Guide | How To Ransomware posing as Microsoft

The associated guide may contain user-generated or external content.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Forum Veteran
Jan 24, 2011
9,380
1
24,873
8,379
malwaretips.com
Panda Labs said:
We've found yet another malware piece, this time it is a ransomware to take some of your money. Once you get infected (you can receive it in a number of different ways, most likely via spam messages and P2P), your computer is restarted. What for? Well, the malware installs itself to run every time your computer is started. And at the very beginning, just after you log in, it will show you the following screen:
Pantallazo1.png

With my English an Spanish knowledge I was able to understand what it was saying in German, but I translated it just in case. The threat is clear: your Microsoft Windows authenticity could not be verified, you need to have it fixed, which is just a 100€ payment. They give you the payment instructions and before saying goodbye they let you know that in case you don’t pay you’ll lose access to the computer and will lose all your data, as well as that the district attorney’s office has already your IP address and that you’ll be prosecuted in case you fail to pay the 100€ in 48 hours.

Read more
 
lol only german will believe it because only them will understand it. :D btw i like the "as well as that the district attorney’s office has already your IP address and that you’ll be prosecuted in case you fail to pay the 100€ in 48 hours."
 
umbrapolaris said:
lol only german will believe it because only them will understand it. :D btw i like the "as well as that the district attorney’s office has already your IP address and that you’ll be prosecuted in case you fail to pay the 100€ in 48 hours."
Yes...classic trick ....only the idea that they'll need to go to court scares a lot of people.....I don't think this trick would actually work in my country , not because people are smarter but because a court process usually takes at least 2 years so their's that:P
BTW +1 to Panda for also providing the deactivation code : QRT5T5FJQE53BGXT9HHJW53YT
 
Well they are trying to make more creative but its sense was only one theme, convinced to make an SMS or pay just to deactivate the code.