Is this ransomware?

I had a torrent, it was a acidedent, actually. Never really played it, but thats not whats wrong. When I visit a domain, charter (my ISP) has a page that says call Charter and they have seen I have crysis, and its punishable buy a 50 thousand dollar fine. Is it ransomware?
 
C:\Windows\system32\drivers\etc is where the Hosts file is located. Open it up in Notepad and see if there's anything suspicious in it.
 
So its happening on multiple browsers and multiple computers that is connected to Charter?

$50,000 is absolutely Ransomware. Run ccleaner and then Malwarebytes.
 
I downloaded Crysis 2, though, not 1. So, why does it say that I downloaded Crysis? Here is what it says:


Dear Charter Internet Subscriber:

Charter Communications ("Charter") has been notified by a copyright owner, or its authorized agent, that your Internet account may have been involved in the exchange of unauthorized copies of copyrighted material (e.g., music, movies, or software). We are enclosing a copy of the Digital Millennium Copyright Act (DMCA) notice that Charter received from the copyright holder which includes the specific allegation.

Under the DMCA, copyright owners have the right to notify Charter뭩 register agent if they believe that a Charter customer has infringed on their work(s). When Charter receives a complaint notice from a copyright owner, Charter will notify the identifiable customer of the alleged infringement by providing them a copy of the submitted DMCA notice. As required by law, Charter may determine that the customer is a repeat copyright infringer and reserves the right to suspend or terminate the accounts of repeat copyright infringers.

It is possible that this activity has occurred without your permission or knowledge by an unauthorized user, a minor who may not fully understand the copyright laws, or even as a result of a computer virus. However, as the named subscriber on the account, you may be held responsible for any misuse of your account. Please be aware that using Charter뭩 service to engage in any form of copyright infringement is expressly prohibited by Charter's Acceptable Use Policy and that repeat copyright infringement, or violations of any other Charter policy, may result in the suspension or termination of your service. You may view Charter's rules and policies, including Charter뭩 Acceptable Use Policy, under the policies section of charter.com.

We ask that you take immediate action to stop the exchange of any infringing material. For additional information regarding copyright infringement and for a list of frequently asked questions, please visit charter.com/dmca.

If you have questions about this letter, you may contact us at 1-866-229-7286. Representatives will be available to take your call Monday through Friday 8am - 8pm, Saturday and Sunday 8am - 5pm (CST).


Sincerely,


Charter Communications Security Resolution Team
http://www.charter.com/security


--- The following material was provided to us as evidence ---



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

10-11-2012

Entertainment Software Association
575 7th Street, NW, Suite 300
Washington, DC 20004 USA

Attention: Intellectual Property Enforcement
E-mail: [email protected]

Laurie Jill Wood
Charter Communications
Charter Communications =0A12405 Powerscourt Dr. =0ASt. Louis, =0AMO 6313=
1

Re: Copyright Infringement by Charter Communications Subscriber=20
Using IP 24.217.215.179 on 2012-10-10T08:38:00.90Z (the "Subscriber")
Reference Number 22262579611

Dear Charter Communications:

The Entertainment Software Association ("ESA") is the U.S. trade associa=
tion that represents the intellectual property interests of companies th=
at publish interactive games for video game consoles, personal computers=
, handheld devices, and the Internet (hereinafter collectively referred =
to as "ESA members"). A list of ESA members can be found at http://www.=
theesa.com/about/members.asp. Under penalty of perjury, we affirm that =
ESA is authorized to act on behalf of ESA members whose exclusive copyri=
ght rights we believe to have been infringed as described herein.

ESA is providing this notice pursuant to the Digital Millennium Copyrigh=
t Act ("DMCA"), 17 U.S.C. section 512, to request that you take immediat=
e action with respect to infringement of ESA member copyrighted works by=
your Subscriber. Using the IP address on the date and time referenced =
in the subject line of this notice, the Subscriber employed a peer-to-pe=
er service or software to distribute infringing copies of ESA member gam=
e products, including the following title:

CRYSIS

Courts in the United States have held consistently that the unauthorized=
distribution of copyrighted works using peer-to-peer or similar service=
s constitutes copyright infringement. E.g., MGM Studios, Inc. v. Grokst=
er, Ltd., 545 U.S. 913 (2005); BMG Music v. Gonzalez, 430 F.3d 888, 891 =
(7th Cir. 2005); Arista Records LLC v. Lime Group LLC, 2010 U.S. Dist. L=
EXIS 46638, *49 (S.D.N.Y. May 11, 2010

This Subscriber should understand clearly that there are serious consequ=
ences for infringement. The Copyright Act in the United States provides=
for statutory damages of up to $30,000 per work infringed, and up to $1=
50,000 per work for willful infringement. 17 U.S.C. section 504(c).

We ask that you work with us to protect the intellectual property rights=
of ESA members by:

1. Providing the Subscriber with a copy of this notice of copyright infr=
ingement, and warning the Subscriber that his or her conduct was unlawfu=
l and could be subject to civil or even criminal prosecution.
2. Promptly taking steps to stop the Subscriber's infringing activity.
3. Pursuant to 17 U.S.C. section 512(i)(1)(A), as appropriate, terminati=
ng the account of the Subscriber if your records show that he or she is =
a repeat copyright infringer.

