Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 7 June 2008 11:57:27 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Gpcode-D encrypts files found on the infected computer, in an attempt to blackmail the owner.
When files are encrypted, the string "._CRYPT" is appended to the original filename.
Multiple copies of a text file "!_READ_ME_!.txt" may be dropped. This file contains the following text:
"Your files are encrypted with RSA-1024 algorithm.
To recovery your files you need to buy our decryptor.
To buy decrypting tool contact us at: <email address>"
A message box may also be displayed containing the same text.
The Trojan attempts to delete itself at the same time this message is displayed.
