Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

New GpCode Ransomeware variants have surfaced

New GpCode ransomeware attacks are circulating on a limited basis in the wild and AV vendors are adding protection.  These new variants will encrypt several types of data files on a PC, demanding $150 in an online payment for a de-crypting capability

Users should never pay these "ransoms" as the cleaning tool most likely won't arrive and some AV vendors provide de-crypting tools to clean infected systems.  Still, this reminds us to periodically take a backup of important files and always avoid untrusted URLs and email attachments

New GpCode Ransomeware variants have surfaced
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FGPCODE%2EAB
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FGPCODE%2EAC

quote:

This Trojan may arrive as a dropped file or downloaded file of another malware. This Trojan encrypts all files with certain extension names found on any readable and writable drive. As a result, the said files become unreadable. It then drops and opens the file ASAP!!!.TXT on the current user's Desktop folder. The said text file informs the user that the files have been encrypted, and that special software must be purchased to decrypt the files.