FYI…

- http://www.websensesecuritylabs.com/alerts…php?AlertID=320
October 24, 2005
"Websense® Security Labs™ has received reports of a new attack that attempts to extort money from users by encoding files on their machines, and then requesting payment for a decoder tool. The attack dynamics are very similar to the original discovery we reported on May 23, 2005 : http://www.websensesecuritylabs.com/alerts…php?AlertID=194 ('…The original infection occurs when the user visits a malicious website that exploits a previous vulnerability in Microsoft Internet Explorer. This vulnerability allows applications to run without user intervention…').
This attack appears to only be attacking Russian speakers and was first reported on Kaspersky's research blog: http://www.viruslist.com/en/weblog . Several vendors are calling the two pieces of malcode (JuNy.A and JuNy.B). Upon infection, the application searches on the machine or any mapped drives for more than 100 file types by extension. The malicious code modifies…registry items…
Like the encoder previously reported, the attacker requests that end-users send money in order to receive their data back. Also, like the former attack, the requested amount is $20. The code also displays two messages on the screen with instructions for contacting an email account in order to get the files back, and includes a list of files that it encoded…"

(Use first URL listed to see screenshots.)

:ph34r: