<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Malware Extorts Cash From BitTorrent Users</title>
	<atom:link href="http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/</link>
	<description>Torrent News, Torrent Sites and the latest Scoops</description>
	<lastBuildDate>Tue, 22 May 2012 22:55:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: BitTorrent users beware: New Virus - E-Cigarette Forum</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-655458</link>
		<dc:creator>BitTorrent users beware: New Virus - E-Cigarette Forum</dc:creator>
		<pubDate>Sun, 25 Apr 2010 01:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-655458</guid>
		<description>[...] users beware: New Virus      Malware Extorts Cash From BitTorrent Users &#124; TorrentFreak  Don&#039;t know if any of you torrent music or movies, but if you do, beware of this one. It had a very [...]</description>
		<content:encoded><![CDATA[<p>[...] users beware: New Virus      Malware Extorts Cash From BitTorrent Users | TorrentFreak  Don&#39;t know if any of you torrent music or movies, but if you do, beware of this one. It had a very [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BitTorrent Extortion? &#171; TTC Shelbyville &#8211; Technical Blog</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-655283</link>
		<dc:creator>BitTorrent Extortion? &#171; TTC Shelbyville &#8211; Technical Blog</dc:creator>
		<pubDate>Sat, 24 Apr 2010 03:24:04 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-655283</guid>
		<description>[...] to article     Categories: Computers Tags: bittorrent, Malware, scareware       Comments (0) Trackbacks (0) [...]</description>
		<content:encoded><![CDATA[<p>[...] to article     Categories: Computers Tags: bittorrent, Malware, scareware       Comments (0) Trackbacks (0) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: La violation des droits d’auteurs – le malware de la fondation ICPP</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-654902</link>
		<dc:creator>La violation des droits d’auteurs – le malware de la fondation ICPP</dc:creator>
		<pubDate>Thu, 22 Apr 2010 11:24:10 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-654902</guid>
		<description>[...] Na paniquez pas, ce ne sont que des programmes malveillants. Personne ne peut scanner votre ordinateur sans votre permission ou sans un mandat de la cour de justice. La fondation ICPP semble au dessus de tout cela,  en tentant par cette escroquerie de soutirer de l’argent.  Lisez l’article en entier sur  TorrentFreak. [...]</description>
		<content:encoded><![CDATA[<p>[...] Na paniquez pas, ce ne sont que des programmes malveillants. Personne ne peut scanner votre ordinateur sans votre permission ou sans un mandat de la cour de justice. La fondation ICPP semble au dessus de tout cela,  en tentant par cette escroquerie de soutirer de l’argent.  Lisez l’article en entier sur  TorrentFreak. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wtf?!?!?! Copyright violation : Copyrighted content detected??!!!?!! - Page 2 - Grasscity.com Forums</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-654485</link>
		<dc:creator>Wtf?!?!?! Copyright violation : Copyrighted content detected??!!!?!! - Page 2 - Grasscity.com Forums</dc:creator>
		<pubDate>Tue, 20 Apr 2010 01:27:58 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-654485</guid>
		<description>[...] Re: Wtf?!?!?! Copyright violation : Copyrighted content detected??!!!?!!    ya this is a virus.    Malware Extorts Cash From BitTorrent Users &#124; TorrentFreak [...]</description>
		<content:encoded><![CDATA[<p>[...] Re: Wtf?!?!?! Copyright violation : Copyrighted content detected??!!!?!!    ya this is a virus.    Malware Extorts Cash From BitTorrent Users | TorrentFreak [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bittorrent &#171; Javierserna&#39;s Blog</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653718</link>
		<dc:creator>bittorrent &#171; Javierserna&#39;s Blog</dc:creator>
		<pubDate>Fri, 16 Apr 2010 06:18:20 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653718</guid>
		<description>[...] Vía: TorrentFreak [...]</description>
		<content:encoded><![CDATA[<p>[...] Vía: TorrentFreak [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UniversoTek &#187; &#161;Cuidado con el virus chantajista! [BitTorrent]</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653689</link>
		<dc:creator>UniversoTek &#187; &#161;Cuidado con el virus chantajista! [BitTorrent]</dc:creator>
		<pubDate>Fri, 16 Apr 2010 00:39:14 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653689</guid>
		<description>[...] TorrentFreak  var addthis_language = [...]</description>
		<content:encoded><![CDATA[<p>[...] TorrentFreak  var addthis_language = [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Usuarios de BitTorrent: cuidado con el virus chantajista - Vaya Huevos</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653631</link>
		<dc:creator>Usuarios de BitTorrent: cuidado con el virus chantajista - Vaya Huevos</dc:creator>
		<pubDate>Thu, 15 Apr 2010 21:27:06 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653631</guid>
		<description>[...] Vía: TorrentFreak [...]</description>
		<content:encoded><![CDATA[<p>[...] Vía: TorrentFreak [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Usuarios de BitTorrent: cuidado con el virus chantajista &#124; tuexperto.com</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653628</link>
		<dc:creator>Usuarios de BitTorrent: cuidado con el virus chantajista &#124; tuexperto.com</dc:creator>
		<pubDate>Thu, 15 Apr 2010 21:21:20 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653628</guid>
		<description>[...] Vía: TorrentFreak [...]</description>
		<content:encoded><![CDATA[<p>[...] Vía: TorrentFreak [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Whatever</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653499</link>
		<dc:creator>Whatever</dc:creator>
		<pubDate>Thu, 15 Apr 2010 08:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653499</guid>
		<description>@127 Deltaplan
For as far as i have encountered any of those fake AV advertisement in a browser window, for instance TPB or other sites, do NOT scan anything. However, when you allow to download something then you are in trouble.

It is a PICTURE (or movie) possibly with a dir command on your C: drive (in YOUR browser) so it looks like they see your drive and do an online scan !!! (it is part of the scaM to make you believe they did an online scaN)</description>
		<content:encoded><![CDATA[<p>@127 Deltaplan<br />
For as far as i have encountered any of those fake AV advertisement in a browser window, for instance TPB or other sites, do NOT scan anything. However, when you allow to download something then you are in trouble.</p>
<p>It is a PICTURE (or movie) possibly with a dir command on your C: drive (in YOUR browser) so it looks like they see your drive and do an online scan !!! (it is part of the scaM to make you believe they did an online scaN)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653415</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Wed, 14 Apr 2010 21:27:34 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653415</guid>
		<description>i probbably could of worded that better

more along the lines of a listing of where the malware infects your computer and how to remove and some apps to diagnose that its gone (and could detect a significant amount of other malware at the same time!)</description>
		<content:encoded><![CDATA[<p>i probbably could of worded that better</p>
<p>more along the lines of a listing of where the malware infects your computer and how to remove and some apps to diagnose that its gone (and could detect a significant amount of other malware at the same time!)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653414</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Wed, 14 Apr 2010 21:24:37 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653414</guid>
		<description>@129
7 is just exessive, you should instead have one. plus multiple others but disabled in registry and services

knowing how to do that would give you a great start on how to combat most malware your self anyway and not need such a brutal security regieme 

sure use a good firewall, anti virus and anti spyware have sandbox apps, and blaclist apps if you were real parinoid run in a virtual enviroment and have a firewall box as well

good security should not reduce your computer to a crawl and should be able to disable at will for gaming simply installing 7 of them is just counter productive and recomening it to people who dont have the skill to reconise the pros and cons and workarouns is realy doing more harm than good



@131
avast is good :D 
glad they finaly picked it up
but i would doubble check on the registry key is set right

in:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

edit:
Shell = “%AppData%\IQManager\iqmanager.exe”

to:
Shell = “c:\windows\explorer.exe”

just because the message is gone dosent mean it is.

that bit is far more dangerous than the run entry

and of course if you know how to interpret, or want to, to insure your computer is clean read up for the link to the forums where all the tools and components of the files are hiding

if you have any troubles let me know you have done well so far :)</description>
		<content:encoded><![CDATA[<p>@129<br />
7 is just exessive, you should instead have one. plus multiple others but disabled in registry and services</p>
<p>knowing how to do that would give you a great start on how to combat most malware your self anyway and not need such a brutal security regieme </p>
<p>sure use a good firewall, anti virus and anti spyware have sandbox apps, and blaclist apps if you were real parinoid run in a virtual enviroment and have a firewall box as well</p>
<p>good security should not reduce your computer to a crawl and should be able to disable at will for gaming simply installing 7 of them is just counter productive and recomening it to people who dont have the skill to reconise the pros and cons and workarouns is realy doing more harm than good</p>
<p>@131<br />
avast is good :D<br />
glad they finaly picked it up<br />
but i would doubble check on the registry key is set right</p>
<p>in:<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</p>
<p>edit:<br />
Shell = “%AppData%\IQManager\iqmanager.exe”</p>
<p>to:<br />
Shell = “c:\windows\explorer.exe”</p>
<p>just because the message is gone dosent mean it is.</p>
<p>that bit is far more dangerous than the run entry</p>
<p>and of course if you know how to interpret, or want to, to insure your computer is clean read up for the link to the forums where all the tools and components of the files are hiding</p>
<p>if you have any troubles let me know you have done well so far :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: deleted</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653399</link>
		<dc:creator>deleted</dc:creator>
		<pubDate>Wed, 14 Apr 2010 20:35:58 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653399</guid>
		<description>Well since ive got this virus ive been called several names by &#039;kataanglover1&#039;, inc &#039;new fag&#039;. but all of his ideas to fix this virus on my laptop did not work. Just because i dont know much about computers doesn&#039;t mean you should be harsh to people. This is why im posting this now for all of the people out there and dont think that there amazing on computers and dont take the mic out of people who struggle on computers.log onto the affected account and press &#039;ctrl,alt,del&#039; to start &#039;task manager&#039; select &#039;I-Q Manager&#039; and select end task. When the program is closed, select file in the top left corner of &#039;Task manager&#039; and select&#039;new task&#039; browse your files to find a web browser and open it. Go to google, and search for &#039;avast free antivirus&#039; download it following the onscreen instructions. when the download is complete log off the administrator account(affected account) and log into a standard account, on this account run &#039;avast full search&#039;  when it is complete select the &#039;IQ manager virus&#039; and select &#039;delete&#039;  when the virus is deleted, shut down the computer. Power on the computer, and log into previously affected account and it should now work:), pretty good for an &#039;new fag&#039; dont you think?</description>
		<content:encoded><![CDATA[<p>Well since ive got this virus ive been called several names by &#8216;kataanglover1&#8242;, inc &#8216;new fag&#8217;. but all of his ideas to fix this virus on my laptop did not work. Just because i dont know much about computers doesn&#8217;t mean you should be harsh to people. This is why im posting this now for all of the people out there and dont think that there amazing on computers and dont take the mic out of people who struggle on computers.log onto the affected account and press &#8216;ctrl,alt,del&#8217; to start &#8216;task manager&#8217; select &#8216;I-Q Manager&#8217; and select end task. When the program is closed, select file in the top left corner of &#8216;Task manager&#8217; and select&#8217;new task&#8217; browse your files to find a web browser and open it. Go to google, and search for &#8216;avast free antivirus&#8217; download it following the onscreen instructions. when the download is complete log off the administrator account(affected account) and log into a standard account, on this account run &#8216;avast full search&#8217;  when it is complete select the &#8216;IQ manager virus&#8217; and select &#8216;delete&#8217;  when the virus is deleted, shut down the computer. Power on the computer, and log into previously affected account and it should now work:), pretty good for an &#8216;new fag&#8217; dont you think?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NEWS: Copyright malware appears on Bittorrent &#124; DigiCamBlog: Digital Camera Tips and Techniques</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653343</link>
		<dc:creator>NEWS: Copyright malware appears on Bittorrent &#124; DigiCamBlog: Digital Camera Tips and Techniques</dc:creator>
		<pubDate>Wed, 14 Apr 2010 15:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653343</guid>
		<description>[...] nasty bit of malware is reportedly doing the rounds in the BitTorrent community, taking the form of a fake copyright violation notice [...]</description>
		<content:encoded><![CDATA[<p>[...] nasty bit of malware is reportedly doing the rounds in the BitTorrent community, taking the form of a fake copyright violation notice [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheJoker</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653319</link>
		<dc:creator>TheJoker</dc:creator>
		<pubDate>Wed, 14 Apr 2010 12:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653319</guid>
		<description>Having read all the comments about this issue a lot of you seem to forget you were new to pc&#039;s once and have forgoten that fact whilst calling people morons .I wonder who are the real morons the new or you</description>
		<content:encoded><![CDATA[<p>Having read all the comments about this issue a lot of you seem to forget you were new to pc&#8217;s once and have forgoten that fact whilst calling people morons .I wonder who are the real morons the new or you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DeltaPan</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653295</link>
		<dc:creator>DeltaPan</dc:creator>
		<pubDate>Wed, 14 Apr 2010 11:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653295</guid>
		<description>A few mateys are mentioning anti-piracy agents themselves may be involved.

Would not surprise me for a moment if it transpires they are.

As i&#039;ve mentioned quite a few times recently, a few years back a group called &quot;Media Defender&quot; had one of their main operatives Gmail account hacked and the whole contents of the account were floated on torrent, still available on TPB.
http://thepiratebay.org/torrent/3806944/MediaDefender.Mail.200612.200709-MDD

Instructions of how to browse the emails given in comments on page.

These show how many shenanigans they were involved in, thanks again to Media Defender defenders for making these available.

It shows anti-piracy agents are involved in criminal activities against us, such as hacking, illegal privacy invasions using fake sites, honey traps etc.

The amount of criminal activities they were involved in is unbelievable, they should have served time for their activities, where we are simply civil infractors, they are criminals with no respect for criminal law never mind our civil infractions.

So it wouldn&#039;t surprise me one bit, if some anti-piracy outfit is actually behind this, they seem to think acting criminally towards us is perfectly justified and actually find it funny, sick sociopaths the fracking lot of them.

Take a look at the emails, as i&#039;ve said, too much time and money was spent to simply abandon their plans, they just waited until it all died down and we are indeed seeing their plans resurface and indeed, as time goes on their plans become more complex and improved but those emails give an idea of what these oiks are prepared to do.

Governments and law enforcement agencies want to concentrate on what anti-piracy groups are doing more, again, file sharing is a civil matter, what these anti-piracy agents working on behalf of copyright holders are doing is often criminal and they break criminal laws and they seem to be completely ignored and shouldn&#039;t be!

As in the emails, they even think completely ignoring criminal laws and acting criminally towards file sharers is funny, utter contempt for criminal law, laws which are present in most nations, anti-piracy think criminal laws do not apply to them.

Some idiot mentioned about Federal Taskforces in another thread, well they aren&#039;t interested in file sharing, but were they to bother, they&#039;d find a lot of financial irregularities in the accounts of these people, copyright holding companies and anti-piracy group;s both, as much as a plethora of other criminal offences perpetrated by these corporate oiks.

Again, perhaps governments and law enforcement of nations should look at those before focusing on file sharers because both of those groups, copyright holders and anti-piracy agents, deem themselves above the law and act criminally as a norm, not a rarity but commonly, if the FBI did look into them, they&#039;d find enough criminality to recoup millions of Dollars and  Euro&#039;s to keep courts busy for years.

 
Peace. : )</description>
		<content:encoded><![CDATA[<p>A few mateys are mentioning anti-piracy agents themselves may be involved.</p>
<p>Would not surprise me for a moment if it transpires they are.</p>
<p>As i&#8217;ve mentioned quite a few times recently, a few years back a group called &#8220;Media Defender&#8221; had one of their main operatives Gmail account hacked and the whole contents of the account were floated on torrent, still available on TPB.<br />
<a href="http://thepiratebay.org/torrent/3806944/MediaDefender.Mail.200612.200709-MDD" rel="nofollow">http://thepiratebay.org/torrent/3806944/MediaDefender.Mail.200612.200709-MDD</a></p>
<p>Instructions of how to browse the emails given in comments on page.</p>
<p>These show how many shenanigans they were involved in, thanks again to Media Defender defenders for making these available.</p>
<p>It shows anti-piracy agents are involved in criminal activities against us, such as hacking, illegal privacy invasions using fake sites, honey traps etc.</p>
<p>The amount of criminal activities they were involved in is unbelievable, they should have served time for their activities, where we are simply civil infractors, they are criminals with no respect for criminal law never mind our civil infractions.</p>
<p>So it wouldn&#8217;t surprise me one bit, if some anti-piracy outfit is actually behind this, they seem to think acting criminally towards us is perfectly justified and actually find it funny, sick sociopaths the fracking lot of them.</p>
<p>Take a look at the emails, as i&#8217;ve said, too much time and money was spent to simply abandon their plans, they just waited until it all died down and we are indeed seeing their plans resurface and indeed, as time goes on their plans become more complex and improved but those emails give an idea of what these oiks are prepared to do.</p>
<p>Governments and law enforcement agencies want to concentrate on what anti-piracy groups are doing more, again, file sharing is a civil matter, what these anti-piracy agents working on behalf of copyright holders are doing is often criminal and they break criminal laws and they seem to be completely ignored and shouldn&#8217;t be!</p>
<p>As in the emails, they even think completely ignoring criminal laws and acting criminally towards file sharers is funny, utter contempt for criminal law, laws which are present in most nations, anti-piracy think criminal laws do not apply to them.</p>
<p>Some idiot mentioned about Federal Taskforces in another thread, well they aren&#8217;t interested in file sharing, but were they to bother, they&#8217;d find a lot of financial irregularities in the accounts of these people, copyright holding companies and anti-piracy group;s both, as much as a plethora of other criminal offences perpetrated by these corporate oiks.</p>
<p>Again, perhaps governments and law enforcement of nations should look at those before focusing on file sharers because both of those groups, copyright holders and anti-piracy agents, deem themselves above the law and act criminally as a norm, not a rarity but commonly, if the FBI did look into them, they&#8217;d find enough criminality to recoup millions of Dollars and  Euro&#8217;s to keep courts busy for years.</p>
<p>Peace. : )</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Question</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653286</link>
		<dc:creator>Question</dc:creator>
		<pubDate>Wed, 14 Apr 2010 11:14:32 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653286</guid>
		<description>@105 HasABrain
&quot;it’s also being passed via facebook ads as well&quot;

You mean, internal messages with links to files which people download and run on purpose?

Just curious, what is the content of the messages if it&#039;s the case?</description>
		<content:encoded><![CDATA[<p>@105 HasABrain<br />
&#8220;it’s also being passed via facebook ads as well&#8221;</p>
<p>You mean, internal messages with links to files which people download and run on purpose?</p>
<p>Just curious, what is the content of the messages if it&#8217;s the case?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DeltaPan</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653282</link>
		<dc:creator>DeltaPan</dc:creator>
		<pubDate>Wed, 14 Apr 2010 10:51:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653282</guid>
		<description>16 Apr 11, 2010 at 22:57 by ROLF 
.exe, whats that ? :)
- - -
18 Apr 11, 2010 at 22:59 by politux 
.exe is short for “executes a virus”


An exe is an Executable, a programme file which can run independently as opposed to a complex application which requires drivers and multivarious scripts to function, an exe runs as a stand alone.

- - - 

Don&#039;t know if anybody has noticed, but for a few weeks, until last week is when it last happened with me....

TPB had a bogus virus scanner activating when navigating the site which was the usual malware BS, immediately stating &quot;Your Computer Is Infected&quot; and running an online scan.

I didn&#039;t let it get any farther and disconnected immediately, rebooted and added the URL from browser history to prohibited sites in Internet Options, whoever the tw@ts who were doing this were, they changed the URLs, i counted 8 different sites with the same virus.

Don&#039;t know about any other sites but maybe others can say if any other torrent sites were targeted.

They didn&#039;t get very far with me, but same as other sites all over the net where these bogus virus scans are used, they do two things, they scan everything so a list of drive contents becomes available for later hacking of your &#039;puter and 2, malware is dropped allowing backdoor access and others like automated transmission of personal details etc, various malicious uses.

Like i say, it didn&#039;t get more than a couple of seconds every time it occurred with me, but it&#039;d be interesting to see if somebody getting one of these fake copyright notices also had experiences of bogus online virus scans while navigating torrent sites.

I&#039;ve spyware 7 AV scanners anyway, only a fool hasn&#039;t, so even if it got far enough and dropped something it&#039;d no doubt be quarantined anyway.

But there may be a connection here, don&#039;t know.

