Solutions Buy Download Information Partners Support Forum About us «Doctor Web» company news (RSS channel)

Dr.Web Anti-virus disinfects the new variant of Trojan.Encoder

June 1, 2006

Virus monitoring service of Doctor Web, Ltd. informs all users on new modification of Trojan. Encoder (see our first <"http://info.drweb.com/show/2747/en">news about it.) detected by Dr.Web Anti-virus as Trojan.Encoder.6.

Several variants of this Trojan program are detected at present. Different from previous versions, the Trojan’s author uses much longer encryption keys of 260 bits, which makes the process of decoding much more difficult.

All versions of this Trojan program are distributed via e-mail as spam and a careless user may run the attachment and become a victim of the blackmailer - all document files of the invaded computer get encrypted. The user is offered to buy a decryptor; for this he should contact an unknown blackmailer via e-mail. After the Trojan has encrypted files, a readme.txt file of the following content appears in each folder:



Some files are coded by RSA method.
To buy decoder mail: k47674@mail.ru
with subject: REPLY

At present, virus analytics of Doctor Web, Ltd. have managed to find one of the keys used by the felon for crypting the documents of the victimized computer. The curing decoding utility is soon to be released.

Meanwhile, the preventive measures are recommended by Doctor Web, Ltd. to keep safe from viruses – both for those who has an anti-virus program installed and for those who do not have any:

  • Use only a legal anti-virus software – only in this case you will receive hot add-ons to virus database.
  • Keep abreast of updates.
  • Never open attachments arrived in suspicious e-mail messages or from unknown contacts
  • Do not work under administrator account if you do not have any anti-virus program installed
  • If you have a suspicion that your computer is infected, and you do not have any anti-virus installed, check your computer with FREE curing scanner - Dr.Web CureIt!. This utility will not only check the computer, but in most cases will cure remove the infection - not only viruses, but also spyware, adware, hacker tools and paid dialers.



  •      Other news

    2008-05-13April 2008 virus activity review from Doctor Web, Ltd.
    2008-05-13Twenty five thousand subscribers of Eltel get protection by Dr.Web AV-Desk™
    2008-05-07Dr.Web AV-Desk shields four hundred educational institutions of the Russian university network RUNNet
    2008-05-06New version of Dr.Web anti-virus scanner for Windows released
    2008-05-06Win32.Ntldrbot (aka Rustock.C) no longer a myth, no longer a threat. New Dr.Web scanner detects and cures it for real
    2008-05-05Another 17 Russian cities get anti-virus as a service with Dr.Web AV-Desk
    2008-05-04Protection against viruses and spam from Doctor Web, Ltd. and Sun Microsystems thoroughly tested
    2008-05-04Another Russian ISP launches Dr.Web AV-Desk
    2008-05-02Doctor Web – Central Asia Kazakhstan market summary 2007
    2008-05-02Doctor Web came to China at the eve of Olympics
    2008-04-08PC Magazine Russia: Dr.Web AV-Desk – the best product-as-a-service of 2007
    2008-04-07Dr.Web for IBM Lotus Domino – a new product by Doctor Web, Ltd. protecting application servers of enterprises and corporations
    2008-04-03Updated Dr.Web Shell Extension library released
    2008-04-03Dr.Web for Unix Mail servers and Dr.Web Mail Gateway have been updated to version 4.44.1
    2008-04-02March 2008 virus activity review from Doctor Web, Ltd.
    2008-04-01Updated version of Dr.Web Enterprise Suite 4.44.2 released
    2008-04-01Dr.Web scanner vanquishes BackDoor.MaosBoot once again
    2008-04-01Updated modules of Dr.Web anti-virus for Windows workstations released

       Information



       My five cents
     
    What is the screen size of your monitor?

    12''
    14''
    15''
    17''
    19''
    more than 19''
    other



    Doctor Web, Ltd. © 2008 Doctor Web, Ltd. - a Russian company developing and distributing Dr.Web® Anti-virus solutions.
    Our customers can be found among home users from all regions of the world and in large enterprises, small companies and nationwide corporations. We thank all of them for support and long-term devotion to our product. State certificates and awards received by the Dr.Web Anti-virus, as well as the geography of our users are the best evidence of exceptional trust to the products created by the talented Russian programmers.