MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

New GpCode Ransomeware variants have surfaced

New GpCode ransomeware attacks are circulating on a limited basis in the wild and AV vendors are adding protection.  These new variants will encrypt several types of data files on a PC, demanding $150 in an online payment for a de-crypting capability

Users should never pay these "ransoms" as the cleaning tool most likely won't arrive and some AV vendors provide de-crypting tools to clean infected systems.  Still, this reminds us to periodically take a backup of important files and always avoid untrusted URLs and email attachments

New GpCode Ransomeware variants have surfaced
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FGPCODE%2EAB
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FGPCODE%2EAC

quote:

This Trojan may arrive as a dropped file or downloaded file of another malware. This Trojan encrypts all files with certain extension names found on any readable and writable drive. As a result, the said files become unreadable. It then drops and opens the file ASAP!!!.TXT on the current user's Desktop folder. The said text file informs the user that the files have been encrypted, and that special software must be purchased to decrypt the files.

Only published comments... Aug 17 2007, 02:46 PM by harry

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems