Showing posts with label Gpcode. Show all posts
Showing posts with label Gpcode. Show all posts

Saturday, March 26, 2011

Another Return of GpCode

Kaspersky warns about a new version of nasty Gpcode ransomware type pest that encrypts files on infected system with a strong encryption and tries to make victim pay for getting those decrypted.

The program spreads via malicious websites as a drive by download. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.bn.

Due to heavy cryptography used, the encrypted files cannot be recovered making existing backups only possible solution (one good reason to have all important stuff always backed up on separate location).

More information can be read from Kaspersky blog.

Tuesday, November 30, 2010

GpCode Makes A Comeback

Kaspersky warns about a new version of nasty Gpcode ransomware pest that encrypts files on infected system and tries to make victim pay for getting those decrypted. Preliminary analysis indicate that RSA-1024 and AES-256 crypto-algorithms are used to encrypt part of files, starting from the first byte.

The program spreads via malicious websites and P2P networks. Kaspersky detect the pest as Trojan-Ransom.Win32.Gpcode.ax.

More information can be read from Kaspersky blog.

Friday, August 15, 2008

New Gpcode Variant Not As Dangerous As Earlier Variants

On Tuesday I blogged about Kaspersky's report of new Gpcode variant. Closer analyzes has shown this be less dangerous than its predecessors. " The claims made by the author about the use of AES-256 and the enormous number of unique keys were a bluff. The author even didn’t use a public key in encryption, so all the information needed to decrypt files is right there in the body of the malicious program", is told in Kaspersky's Blog.

Kaspersky analysis shows that the Trojan uses the 3DES algorithm but the author dug up an off-the-peg Delphi component rather than going to the trouble of creating his own encryption routine. Also, the Trojan's code is quite messy making it look like the author isn't much of a programmer.

Kaspersky calls this new Gpcode variant as Trojan-Ransom.Win32.Gpcode.am. The trojan was spread by another malicious program, P2P-Worm.Win32.Socks.fe.

Tuesday, August 12, 2008

New Version of Gpcode On Loose

Kaspersky reports in its blog about new variant of Gpcode. This version is currently spread via a botnet which name is withheld for security purposes.

Gpcode leaves a text file named crypted.txt which includes a ransom demand of $10. The file also contains the author's contact details: an email address, an ICQ number and a URL. In addition to encrypting files and leaving the message Gpcode changes the desktop wallpaper to a giant red skull with crossbones on white background (screenshot).

The ransom shouldn't be paid since it encourages the author to produce new variants. Also, the authors' details about used encryption algorithm can't be verified at this point. Kaspersky's analysts are analyzing it to find way to crack the encryption and restore files. Meanwhile, victims of latest Gpcode variant are suggested to attempt to restore their files using methods described here. Some victims have reported that the method does partially restore encrypted files.

Gpcode victims are instructed to contact Kaspersky on stopgpcode at kaspersky dot com and watch the blog space for new updates on the matter.

Friday, June 13, 2008

Gpcode Returns

Security company Kaspersky tells in its blog that there's been detected a new variant of Gpcode. Gpcode is a dangerous file-encryptor which encrypts a whole variety of user files, targeting files with extensions such as DOC, TXT, PDF, XLS, JPG, PNG, CPP, H. First version of Gpcode was seen in 2006.

Gpcode.ak, as Kaspersky calls it, encrypts files of infected machine using RSA encryption with public key coded in the malware itself. These encrypted files can only be decrypted by using private, 1024 bit key that in this case is in possession of the author or the owner of Gpcode. It's estimated that cracking that key would take 15 million modern computers running for about a year.

Kaspersky recommends to enable all possible anti-malware components that are installed in the system since it's unclear at the moment how the virus spreads.


If following picture appears on the screen then it's possible that system has gotten infected with Gpcode:


In those cases users are advised to keep their systems on and contact Kaspersky (stopgpcode@kaspersky.com) through clean system telling details about the infection: exact time and date that system got infected and what had been done during last 5 minutes before the infection (what programs were run, what web sites were visited etc).



To keep people up-to-date on the situation Kaspersky has set up dedicated forum.