Bad time to change your mind, in case you are using a non-licensed / trial copy of Microsoft Windows. What the scamsters promise you here, is not what you think you'll get - Don't fall for their trick! This new ransomware in Windows style reminds us of the German Federal Police blackmailing Trojan that came up earlier this year.
In case of an infection, the pc is locked and inoperable. The malware displays a screen with a fake Microsoft Windows activation request:
G Data products identify this particular ransomware as Trojan.Generic.KDV.340157 (Engine A) and Win32:Trojan-gen (Engine B).
How one can identify this kind of threat as rip-off:
First of all, one should not be fooled by the official Windows logo or any other kind of alleged expression of authenticity! Do not pay the money asked for and do not enter any kind of personal information or any original Windows license information on the website.
The screen message pretends to have checked the genuineness of the installed Windows version. But the warning message displayed does not look like the original Windows activation notification screen at all.
One can check the genuineness of the installed Windows version on the official Microsoft “Genuine Windows” website and can also find all necessary information on how to activate a Windows copy there.
The victim is urged to pay €100 with a Ukash coupon code or Paysafecard – both are pre-paid currencies available in many public shops (post offices, gas stations, etc.).
Microsoft would never ask a customer to pay a fee or fine using Ukash coupon codes or Paysafecard payment!
The victim is asked to enter the pre-paid card’s identification number and a personal identification number, along with an email address or cell phone number, <link file:25268 _blank - "IMAGE, ransomware web codeentry, ransomware_web_codeentry.png, 119 KB">on a website</link>. This website is said to be “Microsoft’s activation page”, which obviously is a fake! Even the <link file:25271 _blank - "The original Windows activation notification screen">buttons</link> that are supposed to be hyperlinks are no real hyperlinks, but pictures only!
Microsoft would not launch any kind of official service on a website outside the official Microsoft domains!
Microsoft would take much better care for typos within the URL.
One can acquire individually licensed genuine Windows 7 retail licenses “through one of three channels: retail, original equipment manufacturer (OEM), or Volume Licensing (VL)”, Microsoft explains. One will not receive licenses by email or SMS, as the fake screen above tries to imply.
The screen message wants to add emphasize to the call by explaining that all data stored on the computer and the Windows copy will be irrevocably deleted in case the user ignores this warning and does not activate the Windows version within 48 hours.
Our analyses have not shown any deletion of files after 48 or more hours, so far.
The mentioned law (§126 para. 3 German Copyright Law) is used to imply the user would act unlawfully in case he/she does not perform the activation. This argument has no basis, as this particular section and paragraph touch a totally different topic.
The method of presenting legal facts and allegedly possible consequences is not a trustworthy one! Legal entities would not announce an accusation on a website – especially not with linguistic inadequacies and without hard facts.
System modifications detected:
The orphaned registry entries are harmless if the malicious msvcs.exe files were removed properly. If you do not feel comfortable to work in the registry or have never done it before, you may leave the files untouched. Please note: The X symbols in the following registry entries stand for an individual machine code.