Home Malware Programs Trojans Gpcoder.d

Gpcoder.d

Posted: March 28, 2006

Gpcoder.d is a trojan that searches the infected computer for files of predefined formats and encrypts them. The list of file formats includes text documents , spreadsheets , web pages , archives , applicationming projects , databases, password files and files of other types. Once Gpcoder.d encrypts a file, it creates a text document in a folder containing that file. This document explains the situation and demands to buy a decoder tool in order to decrypt encrypted files. Gpcoder.d runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 autosave.sin

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftSysinfcur_not_doneHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun[filename]
Loading...