Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Scary new "blackmailing" virus

Lindal Kidd
Dances With Noobs
Join date: 26 Jun 2007
Posts: 8,371
06-11-2008 10:36
A friend just sent me this link.

http://www.computerweekly.com/Articles/2008/06/06/230968/variant-of-blackmailing-virus-now-spreading-on-the-web.htm

Synopsis: This virus encrypts your files and then offers to sell you a decryption tool. So far, the antivirus folks haven't managed to crack the encryption key.
_____________________
It's still My World and My Imagination! So there.
Lindal Kidd
Maureen Boccaccio
TWJKFA
Join date: 28 Feb 2008
Posts: 14,484
06-11-2008 10:39
Yes, I just saw something about that. Thanks for the head's up.
_____________________
Brenda Connolly
Un United Avatar
Join date: 10 Jan 2007
Posts: 25,000
06-11-2008 10:41
From: Lindal Kidd
A friend just sent me this link.

http://www.computerweekly.com/Articles/2008/06/06/230968/variant-of-blackmailing-virus-now-spreading-on-the-web.htm

Synopsis: This virus encrypts your files and then offers to sell you a decryption tool. So far, the antivirus folks haven't managed to crack the encryption key.

I have my own decryption tool. Reinstall. All my important files are on an external drive that's disconnected when not needed.
_____________________
Don't you ever try to look behind my eyes. You don't want to know what they have seen.

http://brenda-connolly.blogspot.com
Maggie McArdle
FIOS hates puppies
Join date: 8 May 2006
Posts: 2,855
06-11-2008 10:45
ok since the creator/owner provided an email addy, wouldn't it be easier to just track him/her down thru it?
_____________________
There's, uh, probably a lot of things you didn't know about lindens. Another, another interesting, uh, lindenism, uh, there are only three jobs available to a linden. The first is making shoes at night while, you know, while the old cobbler sleeps.You can bake cookies in a tree. But the third job, some call it, uh, "the show" or "the big dance," it's the profession that every linden aspires to.
MoxZ Mokeev
Invisible Alpha Texture
Join date: 10 Jan 2008
Posts: 870
06-11-2008 11:07
Another reason not to let my 15 year old have free reign of the desktop.
_____________________
:p
Desmond Shang
Guvnah of Caledon
Join date: 14 Mar 2005
Posts: 5,250
06-11-2008 11:08
I lost a whole bunch of original texture files last Friday (for other reasons than this virus) and oddly enough, didn't lose my most critical ones because I had uploaded them to the grid's asset server.

Strange but true...
_____________________

Steampunk Victorian, Well-Mannered Caledon!
Sling Trebuchet
Deleted User
Join date: 20 Jan 2007
Posts: 4,548
06-11-2008 11:26
From: Maggie McArdle
ok since the creator/owner provided an email addy, wouldn't it be easier to just track him/her down thru it?


Emails are throwaway run from net cafes, insecure wireless networks, etc.
The centre is probably in Russia. Good luck.

Try follow the money.

and ...

Most people have probably received those spams that are looking for people to process payments on behalf of a business that doesn't have an office in 'your' country. That sort of flavour. I see it wall to wall in spam filters.

The money will go through a chain of these mules/dupes.
_____________________
Maggie: We give our residents a lot of tools, to build, create, and manage their lands and objects. That flexibility also requires people to exercise judgment about when things should be used.
http://www.ace-exchange.com/home/story/BDVR/589
Macphisto Angelus
JAFO
Join date: 21 Oct 2004
Posts: 5,831
06-11-2008 11:29
Wait.. my pron is in danger? :eek:
_____________________
From: Natalie P from SLU
Second Life: Where being the super important, extra special person you've always been sure you are (at least when you're drunk) can be a reality!


From: Ann Launay
I put on my robe and wizard ha...
Oh. Nevermind then.
Maggie McArdle
FIOS hates puppies
Join date: 8 May 2006
Posts: 2,855
06-11-2008 12:06
From: Sling Trebuchet
Emails are throwaway run from net cafes, insecure wireless networks, etc.
The centre is probably in Russia. Good luck.

Try follow the money.

and ...

Most people have probably received those spams that are looking for people to process payments on behalf of a business that doesn't have an office in 'your' country. That sort of flavour. I see it wall to wall in spam filters.

The money will go through a chain of these mules/dupes.

ahh ok ...good thing i usually chuck those.
_____________________
There's, uh, probably a lot of things you didn't know about lindens. Another, another interesting, uh, lindenism, uh, there are only three jobs available to a linden. The first is making shoes at night while, you know, while the old cobbler sleeps.You can bake cookies in a tree. But the third job, some call it, uh, "the show" or "the big dance," it's the profession that every linden aspires to.
Joshua Jamberoo
Registered User
Join date: 18 May 2006
Posts: 27
06-11-2008 12:08
From: Macphisto Angelus
Wait.. my pron is in danger? :eek:


:eek: :eek:
Rhaorth Antonelli
Registered User
Join date: 15 Apr 2006
Posts: 7,425
06-11-2008 12:10
this seems to be similar to the smitfraud virus out there

hubby has it on his PC so at the moment it is not being used

basically it disables things, and sends a popup that you are infected with a link to a site to get software to clean it out

annoying and neither of us are comfortable messing with the registry, so will be taking it to the computer guy to clean it out
_____________________
From: someone
Morpheus Linden: But then I change avs pretty often too, so often, I look nothing like my avatar. :)


They are taking away the forums... it could be worse, they could be taking away the forums AND Second Life...
Zan Beck
Registered User
Join date: 21 Mar 2007
Posts: 131
06-11-2008 12:22
From: Macphisto Angelus
Wait.. my pron is in danger? :eek:




Nooooo we must save the Pron!!!
Macphisto Angelus
JAFO
Join date: 21 Oct 2004
Posts: 5,831
06-11-2008 12:45
*whew* I am glad it just isn't me worried.
_____________________
From: Natalie P from SLU
Second Life: Where being the super important, extra special person you've always been sure you are (at least when you're drunk) can be a reality!


From: Ann Launay
I put on my robe and wizard ha...
Oh. Nevermind then.
Yumi Murakami
DoIt!AttachTheEarOfACat!
Join date: 27 Sep 2005
Posts: 6,860
06-11-2008 13:54
From: Sling Trebuchet
Emails are throwaway run from net cafes, insecure wireless networks, etc.
The centre is probably in Russia. Good luck.


I honestly believe we should be able to request our ISPs block all access (for us) to and from countries which enforcement cannot reach.

On the other hand, this virus is not to be worried about any more than any other virus. Encrypting your data is actually _nicer_ that deleting it, which other viruses would do.
Ceka Cianci
SuperPremiumExcaliburAcc#
Join date: 31 Jul 2006
Posts: 4,489
06-11-2008 14:08
i've had a few of these russian things..they used to be spyware blackmails that did the same thing..they run a scan telling you that you have 5,000 infections and you need to buy this software to get rid of it..they'll have it cracked soon..
it sounds more like spyware than a virus really to me..they sound identical and were a pain to get rid of manually
_____________________
RandyChris Nightfire
Arrogant pervert
Join date: 21 Dec 2007
Posts: 61
06-11-2008 14:11
From: Rhaorth Antonelli
this seems to be similar to the smitfraud virus out there

hubby has it on his PC so at the moment it is not being used

basically it disables things, and sends a popup that you are infected with a link to a site to get software to clean it out

annoying and neither of us are comfortable messing with the registry, so will be taking it to the computer guy to clean it out


I have just had the same thing happen...It was the IEantivirus pop up, I spoke with the computer geeks and they told me it is an application file, that tells you there is something wrong, but there is nothing there... Lucky my P.C. was 8 yrs.old, and in need of joining P.C. heaven...Now I have brand new 1 complete with Vista, not XP, Firefox not IE6..Then to cap it all, everything is in German..Not bad for an English guy living in Austria, and not being able to speak much German...Yes I really did say 8 yrs.old and I have been using SL on it for 6 months...Good old HP, they really do make long lasting P.C.'s...
foehn Breed
More random than random
Join date: 16 Jan 2006
Posts: 1,142
06-11-2008 14:37
_____________________
You have no friends online at this time. "Excellent!"

Einstein "I never think of the future. It comes soon enough."
Macphisto Angelus
JAFO
Join date: 21 Oct 2004
Posts: 5,831
06-11-2008 15:13
From: foehn Breed


You rock. :)
_____________________
From: Natalie P from SLU
Second Life: Where being the super important, extra special person you've always been sure you are (at least when you're drunk) can be a reality!


From: Ann Launay
I put on my robe and wizard ha...
Oh. Nevermind then.
Micheal Moonlight
Registered User
Join date: 4 Sep 2005
Posts: 197
06-11-2008 15:45
From: Rhaorth Antonelli
this seems to be similar to the smitfraud virus out there

hubby has it on his PC so at the moment it is not being used

basically it disables things, and sends a popup that you are infected with a link to a site to get software to clean it out

annoying and neither of us are comfortable messing with the registry, so will be taking it to the computer guy to clean it out



Save yourself a couple bucks, if you actually have smitfraud use

http://siri.geekstogo.com/SmitfraudFix.php

very simple walkthrough with no registry editing... the only downside is once the tool is done you loose your current desktop background and have to set it again.
Micheal Moonlight
Registered User
Join date: 4 Sep 2005
Posts: 197
06-11-2008 15:56
From: Yumi Murakami
I honestly believe we should be able to request our ISPs block all access (for us) to and from countries which enforcement cannot reach.

On the other hand, this virus is not to be worried about any more than any other virus. Encrypting your data is actually _nicer_ that deleting it, which other viruses would do.


enforcement can reach any and every country. It is just tracking down the author that takes time.... Kevin Mitnik was U.S. based.. and had free rein for years before he got caught... the comcast hijack 2 weeks ago was U.S. based... should we ban access to the U.S? (i know these are hacks not viruses.. but both fall under computer criminal codes and both just as difficult to track down) sounds good to me *nods*

virus's haven't deleted your files since the dos days, and even then they corrupted the master boot sector, or moved the partition table to a different sector rather then delete the files and could be repaired.... very very few viruses actually delete files, doing unrecoverable damage to systems stands a bigger chance of you getting busted by the feds as corporate America calls for your head. *looks shifty* not that I know anything about this stuff.
Tod69 Talamasca
The Human Tripod ;)
Join date: 20 Sep 2005
Posts: 4,107
06-11-2008 17:56
Yea, the whole "haxxor" thing is kind of amusing.

After all these years, you'd think people would be a bit wiser?

But no, they click on things, leave their systems exposed without Anti-virus or anti-spyware software, or answer unsolicited emails from total strangers. I won't go into the whole "virus infected bit torrent" stuff.
_____________________
really pissy & mean right now and NOT happy with Life.
Tegg Bode
FrootLoop Roo Overlord
Join date: 12 Jan 2007
Posts: 5,707
06-12-2008 00:51
From: Tod69 Talamasca
Yea, the whole "haxxor" thing is kind of amusing.

After all these years, you'd think people would be a bit wiser?

But no, they click on things, leave their systems exposed without Anti-virus or anti-spyware software, or answer unsolicited emails from total strangers. I won't go into the whole "virus infected bit torrent" stuff.

Yeah but you got to worry about "antivirus software" when you pay money for it and it announces it just cleaned 5 new virus's found on your PC apparently contracted while sitting on the floor unplugged for 6 weeks. Or contracts new virus's without and internet connection or loading any new disks into it.
_____________________
Level 38 Builder [Roo Clan]

Free Waterside & Roadside Vehicle Rez Platform, Desire (88, 17, 107)

Avatars & Roadside Seaview shops and vendorspace for rent, $2.00/prim/week, Desire (175,48,107)
Raymond Nightfire
Known reverse engineer
Join date: 5 Nov 2007
Posts: 51
Get AVG 8.0
06-12-2008 09:59
AVG 8.0 is a free anti-virus, spyware, and any other nasty programs attacker.
It may slow down your system while scaning, but you can cancel that periodically.
Basiclay nothing you don't want can't get in, plus it will get update daily.
Macphisto Angelus
JAFO
Join date: 21 Oct 2004
Posts: 5,831
06-12-2008 10:03
From: Raymond Nightfire
AVG 8.0 is a free anti-virus, spyware, and any other nasty programs attacker.
It may slow down your system while scaning, but you can cancel that periodically.
Basiclay nothing you don't want can't get in, plus it will get update daily.


Yep, this and spybot keep my PC happy and healthy.
_____________________
From: Natalie P from SLU
Second Life: Where being the super important, extra special person you've always been sure you are (at least when you're drunk) can be a reality!


From: Ann Launay
I put on my robe and wizard ha...
Oh. Nevermind then.
Brenda Connolly
Un United Avatar
Join date: 10 Jan 2007
Posts: 25,000
06-12-2008 10:13
From: Raymond Nightfire
AVG 8.0 is a free anti-virus, spyware, and any other nasty programs attacker.
It may slow down your system while scaning, but you can cancel that periodically.
Basiclay nothing you don't want can't get in, plus it will get update daily.
I just run a scan at a time when I'm not using the computer, so slow down is not a problem. But it is a great program, especially at the price. I use that, Spybot, and the Windows Firewall, and have never had any problems.
_____________________
Don't you ever try to look behind my eyes. You don't want to know what they have seen.

http://brenda-connolly.blogspot.com
1 2