Jump to content

SOPA Is Back! … As a Ransomware Virus


nsane.forums

Recommended Posts

After historic Internet protests in January the SOPA anti-piracy bill was defeated. However, this week several reports have pointed to a rather unfortunate SOPA comeback. Not in Congress, but as a nasty cryptovirus that locks up people’s computers and accuses them of distributing copyright infringing files. Infected users can get their data back after a payment of $200 – at least, that’s what the virus makers promise.

The Stop Online Piracy ACT (SOPA) was a major threat to the Internet. The bill introduced draconian censorship tools for the Government and copyright holders, that worried the public and many key Internet companies including Reddit, Google and Wikipedia.

After months of protest, the bill was eventually killed off following the Internet Blackout earlier this year.

But that doesn’t mean SOPA is no longer a threat. This week ‘the bill’ was resurrected by a virus maker, who has been warning users of infected computers that their IP-address is on a blacklist after it was discovered distributing illegal content.

SOPA Ransomware

Posted Image

As a result, the SOPA virus holds all files on the host computer ransom.

“Your computer is locked!” the splash screen above warns, adding:

If you see a warning.txt or warning screen, it means your IP address was included in S.O.P.A. Black List. One or more of the following items were made from your PC:

1. Downloading or distributing audio or video files protected by Copyright Law.

2. Downloading or distributing illegal content (child porn, phishing software, etc.)

3. Downloading or distributing Software protected by Copyright Law.

As a result of these infringements based on Stop Online Piracy Act (H.R. 3261) your PC and files are now blocked.

The SOPA virus is so-called ransomware, meaning that it holds computers hostage and only promises to free data after victims hand over cash. In the U.S. and Canada people are instructed to pay with a MoneyPak prepaid voucher, and in other parts of the world they can use Western Union.

Those who don’t pay within three days are in trouble, the virus maker warns.

“WARNING!!!: If you don’t pay the fine within 72 HOURS at the amount of 200 USD, all your computer data will be erased.”

People who are affected should of course ignore all the above. Searching online for “Stop Online Piracy Automatic Protection System Removal”” is a better option, there are plenty of ways to defeat the resurrected SOPA and get your data back.

Posted Image View: Original Article

Link to comment
Share on other sites


  • Replies 14
  • Views 1.6k
  • Created
  • Last Reply

If this is a "Scam" and not "officially sanctioned", then any decent Anti-Malware should detect it. Right?

Link to comment
Share on other sites


If this is a "Scam" and not "officially sanctioned", then any decent Anti-Malware should detect it. Right?

Yes but the people who are ignorant or maybe dumb enough to fall for somthing as blatantly rediculously fake as this are teh same people who wont have any decent AV/AM installed.

Link to comment
Share on other sites


lol so those bastards saw that their bill got crushed so they found another way of getting their money by making a virus and scare ppl into paying (bet you anything they paid someone to make the virus for them)

what's more sad is that over 50% of the population have 0 knowledge in the ways of using an anti-virus and end up doing just what the virus in telling them :uhoh:

Link to comment
Share on other sites


Can someone PM a link or archive this malware file? I want to test it out on VMware. I have a few programs to test it against. THanks.

Link to comment
Share on other sites


Google for GEMA Virus/GEMA Trojaner, Bundespolizei Virus, they all have nothing to do with the GEMA or the Bundespolizei officially, they just use their names/logos/text-phrases and other related contents for the "official-look". Especially the GEMA Virus has a encryption feature, it locks your computer and encrypts your hard disk or a bunch of files from it. You also will be forced to pay a "special" price to get the decryption key and unlock the computer to be able to log-in to the desktop. We all know what you get after paying: your money is gone and you see nothing back.

I know how the SOPA virus works, the same way like the both i mentioned above, so it might be the same creator.

Link to comment
Share on other sites


First, take a big step back... and literally, FUCK YOUR OWN FACE! I don't know what kind of pan-pacific bullshit power play you're trying to pull here. So whatever you're thinking, you'd better think again! Otherwise I'm gonna have to head down there and I will rain down in a Godly fucking firestorm upon you! You're gonna have to call the fucking United Nations and get a fucking binding resolution to keep me from fucking destroying you. I'm talking about a scorched earth, motherfucker! I will massacre you! I WILL FUCK YOU UP!

Link to comment
Share on other sites


those are the peope that we need to go after.the real scum bag thieves of the internet

Link to comment
Share on other sites


strange that this hasn't been mentioned before brcause it's been active for almost 6 months now in different versions. It's easy enough to get rid off using Malwarebytes in safe mode first and then clean your registry when all related files found by Malwarebytes have been deleted!

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...