I do know there&#039;s a lot of naive people who go to Warez sites and get malwares dropped on their PC&#039;s, since i was member to XWT forum i have noticed so many people suffering from infections after going to porn sites and Warez sites without proper protection, these days even media portals like online newspapers and shopping sites and alsorts are hacked and users navigating get infected.

bottom line is be aware at all times, the Internet is not a fluffy and safe environment and all too many feel being online is as safe as being at home in their nice safe house, you are at home, wherever, so feel secure, sites are nice and tidy and people are lulled into a false sense of security.

but it&#039;s actually better to consider yourself driving through a Crack Cocaine and Meth ridden ghetto, ergo, always be on guard.

there&#039;s as many deviants in the cyber world as there are in society, online doesn&#039;t mean safe, only your own vigilance means you stay safe.

As mentioned, anything happens, research it, don&#039;t take a fracking thing on face value.

scam&#039;s are usually flagged by people who realise they have been targeted, do a few searches and you&#039;ll find the sites which alert people to what scams are happeneing, plenty of those alert sites around and they can save you a lot of grief so use them if anything suss occurs, don&#039;t ignore things however benign they may seem, there&#039;s a lot of dodgy frackers out there committing cyber crimes so don&#039;t be a victim.


Peace. : )</description>
		<content:encoded><![CDATA[<p>16 Apr 11, 2010 at 22:57 by ROLF<br />
.exe, whats that ? :)<br />
- &#8211; -<br />
18 Apr 11, 2010 at 22:59 by politux<br />
.exe is short for “executes a virus”</p>
<p>An exe is an Executable, a programme file which can run independently as opposed to a complex application which requires drivers and multivarious scripts to function, an exe runs as a stand alone.</p>
<p>- &#8211; - </p>
<p>Don&#8217;t know if anybody has noticed, but for a few weeks, until last week is when it last happened with me&#8230;.</p>
<p>TPB had a bogus virus scanner activating when navigating the site which was the usual malware BS, immediately stating &#8220;Your Computer Is Infected&#8221; and running an online scan.</p>
<p>I didn&#8217;t let it get any farther and disconnected immediately, rebooted and added the URL from browser history to prohibited sites in Internet Options, whoever the tw@ts who were doing this were, they changed the URLs, i counted 8 different sites with the same virus.</p>
<p>Don&#8217;t know about any other sites but maybe others can say if any other torrent sites were targeted.</p>
<p>They didn&#8217;t get very far with me, but same as other sites all over the net where these bogus virus scans are used, they do two things, they scan everything so a list of drive contents becomes available for later hacking of your &#8216;puter and 2, malware is dropped allowing backdoor access and others like automated transmission of personal details etc, various malicious uses.</p>
<p>Like i say, it didn&#8217;t get more than a couple of seconds every time it occurred with me, but it&#8217;d be interesting to see if somebody getting one of these fake copyright notices also had experiences of bogus online virus scans while navigating torrent sites.</p>
<p>I&#8217;ve spyware 7 AV scanners anyway, only a fool hasn&#8217;t, so even if it got far enough and dropped something it&#8217;d no doubt be quarantined anyway.</p>
<p>But there may be a connection here, don&#8217;t know.</p>
<p>I do know there&#8217;s a lot of naive people who go to Warez sites and get malwares dropped on their PC&#8217;s, since i was member to XWT forum i have noticed so many people suffering from infections after going to porn sites and Warez sites without proper protection, these days even media portals like online newspapers and shopping sites and alsorts are hacked and users navigating get infected.</p>
<p>bottom line is be aware at all times, the Internet is not a fluffy and safe environment and all too many feel being online is as safe as being at home in their nice safe house, you are at home, wherever, so feel secure, sites are nice and tidy and people are lulled into a false sense of security.</p>
<p>but it&#8217;s actually better to consider yourself driving through a Crack Cocaine and Meth ridden ghetto, ergo, always be on guard.</p>
<p>there&#8217;s as many deviants in the cyber world as there are in society, online doesn&#8217;t mean safe, only your own vigilance means you stay safe.</p>
<p>As mentioned, anything happens, research it, don&#8217;t take a fracking thing on face value.</p>
<p>scam&#8217;s are usually flagged by people who realise they have been targeted, do a few searches and you&#8217;ll find the sites which alert people to what scams are happeneing, plenty of those alert sites around and they can save you a lot of grief so use them if anything suss occurs, don&#8217;t ignore things however benign they may seem, there&#8217;s a lot of dodgy frackers out there committing cyber crimes so don&#8217;t be a victim.</p>
<p>Peace. : )</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ransomware Malware Threatens to Sue Bit Torrent Pirates &#124; We Control The Net</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653257</link>
		<dc:creator>Ransomware Malware Threatens to Sue Bit Torrent Pirates &#124; We Control The Net</dc:creator>
		<pubDate>Wed, 14 Apr 2010 03:36:38 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653257</guid>
		<description>[...] Malware Extorts Cash From BitTorrent Users (torrentfreak.com)    breaking, Malware, News, ransomware, scam [...]</description>
		<content:encoded><![CDATA[<p>[...] Malware Extorts Cash From BitTorrent Users (torrentfreak.com)    breaking, Malware, News, ransomware, scam [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Malware Extorts Cash From&#160;BitTorrent&#160;Users &#171; The College of Arts and Sciences &#8211; Gathering Point for Technology at the University of Oregon</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653203</link>
		<dc:creator>Malware Extorts Cash From&#160;BitTorrent&#160;Users &#171; The College of Arts and Sciences &#8211; Gathering Point for Technology at the University of Oregon</dc:creator>
		<pubDate>Tue, 13 Apr 2010 21:27:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653203</guid>
		<description>[...] published on TorrentFreak. Read the original story here  April 13th, 2010 &#124; Leave a [...]</description>
		<content:encoded><![CDATA[<p>[...] published on TorrentFreak. Read the original story here  April 13th, 2010 | Leave a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ransomware and BitTorrent Scam &#171; Malware Survival</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653202</link>
		<dc:creator>Ransomware and BitTorrent Scam &#171; Malware Survival</dc:creator>
		<pubDate>Tue, 13 Apr 2010 21:21:23 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653202</guid>
		<description>[...] TorrentFreaks! [...]</description>
		<content:encoded><![CDATA[<p>[...] TorrentFreaks! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hms-one</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653170</link>
		<dc:creator>hms-one</dc:creator>
		<pubDate>Tue, 13 Apr 2010 19:26:23 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653170</guid>
		<description>UCC was right. It was only a matter of time. Why go to all the effort and cost to gather &quot;evidence&quot; and file legal paperwork, and mail warning letters? You still end up with no more valid a &quot;claim&quot; than a shite piece of scareware can pull off with a simple hard drive scan. This BS exposes the efforts of ACS and friends as the frauds they are.</description>
		<content:encoded><![CDATA[<p>UCC was right. It was only a matter of time. Why go to all the effort and cost to gather &#8220;evidence&#8221; and file legal paperwork, and mail warning letters? You still end up with no more valid a &#8220;claim&#8221; than a shite piece of scareware can pull off with a simple hard drive scan. This BS exposes the efforts of ACS and friends as the frauds they are.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NEWS: Copyright malware appears on Bittorrent &#124; iPod and iPhone</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653165</link>
		<dc:creator>NEWS: Copyright malware appears on Bittorrent &#124; iPod and iPhone</dc:creator>
		<pubDate>Tue, 13 Apr 2010 19:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653165</guid>
		<description>[...] nasty bit of malware is reportedly doing the rounds in the BitTorrent community, taking the form of a fake copyright violation notice [...]</description>
		<content:encoded><![CDATA[<p>[...] nasty bit of malware is reportedly doing the rounds in the BitTorrent community, taking the form of a fake copyright violation notice [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DXdiag</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653140</link>
		<dc:creator>DXdiag</dc:creator>
		<pubDate>Tue, 13 Apr 2010 17:43:48 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653140</guid>
		<description>if someone knows of a link to where I can this then please post it here, I want to decode it and see how it works.</description>
		<content:encoded><![CDATA[<p>if someone knows of a link to where I can this then please post it here, I want to decode it and see how it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virusi care cer Bani &#8211; atac asupra utilizatorilor BitTorrent</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653131</link>
		<dc:creator>Virusi care cer Bani &#8211; atac asupra utilizatorilor BitTorrent</dc:creator>
		<pubDate>Tue, 13 Apr 2010 17:00:46 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653131</guid>
		<description>[...] Sursa: TorrentFreak [...]</description>
		<content:encoded><![CDATA[<p>[...] Sursa: TorrentFreak [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yes yes yes</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653124</link>
		<dc:creator>yes yes yes</dc:creator>
		<pubDate>Tue, 13 Apr 2010 16:30:39 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653124</guid>
		<description>Thank God. I saw this on my computer and got really nervous. I was hoping it was a scam although I thought it was a small chance. Fortunately my research proves me right</description>
		<content:encoded><![CDATA[<p>Thank God. I saw this on my computer and got really nervous. I was hoping it was a scam although I thought it was a small chance. Fortunately my research proves me right</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Whatever</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653111</link>
		<dc:creator>Whatever</dc:creator>
		<pubDate>Tue, 13 Apr 2010 15:15:01 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653111</guid>
		<description>@All trying to give advice... which is fine and helps people with problems however &quot;deleted&quot; (@30) is 99 percent certainly faking it. The following text gives it away as this site is called &quot;Torrentfreak&quot;: &quot;the thing is i dont even know what a torrent is @28&quot;

And how does someone clueless of all (like flash drive) know how to comment with a nickname (called &quot;deleted&quot;). Next, it doesn&#039;t make sense telling someone how to put all important stuff in one folder and burn on CD/DVD if they don&#039;t know how to use the computer.

Finally, never send anyone to just any computer repair place if data is to be saved. Almost all of them will just say the data is lost and format the harddrive anyway (to avoid working or clueless themselves). Its better to first search for a computer repair place that will actually do a real attempt to rescue data for sure. So i suggest to add a warning about this when giving that advice.

(yes, i know, wrong forum)</description>
		<content:encoded><![CDATA[<p>@All trying to give advice&#8230; which is fine and helps people with problems however &#8220;deleted&#8221; (@30) is 99 percent certainly faking it. The following text gives it away as this site is called &#8220;Torrentfreak&#8221;: &#8220;the thing is i dont even know what a torrent is @28&#8243;</p>
<p>And how does someone clueless of all (like flash drive) know how to comment with a nickname (called &#8220;deleted&#8221;). Next, it doesn&#8217;t make sense telling someone how to put all important stuff in one folder and burn on CD/DVD if they don&#8217;t know how to use the computer.</p>
<p>Finally, never send anyone to just any computer repair place if data is to be saved. Almost all of them will just say the data is lost and format the harddrive anyway (to avoid working or clueless themselves). Its better to first search for a computer repair place that will actually do a real attempt to rescue data for sure. So i suggest to add a warning about this when giving that advice.</p>
<p>(yes, i know, wrong forum)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653099</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Tue, 13 Apr 2010 13:56:26 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653099</guid>
		<description>indeed crap cleaner will nuke the tempory files easily and most other things

but id still want a look at gmer/autoruns/hyjack this logs it is a basic rootkit after all there could be secondary infections.

http://download.cnet.com/CCleaner/3000-2144_4-10547048.html

even if sent in a pm.</description>
		<content:encoded><![CDATA[<p>indeed crap cleaner will nuke the tempory files easily and most other things</p>
<p>but id still want a look at gmer/autoruns/hyjack this logs it is a basic rootkit after all there could be secondary infections.</p>
<p><a href="http://download.cnet.com/CCleaner/3000-2144_4-10547048.html" rel="nofollow">http://download.cnet.com/CCleaner/3000-2144_4-10547048.html</a></p>
<p>even if sent in a pm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: curse</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653082</link>
		<dc:creator>curse</dc:creator>
		<pubDate>Tue, 13 Apr 2010 11:53:37 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653082</guid>
		<description>interesting case.. 
while reading this thread, I really start hate those ewwwbuntu users more, &quot;format HDD and install ewwwbuntu&quot; ain&#039;t the way to give a helpful response to someone in need, you&#039;re almost as bad as the malware makers(lol at using linux without root password, n00bs). On Windows, always make sure you got an updated anti-virus program and that Windows is updated, it takes care of most crap. When the Anti-virus manufacturers hear about this, it will be fixed. If not, complain to them &quot;I pay for your program and still don&#039;t get rid of this virus&quot;
Seems like bitdefender takes it

Remove iqmanager.exe instruction:

1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte iqmanager.exe virus files and kill iqmanager.exe file task process(if have);4.Delete/Modify any values added to the registry by iqmanager.exe ;5.delete IE temp files,restart the computer and run a whole scan with BitDefender. iqmanager.exe virus files as following:</description>
		<content:encoded><![CDATA[<p>interesting case..<br />
while reading this thread, I really start hate those ewwwbuntu users more, &#8220;format HDD and install ewwwbuntu&#8221; ain&#8217;t the way to give a helpful response to someone in need, you&#8217;re almost as bad as the malware makers(lol at using linux without root password, n00bs). On Windows, always make sure you got an updated anti-virus program and that Windows is updated, it takes care of most crap. When the Anti-virus manufacturers hear about this, it will be fixed. If not, complain to them &#8220;I pay for your program and still don&#8217;t get rid of this virus&#8221;<br />
Seems like bitdefender takes it</p>
<p>Remove iqmanager.exe instruction:</p>
<p>1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte iqmanager.exe virus files and kill iqmanager.exe file task process(if have);4.Delete/Modify any values added to the registry by iqmanager.exe ;5.delete IE temp files,restart the computer and run a whole scan with BitDefender. iqmanager.exe virus files as following:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653069</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 13 Apr 2010 10:23:22 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653069</guid>
		<description>@droidberry

Yeah, YOUR lucky someone taught you english real GOOD over THEIR. Retard, indeed.</description>
		<content:encoded><![CDATA[<p>@droidberry</p>
<p>Yeah, YOUR lucky someone taught you english real GOOD over THEIR. Retard, indeed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eylix</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653054</link>
		<dc:creator>Eylix</dc:creator>
		<pubDate>Tue, 13 Apr 2010 06:35:27 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653054</guid>
		<description>If it simply scans the victims computer for .torrents, what if they have downloaded obviously legit stuff like &#039;nix distros?</description>
		<content:encoded><![CDATA[<p>If it simply scans the victims computer for .torrents, what if they have downloaded obviously legit stuff like &#8216;nix distros?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nonono</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653043</link>
		<dc:creator>nonono</dc:creator>
		<pubDate>Tue, 13 Apr 2010 04:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653043</guid>
		<description>norton is the worse piece of crap resource pig/hog computer crashin piece of asswipe ever.</description>
		<content:encoded><![CDATA[<p>norton is the worse piece of crap resource pig/hog computer crashin piece of asswipe ever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653032</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Tue, 13 Apr 2010 02:55:57 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653032</guid>
		<description>ok mods moved the help thread to here:

http://www.p2pfreak.com/forum/bar/4011-iccp-foundation-mal-ware-removal.html</description>
		<content:encoded><![CDATA[<p>ok mods moved the help thread to here:</p>
<p><a href="http://www.p2pfreak.com/forum/bar/4011-iccp-foundation-mal-ware-removal.html" rel="nofollow">http://www.p2pfreak.com/forum/bar/4011-iccp-foundation-mal-ware-removal.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653018</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Tue, 13 Apr 2010 01:17:48 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653018</guid>
		<description>114
dam, well unless you want your computer to act like a relic from the dark ages i would not install that or if have uninstall!

for startes never run 2 antivirus at the same time. or they will each scan what the other opens and scans and in short will sit there and munch away and acieve nothing that is unles you keep one disabled

also why would you install such an ugly recorce hungry pig as nortons
sure there are alot of people out there that like it, but facts speak for them selves, look at the profensional testers comparisons if need be. its usless, it always leaves behind tendrils if it can remove anything at all

sure once upon a time nortans WAS good but that was a long long time ago and pre xp

so now you have your old scool fan boys and now the rather large bribes they place to get the prodouct pre installed and the good buisness deals. just becaue its cheaper dosent mean its any good.

and mcfee thats a laugh there is an urban myth going round that the evil queen her self was sprung writing viruses and releasing them so that her scanner will pick them up fist to improve stats and sales.
i tried finding a link but apart form some very embarising stufups i gave up shortly google is to powerfull for its own good sometimes



if you want a good firewall use comodo or kaspersky
if you want a good antivirus try avast or avg being the current most popular flavors of the last few years

virus total if you have a sample or threat expert are great to upload and see whats happening or what will clean off


@115 exept that shell now no loger knows what to load. restart and it may not work (unless windows is intelegent enough to revert back to default)

thus nessary to fix up the load point of explorer.exe

in:
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

    edit:
Shell = “%AppData%\IQManager\iqmanager.exe”    

to:
Shell = &quot;c:\windows\explorer.exe”

and of course all the other tendrils left behind folow guide here
http://www.p2pfreak.com/forum/p2p-news/4004-malware-extorts-cash-bittorrent-users.html</description>
		<content:encoded><![CDATA[<p>114<br />
dam, well unless you want your computer to act like a relic from the dark ages i would not install that or if have uninstall!</p>
<p>for startes never run 2 antivirus at the same time. or they will each scan what the other opens and scans and in short will sit there and munch away and acieve nothing that is unles you keep one disabled</p>
<p>also why would you install such an ugly recorce hungry pig as nortons<br />
sure there are alot of people out there that like it, but facts speak for them selves, look at the profensional testers comparisons if need be. its usless, it always leaves behind tendrils if it can remove anything at all</p>
<p>sure once upon a time nortans WAS good but that was a long long time ago and pre xp</p>
<p>so now you have your old scool fan boys and now the rather large bribes they place to get the prodouct pre installed and the good buisness deals. just becaue its cheaper dosent mean its any good.</p>
<p>and mcfee thats a laugh there is an urban myth going round that the evil queen her self was sprung writing viruses and releasing them so that her scanner will pick them up fist to improve stats and sales.<br />
i tried finding a link but apart form some very embarising stufups i gave up shortly google is to powerfull for its own good sometimes</p>
<p>if you want a good firewall use comodo or kaspersky<br />
if you want a good antivirus try avast or avg being the current most popular flavors of the last few years</p>
<p>virus total if you have a sample or threat expert are great to upload and see whats happening or what will clean off</p>
<p>@115 exept that shell now no loger knows what to load. restart and it may not work (unless windows is intelegent enough to revert back to default)</p>
<p>thus nessary to fix up the load point of explorer.exe</p>
<p>in:<br />
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</p>
<p>    edit:<br />
Shell = “%AppData%\IQManager\iqmanager.exe”    </p>
<p>to:<br />
Shell = &#8220;c:\windows\explorer.exe”</p>
<p>and of course all the other tendrils left behind folow guide here<br />
<a href="http://www.p2pfreak.com/forum/p2p-news/4004-malware-extorts-cash-bittorrent-users.html" rel="nofollow">http://www.p2pfreak.com/forum/p2p-news/4004-malware-extorts-cash-bittorrent-users.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-653001</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Mon, 12 Apr 2010 23:18:28 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-653001</guid>
		<description>You need to uninstall/remove this: C:\Documents and Settings\Administrator\Application Data\IQManager\iqmanager.exe

Then remove the startup entry (Start - Run - msconfig) or use a tool like HiJackThis/CCleaner

I found it on a client machine and it was easy to clean.</description>
		<content:encoded><![CDATA[<p>You need to uninstall/remove this: C:\Documents and Settings\Administrator\Application Data\IQManager\iqmanager.exe</p>
<p>Then remove the startup entry (Start &#8211; Run &#8211; msconfig) or use a tool like HiJackThis/CCleaner</p>
<p>I found it on a client machine and it was easy to clean.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Micheal Borean</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652999</link>
		<dc:creator>Micheal Borean</dc:creator>
		<pubDate>Mon, 12 Apr 2010 23:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652999</guid>
		<description>My brother got hit by this earlier. I was rather amused, because it seemed legitimate, until I saw that it was complaining about his naruto torrents, and a torrent for a music that isn&#039;t sold.

This came up a day after my brother installed Azuereus, Mcafee, and Norton. I believe it found a back door somewhere there. Windows 7, Home edition.</description>
		<content:encoded><![CDATA[<p>My brother got hit by this earlier. I was rather amused, because it seemed legitimate, until I saw that it was complaining about his naruto torrents, and a torrent for a music that isn&#8217;t sold.</p>
<p>This came up a day after my brother installed Azuereus, Mcafee, and Norton. I believe it found a back door somewhere there. Windows 7, Home edition.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652996</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Mon, 12 Apr 2010 22:56:22 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652996</guid>
		<description>gmail puts the activation link for torrent freak in the spam box.... tf you may want to clear that up!</description>
		<content:encoded><![CDATA[<p>gmail puts the activation link for torrent freak in the spam box&#8230;. tf you may want to clear that up!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652994</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Mon, 12 Apr 2010 22:55:17 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652994</guid>
		<description>also run sigverif (start, run) or ctrl alt del, taskmanager, file, run

and upload that as well</description>
		<content:encoded><![CDATA[<p>also run sigverif (start, run) or ctrl alt del, taskmanager, file, run</p>
<p>and upload that as well</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bert</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652992</link>
		<dc:creator>bert</dc:creator>
		<pubDate>Mon, 12 Apr 2010 22:52:08 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652992</guid>
		<description>@108 &amp; all do that!
great work on picking that one up, my bad i missed it.

@109 that is suprising, and a little hard to belive, its become pretty well much standard practice for scumware to infect system restore or a system rollback that is unles you are using win7 and had a dvd image set to fall back on

i assumed the winlogon allready had explorer.exe in there rather than  in there not that the iq manager replaced it

being a long time user of autoruns (well before he was headhunted by windows and now works on their kernel, and yes the same guy that dicoverd and exposed drm!)

but in that it lists the shell value in 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

have never had to go modify that registry key so never needed to go into the registry and notice the diffrence i didnt realise that it was in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

had i a sample and me instructions not worked the first thing i would of hit it with would of been autoruns and then i would of picked up on it

this knolege now raises the scumware coders skill by several dozen orders of magnatude whats done there has paved the way for a signifigant potential of mayhem unleashed upon infested systems

if done right it can counter most antivirus programs

ill put the revised instuctions on the forums here
http://www.p2pfreak.com/forum/p2p-news/4004-malware-extorts-cash-bittorrent-users.html


fist off dont play with autoruns unless with extreeme care. it dosent find whats good or bad ect like a tradional antivirus rather that its just a diagnostic tool and tells you whats there not whats good or bad, so dont ffs untick everything! same aplys to gmer, hyjackthis ice sword ect...

explorer.exe in short is everything that most people reconise as thier computer it controls among other thigs the gui (grapical user interface) so your desktop, your icons, your bacground my computer...

the fact that iqmanager uses a pre hacked one or loads beforehand and then sinks its teath into it gives it the potential if coded right to render most virus scanners impotent and usless simply by being able to hide from them it all depends on the skill and effort put into its creation

after killing files registry keys and fixing explorer.exe could someone upload a log from autoruns and gmer, and hyjackthis on the forums ill read though and check is clean if not it will let me sniff out any further signs of infection.</description>
		<content:encoded><![CDATA[<p>@108 &amp; all do that!<br />
great work on picking that one up, my bad i missed it.</p>
<p>@109 that is suprising, and a little hard to belive, its become pretty well much standard practice for scumware to infect system restore or a system rollback that is unles you are using win7 and had a dvd image set to fall back on</p>
<p>i assumed the winlogon allready had explorer.exe in there rather than  in there not that the iq manager replaced it</p>
<p>being a long time user of autoruns (well before he was headhunted by windows and now works on their kernel, and yes the same guy that dicoverd and exposed drm!)</p>
<p>but in that it lists the shell value in<br />
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell</p>
<p>have never had to go modify that registry key so never needed to go into the registry and notice the diffrence i didnt realise that it was in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\</p>
<p>had i a sample and me instructions not worked the first thing i would of hit it with would of been autoruns and then i would of picked up on it</p>
<p>this knolege now raises the scumware coders skill by several dozen orders of magnatude whats done there has paved the way for a signifigant potential of mayhem unleashed upon infested systems</p>
<p>if done right it can counter most antivirus programs</p>
<p>ill put the revised instuctions on the forums here<br />
<a href="http://www.p2pfreak.com/forum/p2p-news/4004-malware-extorts-cash-bittorrent-users.html" rel="nofollow">http://www.p2pfreak.com/forum/p2p-news/4004-malware-extorts-cash-bittorrent-users.html</a></p>
<p>fist off dont play with autoruns unless with extreeme care. it dosent find whats good or bad ect like a tradional antivirus rather that its just a diagnostic tool and tells you whats there not whats good or bad, so dont ffs untick everything! same aplys to gmer, hyjackthis ice sword ect&#8230;</p>
<p>explorer.exe in short is everything that most people reconise as thier computer it controls among other thigs the gui (grapical user interface) so your desktop, your icons, your bacground my computer&#8230;</p>
<p>the fact that iqmanager uses a pre hacked one or loads beforehand and then sinks its teath into it gives it the potential if coded right to render most virus scanners impotent and usless simply by being able to hide from them it all depends on the skill and effort put into its creation</p>
<p>after killing files registry keys and fixing explorer.exe could someone upload a log from autoruns and gmer, and hyjackthis on the forums ill read though and check is clean if not it will let me sniff out any further signs of infection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: THANKS</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652985</link>
		<dc:creator>THANKS</dc:creator>
		<pubDate>Mon, 12 Apr 2010 22:24:18 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652985</guid>
		<description>Thanks to everyone who posted advice! There ARE people willing to help even in the TF comments (well, its not youtube, but still...). Anyways, thanks alot! And everyone with a botnet should consider reallocating their DDoS resources...</description>
		<content:encoded><![CDATA[<p>Thanks to everyone who posted advice! There ARE people willing to help even in the TF comments (well, its not youtube, but still&#8230;). Anyways, thanks alot! And everyone with a botnet should consider reallocating their DDoS resources&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HasABrain</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652966</link>
		<dc:creator>HasABrain</dc:creator>
		<pubDate>Mon, 12 Apr 2010 20:55:57 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652966</guid>
		<description>I have also found a fix.  Once I corrupted the iqmanager file and the files within it, I was able to remove them and restart.  Just to be safe I did a system rollback once everything was up and running, re-ran malwarebytes and system appears to be clean.</description>
		<content:encoded><![CDATA[<p>I have also found a fix.  Once I corrupted the iqmanager file and the files within it, I was able to remove them and restart.  Just to be safe I did a system rollback once everything was up and running, re-ran malwarebytes and system appears to be clean.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: malware cash scam by ICCP Foundation</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652951</link>
		<dc:creator>malware cash scam by ICCP Foundation</dc:creator>
		<pubDate>Mon, 12 Apr 2010 20:08:30 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652951</guid>
		<description>[...] Do not freak out, it&#8217;s just ugly malware scam. Nobody can not scan Your computer without Your permission or court of law warrant. ICCP Foundation is apparently behind this, running this cash extortion scam. Read full story on TorrentFreak. [...]</description>
		<content:encoded><![CDATA[<p>[...] Do not freak out, it&#8217;s just ugly malware scam. Nobody can not scan Your computer without Your permission or court of law warrant. ICCP Foundation is apparently behind this, running this cash extortion scam. Read full story on TorrentFreak. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Estafas en línea inspiradas en estrategias antipiratería &#124; Home</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652948</link>
		<dc:creator>Estafas en línea inspiradas en estrategias antipiratería &#124; Home</dc:creator>
		<pubDate>Mon, 12 Apr 2010 19:54:25 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652948</guid>
		<description>[...] caso ha sido expuesto por la gente de Torrent Freak, y no nos extraña. Es una consecuencia de los tiempos en los que vivimos, y de una guerra digital [...]</description>
		<content:encoded><![CDATA[<p>[...] caso ha sido expuesto por la gente de Torrent Freak, y no nos extraña. Es una consecuencia de los tiempos en los que vivimos, y de una guerra digital [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sean</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652926</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Mon, 12 Apr 2010 18:37:11 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652926</guid>
		<description>Hey guys,

I&#039;ve managed to get back to my desktop.  I ran rkill to terminate iqmanager, then downloaded and ran malwarebytes, doing a full scan.  I then went ran regedit and changed hkey_current_user/software/microsoft/windowsNT/currentversion/winlogon shell from iqmanager.exe back to c:\windows\explorer.exe.

I am no computer guru, but this seems to have worked for me.</description>
		<content:encoded><![CDATA[<p>Hey guys,</p>
<p>I&#8217;ve managed to get back to my desktop.  I ran rkill to terminate iqmanager, then downloaded and ran malwarebytes, doing a full scan.  I then went ran regedit and changed hkey_current_user/software/microsoft/windowsNT/currentversion/winlogon shell from iqmanager.exe back to c:\windows\explorer.exe.</p>
<p>I am no computer guru, but this seems to have worked for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652921</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Mon, 12 Apr 2010 18:21:20 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652921</guid>
		<description>Is it only for Windows OS`s?</description>
		<content:encoded><![CDATA[<p>Is it only for Windows OS`s?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scout</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652918</link>
		<dc:creator>Scout</dc:creator>
		<pubDate>Mon, 12 Apr 2010 18:15:40 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652918</guid>
		<description>To get rid of this try running rkill: http://www.technibble.com/rkill-repair-tool-of-the-week/, which stops the bad stuff that is running on your computer and then run malwarebytes: http://www.malwarebytes.org/, which will clean it up and remove it.

It&#039;s easy, it&#039;s free, and it will probably work.</description>
		<content:encoded><![CDATA[<p>To get rid of this try running rkill: <a href="http://www.technibble.com/rkill-repair-tool-of-the-week/" rel="nofollow">http://www.technibble.com/rkill-repair-tool-of-the-week/</a>, which stops the bad stuff that is running on your computer and then run malwarebytes: <a href="http://www.malwarebytes.org/" rel="nofollow">http://www.malwarebytes.org/</a>, which will clean it up and remove it.</p>
<p>It&#8217;s easy, it&#8217;s free, and it will probably work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ???? ????. &#124; Play &#187; ????? ???????? ?????? ?? ????????</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652917</link>
		<dc:creator>???? ????. &#124; Play &#187; ????? ???????? ?????? ?? ????????</dc:creator>
		<pubDate>Mon, 12 Apr 2010 18:13:57 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652917</guid>
		<description>[...] ????????? ????????? ??????. ? ??? ????????? ?????? ?????, ??????? ????????? ?? ????? ?? [...]</description>
		<content:encoded><![CDATA[<p>[...] ????????? ????????? ??????. ? ??? ????????? ?????? ?????, ??????? ????????? ?? ????? ?? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HasABrain</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652904</link>
		<dc:creator>HasABrain</dc:creator>
		<pubDate>Mon, 12 Apr 2010 17:32:43 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652904</guid>
		<description>Just so you know, it&#039;s also being passed via facebook ads as well.  A number of computers on our network at work are infected with this very problem and we are working on eliminating it.  Malwarebytes DOES work to an extent, but it doesn&#039;t entirely fix the registry problems.  Any advice would be appreciated.  

Also, stop hating on people looking for help.  You make IT people like me look bad.  We&#039;re not all jerks.  I would like to say most of us like to help, not put down end users.  I&#039;m ashamed to be associated with the acid-tongued users posting on this page.

Oh, and another thing, Linux isn&#039;t always an option for everyone, so quit being so smug about it.</description>
		<content:encoded><![CDATA[<p>Just so you know, it&#8217;s also being passed via facebook ads as well.  A number of computers on our network at work are infected with this very problem and we are working on eliminating it.  Malwarebytes DOES work to an extent, but it doesn&#8217;t entirely fix the registry problems.  Any advice would be appreciated.  </p>
<p>Also, stop hating on people looking for help.  You make IT people like me look bad.  We&#8217;re not all jerks.  I would like to say most of us like to help, not put down end users.  I&#8217;m ashamed to be associated with the acid-tongued users posting on this page.</p>
<p>Oh, and another thing, Linux isn&#8217;t always an option for everyone, so quit being so smug about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anti-execute</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652890</link>
		<dc:creator>anti-execute</dc:creator>
		<pubDate>Mon, 12 Apr 2010 16:37:51 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652890</guid>
		<description>Yet another reason to protect your system with an executable whitelisting product.</description>
		<content:encoded><![CDATA[<p>Yet another reason to protect your system with an executable whitelisting product.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ...</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652848</link>
		<dc:creator>...</dc:creator>
		<pubDate>Mon, 12 Apr 2010 13:45:36 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652848</guid>
		<description>@ 55 politux

A simple misspelling does not qualify as broken English. Please refrain from pointlessly posting and further embarrassing yourself.</description>
		<content:encoded><![CDATA[<p>@ 55 politux</p>
<p>A simple misspelling does not qualify as broken English. Please refrain from pointlessly posting and further embarrassing yourself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Haittaohjelma uhkailee laittomia latailijoita &#124; Digilelut</title>
		<link>http://torrentfreak.com/malware-extort-cash-from-bittorrent-users-100411/#comment-652835</link>
		<dc:creator>Haittaohjelma uhkailee laittomia latailijoita &#124; Digilelut</dc:creator>
		<pubDate>Mon, 12 Apr 2010 12:45:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=23065#comment-652835</guid>
		<description>[...] Uusi haittaohjelma yrittää saada laittomien videoiden latailijoilta rahaa pelottelemalla heitä viidellä vankilavuodella ja 250 000 dollarin sakoilla. Haittaohjelma väittää löytäneensä käyttäjän koneelta tekijänoikeuksilla suojattuja tiedostoja ja lisätäkseen uskottavuuttaan se myös listaa käyttäjän koneelta löytämänsä torrent-tiedostot. [...]</description>
		<content:encoded><![CDATA[<p>[...] Uusi haittaohjelma yrittää saada laittomien videoiden latailijoilta rahaa pelottelemalla heitä viidellä vankilavuodella ja 250 000 dollarin sakoilla. Haittaohjelma väittää löytäneensä käyttäjän koneelta tekijänoikeuksilla suojattuja tiedostoja ja lisätäkseen uskottavuuttaan se myös listaa käyttäjän koneelta löytämänsä torrent-tiedostot. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