ESA has a good faith belief that the Subscriber's reproduction and/or di=
stribution of these copyrighted works as set forth herein is not authori=
zed by the copyright owners, their agents, or the law. The information =
in this notification is accurate. Neither ESA nor its members waive any=
claims or remedies, or their right to engage in other enforcement activ=
ities, and all such claims, rights and remedies are expressly reserved.

You or your Subscriber may contact us through the information provided a=
bove, with email preferred. The Reference Number from the subject line =
of this notice should be included in the subject line of all corresponde=
nce.

Thank you for your prompt attention to this matter.=20

Sincerely,


Intellectual Property Enforcement
Entertainment Software Association
Telephone: 202-903-2314

List of infringing content
- ------------------------------
CRYSIS

- ------------------------------
INFRINGEMENT DETAIL =20
- ------------------------------
Infringing Work : CRYSIS
Filename : Crysis.2=20
First found (UTC): 2012-10-10T08:35:17.53Z
Last found (UTC): 2012-10-10T08:38:00.90Z
Filesize : 8152366592 bytes=20
IP Address: 24.217.215.179
IP Port: 50238
Network: BitTorrent
Protocol: BitTorrent =20
=0A=0AIf you have some issues please reply to [email protected]=
, reply to [email protected] will be ignored.=0A=0A- ---Start ACNS XM=
L=0A<?xml version=3D"1.0" encoding=3D"UTF-8"?>=20
<Infringement xsi:schemaLocation=3D"http://www.acns.net/ACNS http://www.=
acns.net/v1.2/ACNS2v1_2.xsd" xmlns=3D"http://www.acns.net/ACNS" xmlns:xs=
i=3D"http://www.w3.org/2001/XMLSchema-instance"> <Case>
<ID>22262579611</ID>=20
<Status>OPEN</Status>=20
<Severity>Normal</Severity>=20
<Ref_URL></Ref_URL>
</Case>
<Complainant>
<Entity>ESA</Entity>=20
<Contact>Intellectual Property Enforcement</Contact>=20
<Address>Entertainment Software Association 575 7th Street, NW, Suite =
300 Washington, DC 20004 USA</Address>=20
<Phone>202-903-2314</Phone>=20
<Email>[email protected]</Email>=20
</Complainant>
<Service_Provider>
<Entity>CHARTER COMMUNICATIONS</Entity>=20
<Contact>Laurie Jill Wood</Contact>=20
<Address>Charter Communications =0A12405 Powerscourt Dr. =0ASt. Louis,=
=0AMO 63131</Address>=20
<Phone></Phone>
<Email>[email protected]</Email>=20
</Service_Provider>
<Source>
<TimeStamp>2012-10-10T08:38:00.90Z</TimeStamp>=20
<IP_Address>24.217.215.179</IP_Address>=20
<Port>50238</Port>=20
<DNS_Name>24-217-215-179.dhcp.stls.mo.charter.com</DNS_Name>
<Type>P2P</Type>=20
<SubType BaseType=3D"P2P" Protocol=3D"BITTORRENT" />
<Number_Files>1</Number_Files>=20
<IsSource>false</IsSource>
</Source>
<Content>
<Item>
<TimeStamp>2012-10-10T08:38:00.90Z</TimeStamp>=20
<AlsoSeen Start=3D"2012-10-10T08:30:05.83Z" End=3D"2012-10-10T08:36:4=
1.83Z"></AlsoSeen>
<Title>CRYSIS</Title>=20
<Artist></Artist>
<FileName>Crysis.2</FileName>=20
<FileSize>8152366592</FileSize>=20
<Type>Game</Type>=20
<Hash Type=3D"SHA1">AB6E99320CD9CEED8DC2465D47F3512E54857443</Hash>
</Item>
</Content>
<History></History>=20
<Notes></Notes>
</Infringement>=0A- ---End ACNS XML=0A-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (MingW32)

iEYEARECAAYFAlB2wL4ACgkQxDbGXOV1jVJwtgCdH07FZ6/jjnDjX2w/MjqUod8p
KegAoI5Vm8UacMfLb2WMCp+Ie4WMgD/t
=3DuqbL
-----END PGP SIGNATURE-----
 
Last edited:
Okay, in the drivers folder. What should I do?
hosts.png
Here is the hosts file in teamviewer.
 
Last edited:
That means you are in trouble, you got caught downloading illegal material. It's not ransomware. Call charter to find out what you have to do get your browsing back. If this was only on one machine the. It would be ransomware.
 
Okay, it sounds like they give a warning, then they shut off the internet. So I will call them. But, the messages are no longer showing.
 
Yeah... nevermind about my post. They did not explicitly say $50,000, just up to. Tell your parents. They're the ones paying.
 
Yes, that was indeed a legitimate notification from Charter.

At work, a customers computer was torrenting music while I was working on it (without me knowing) and Charter/DMCA detected it. We got a letter in the mail asking us to call about "Important Information". The webpage it sent us to had details on the song and our IP address. We didn't get specifics on the computer, but we knew it was a customer because it wasn't the kind of music I or my co-worker listen to.
 
Back
Top