All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog

 
Archive

<< 2010  
Jan Feb  
     
     
     
Virus Alert Danger Levels
Virus Alert Danger Levels

Wonder what the current virus alert means for your computer? Find out more about our Virus Alerts Threat Levels.

Free Removal Tools
Free Removal Tools

The Kaspersky Lab website removal tools section provides free utilities for removing dangerous viruses during an epidemic.

Antivirus Database Updates
Antivirus Database Updates

Kaspersky Anti-Virus users can always find the latest virus definitions in the database updates on the Kaspersky website.

 

  Home / Viruses / Alerts

Virus.Win32.GPCode.f, .g, .h, .i

06.27.05 11:58 GMT   |  comment

Status : informational

Kaspersky Lab has detected several infections caused by new modifications of Virus.Win32.GPCode. So far, information has only been received from Russian users. Four new modifications have been added to Kaspersky Anti-Virus databases.

This program can encrypt data files with extensions such as .txt, xls, rar, doc, html, pdf etc). Encrypted files contain the words 'PGPCoder' at the beginning of the file. Folders which contain encrypted files will also contain a file named readme.txt. The contents of readme.txt are given below, although the email address may differ:



Some files are coded.
To buy decoder mail: md731@yandex.ru
with subject: PGPcoder md73

If the user sends a message to the address contained in the text file, they will receive an answer saying that files can be decrypted for payment, and a sum will be named.



Kaspersky Lab strongly recommends that users should not attempt to make contact or pay any money for the 'decoder', as this is effectively blackmail. All the newest modifications of Virus.Win32.GPCode are detected by the latest Kaspersky Anti-Virus databases. Users simply need to update antivirus databases and run a full scan of the computer's hard disk in order to decrypt encrypted files.


Related links
Analysis
Malicious code evolution: July – September 2007
Blackmailer: the story of Gpcode
Blog
New Gpcode - mostly hot air
Gpcode - here we go again
Another way of restoring files after a Gpcode attack
Gpcode update
Restoring files attacked by Gpcode.ak
Alerts
Virus.Win32.Gpcode.ak
Virus.Win32.Gpcode.ag
Virus.Win32.GpCode.af
Virus.Win32.GpCode.ae
Virus.Win32.GPCode.ac
 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com