Ransirac

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 11
First Seen: October 3, 2012
Last Seen: May 20, 2023
OS(es) Affected: Windows

Ransirac is a family of ransomware Trojans and characterized because Ransirac uses fake messages from GEMA (Gesellschaft für musikalische Aufführungs), a German association that protects music intellectual property rights. Due to the widespread use of music files from unknown sources, Ransirac takes advantage of victims' guilt by threatening them so that they will pay an elevated fine. There are many variants of the Ransirac Trojan, also commonly known as GEMA ransomware. The original version of Ransirac was first detected in February of 2012 with additional variants being released in the months that followed. Despite the fact that Ransirac uses a threatening message that looks highly realistic, it is important for computer users to remember that Ransirac is not associated in any way with GEMA and that this malicious message is actually part of a ransomware attack designed to steal your money.

How Ransirac Tries to Trick You into Paying Its Ransom

Ransirac carries out an attack that is typical of these kinds of malware threats. Ransirac will install itself on the victim's computer using another Trojan infection or through a social engineering attack. Once installed, Ransirac will block access to the victim's Task Manager, Registry Editor, Desktop, file and other Windows components, and instead displaying a large, intrusive message claiming that the victim's computer was involved in violating intellectual property rights. It threatens to prosecute unless the victim pays a fine of one hundred Euros. To make its message even more authentic, Ransirac uses GEMA's actual HTML style sheets and images from their website. However, ESG security researchers note that Ransirac has no connection with GEMA and is actually a malware attack. Because of this, you should avoid paying Ransirac's ransom, especially since ESG malware analysts have observed that Ransirac will not be removed after doing so.

While most security programs can detect and remove Ransirac with few problems, the main difficulty for most computer users will be actually gaining access to their security software and bypassing Ransirac's malicious message. Fortunately, this can be done with the help of an external memory device to start up Windows. Safe Mode can also help, although it may be necessary to gain access to security software or the registry editor by using the command prompt. Most importantly, you should not pay the fine that Ransirac demands in its threatening message.

Related Posts

Trending

Most Viewed

Loading...