New GpCode ransomeware attacks are circulating on a limited basis in the wild and AV vendors are adding protection. These new variants will encrypt several types of data files on a PC, demanding $150 in an online payment for a de-crypting capability Users should never pay these "ransoms" as the cleaning tool most likely won't arrive and some AV vendors provide de-crypting tools to clean infected systems. Still, this reminds us to periodically take a backup of important files and always avoid untrusted URLs and email attachments. New GpCode Ransomeware variants have surfaced http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FGPCODE%2EAB http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FGPCODE%2EAC quote:This Trojan may arrive as a dropped file or downloaded file of another malware. This Trojan encrypts all files with certain extension names found on any readable and writable drive. As a result, the said files become unreadable. It then drops and opens the file ASAP!!!.TXT on the current user's Desktop folder. The said text file informs the user that the files have been encrypted, and that special software must be purchased to decrypt the files.
myITforum Daily Newsletter August 20, 2007 Articles Forums Blogs Wiki FAQs Email Lists In this issue