Sophos

Troj/Gpcode-D

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 7 June 2008 11:57:27 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Gpcode-D encrypts files found on the infected computer, in an attempt to blackmail the owner.

When files are encrypted, the string "._CRYPT" is appended to the original filename.

Multiple copies of a text file "!_READ_ME_!.txt" may be dropped. This file contains the following text:

"Your files are encrypted with RSA-1024 algorithm.
To recovery your files you need to buy our decryptor.
To buy decrypting tool contact us at: <email address>"

A message box may also be displayed containing the same text.

The Trojan attempts to delete itself at the same time this message is displayed.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer