New Variant of Gpcode Found

New Variant of Gpcode Found

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
New Variant of Gpcode Found What's in a Name? 06-09-2008
Posted by David H. Lipman on June 10, 2008, 7:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| "Rhonda Lea Kirk Fries" wrote in
|
>> I'm using OE, and I can see the follow-ups just fine.
|
| It's been a couple months since I stopped using Outlook Express. I
| don't recall that it ever showed the FollowUp-To header, or allowing the
| user to configure which headers to show, in the preview pane "header"
| section. You have to view the raw source of the message to see the
| header. It might show more headers if you open (double-click on) a
| message to show in its own window but I never used it in that nuisance
| mode. Of course, if you are wary and watch what were the newsgroups to
| which the original post was submitted and then to which newsgroups you
| end up replying to by default then you'll notice there was a change in
| that list of newsgroups.
|

It does. To set Follow-Ups you have to select; view --> all headers

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by VanguardLH on June 10, 2008, 12:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
"What's in a Name?" wrote in

> Has everyone heard about this one?
>
> From ZDNet
> "Virus analysts at Kaspersky Lab have intercepted a new variant of
> Gpcode, a malicious virus that encrypts important files on an infected
> desktop and demands payment for a key to recover the data."
>
> http://blogs.zdnet.com/security/?p=1251&tag=nl.e539
>
> max

NOTE: FollowUp-To ingored. Reply posted to original list of newsgroups.


From a cursory scan of the articles and the ones to which is linked, and
from the dearth of information provided there, the pest infilitrates a
system and then encrypts files to hold them ransom until the user pays
to get a utility to decrypt them. The pest itself is not encrypted (as
something would have to unencrypted to decrypt it to run that executable
but that that other program is the pest). So the pest itself would
still be detectable even if morphed (since polymorphism for a large
number of variants will vaporize when the program gets loaded into
memory). So the anti-malware products could still alert on the pest
based on signature and definitely on heuristics if loaded (by watching
which apps use the crypto API).

Maybe this threat will make some users realize that they really should
be doing regular backups.

Similar ThreadsPosted
Gpcode.ak encryptor virus June 17, 2008, 6:31 pm
Re: New variant? July 1, 2008, 9:09 am
Another Mytob variant November 27, 2005, 8:56 am
New variant of Feebs January 25, 2006, 6:20 pm
New Haxdoor Variant August 13, 2006, 9:11 pm
Key Logger variant? November 5, 2006, 10:09 pm
New Storm variant? September 6, 2007, 11:00 am
Newer Mytob variant September 7, 2005, 12:42 pm
Re: Newer Mytob variant September 7, 2005, 2:53 pm
New email worm variant February 6, 2007, 12:59 pm

The site map in XML format XML site map

Contact Us | Privacy Policy