Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Thursday, September 15, 2016

The Pokemon Go ransomware virus is out to catch’em all!

A Pokemon Go-themed ransomware virus has appeared on Windows computers, tablets and phones. The ransomware is the latest in a series of malicious applications that have popped up in the wake of the global Pokemon Go obsession.

This particular piece of malware is known as POGO Tear and it’s based on open source ransomware code called Hidden Tear. POGO Tear encrypts the files on victims’ computers, changes the extension to “.locked” and then demands a ransom on a screen emblazoned with famed character Pikachu’s picture.

POGO Tear is currently coded to display its ransom message in Arabic only as shown below. The text informs users that their data has been encrypted and instructs them to contact blackhat20152015@gmail.com to decrypt their files. It also thanks them for their generosity.


What’s interesting about this malware is that it incorporates several features not usually found in other ransomware viruses. POGO Tear creates an administrative user account called Hack3r on the victim’s machine and then hides it from the logon screen so the user can’t tell it’s there.

It also creates a network share on the victim’s computer and copies itself to all available network drives. The ransomware automatically executes when Windows starts.

If your computers have been infected with ransomware or any other viurus, call IES today at 781-816-9437. The longer you wait, the worse the situation will be!

Sunday, October 13, 2013

IMPORTANT NOTICE TO ALL COMPUTER USERS: New Crypto Locker Ransomware infecting computers & locking down files.


We are seeing a new version of Crypto Locker Ransomware infecting computers and encrypting files so that you cannot access them. A message comes up as shown in the above link demanding $300 to be paid in order to get the files back.

If you encounter this virus on a work or home machine, turn it off immediately. Do not click on anything to close it. These criminals attempt to panic you into clicking on the "close" buttons which are really an "Ok, infect my computer" button. It is extremely important that you simply turn off the power to the computer immediately and contact your IT support person.

We recommend enabling strict filters on any and all firewalls in both your home and office, which may block some valid HTTPS sites such as banking sites but it's safer than letting this new trojan/virus into your computer systems. The infection is also "network aware" which means that if an infected user has access to a shared folder on a server or another workstation, that user will cause all shared files to become encrypted and unrecoverable as well.

The trojan infection is coming from infected web sites. The links may come in via email or on social media sites. So be very cautious about ANY web links. As we always recommend the sender should clearly identify themselves, you should know the sender and the purpose of the link(s) sent. In any case - it's still best to ignore them and DO NOT click on any links you receive without first calling and verifying that the sender and the link is legitimate.

Please be safe in your email and Internet browsing. If you need assistance securing your computers or find your computers to be infected, feel free to contact us to discuss your options.

IES, Inc.
781-816-9437
iesAdvisors.com