 2007</P>
<P><A href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx">http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx</A></P>
<P>According to SecureWorks, this â€œconstruction kitâ€ is sold for around $1,000.</P>
<P><A href="http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&#38;NewsId=3740">http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&#38;NewsId=3740</A></P>
<P>This variant has been detected as Trj/Sinowal.FY in the signature file. </P><img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=224" width="1" height="1">]]></description>
			<content:encoded><![CDATA[<p><P>We have detected a new case of RansomWare.</P><br />
<P>Once the malware infects users and encrypts their files, several â€œread_me.txtâ€ files are created in the infected system, which warn users that their data files have been encrypted and that they wonâ€™t be able to access them unless they pay a ransom of $300.</P><br />
<P align=center><IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/17/Sinowal1.JPG"></P><br />
<P>&nbsp;The email addresses indicated in the message may vary:</P><br />
<BLOCKQUOTE dir=ltr ><br />
<P><A href="mailto:kiloglamour@gmail.com">kiloglamour@gmail.com</A></P><br />
<P><A href="mailto:tristanniglam@gmail.com">tristanniglam@gmail.com</A></P><br />
<P><A href="mailto:oxyglamour@gmail.com">oxyglamour@gmail.com</A></P><br />
<P><A href="mailto:glamourepalace@gmail.com">glamourepalace@gmail.com</A></P></BLOCKQUOTE><br />
<P>The â€œpersonal codeâ€ may also vary depending on the random value that is used to encrypt the data.</P><br />
<P>The encrypted files usually begin with the text â€œGLAMOURâ€:</P><br />
<P align=center><IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/17/Sinowal2.JPG"></P><br />
<P>We have managed to access the data of the infected systems and there are 1,108 infected computers. </P><br />
<P>Besides, in 111 of those machines the port 6838 is open so that the machines act as socket servers.</P><br />
<P>The â€œconstruction kitâ€ of Trj/Sinowal has been used to create this Trojan.</P><br />
<P>We have already mentioned this malware family in the eCrime 2007</P><br />
<P><A href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx">http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx</A></P><br />
<P>According to SecureWorks, this â€œconstruction kitâ€ is sold for around $1,000.</P><br />
<P><A href="http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&amp;NewsId=3740">http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&amp;NewsId=3740</A></P><br />
<P>This variant has been detected as Trj/Sinowal.FY in the signature file. </P><img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=224" width="1" height="1"></p>
                                <p><center>&copy; Visit the <a href="http://spyware-remover-help.com/">http://spyware-remover-help.com</a> for a free spyware removal help manual</center></p><img src="http://spyware-remover-help.com/wp-content/themes/spike_virus3.gif">                        ]]></content:encoded>
			<wfw:commentRss>http://spyware-remover-help.com/2007/07/16/a-new-case-of-ransomware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

