Dead Men Walking

dMw Chit Chat => The Beer Bar => Technology Section => Topic started by: suicidal_monkey on May 02, 2006, 10:11:09 AM

Title: fyi: Ransom-ware Trojan on the loose
Post by: suicidal_monkey on May 02, 2006, 10:11:09 AM
Ewido found a "Trojan.Ransom.a" infection in the battleracer 1.2.exe file this morning.

http://www.theinquirer.net/?article=31329 (http://www.theinquirer.net/?article=31329)
may be the same thing, though I've not (yet) received any Western Union demands...
Title: fyi: Ransom-ware Trojan on the loose
Post by: delanvital on May 02, 2006, 11:14:04 AM
Heh, that was a new one. Does not even bother to trick you with some fake software or anything... Glad to read that Kaspersky has been able to detect two types of that type of vira for a week :)
Title: fyi: Ransom-ware Trojan on the loose
Post by: Gandalf on May 02, 2006, 12:21:21 PM
I've just downloaded that file and it scans clean. however I notice that there are several mirrors so maybe the one I used was ok?

I used http://www.bf-g.de/data/battleracer_1.2.exe (http://www.bf-g.de/data/battleracer_1.2.exe)
Title: fyi: Ransom-ware Trojan on the loose
Post by: suicidal_monkey on May 02, 2006, 12:31:11 PM
I didn't have time to investigate further this morning before I left for work but will see if I can spot where the file came from (as I installed BR 1.2 last night it might not have originated there? I don't fully understand how these things can spread) With a bit of luck it's not actually installed itself yet, or is one of the versions that could be called bluff-ware or something (i.e. the threats don't actually work - all you really have to deal with is annoying messages ... of which I had received none by the time I left for work...)

 :unsure: