1. /


Risk Level 1: Very Low

June 6, 2008
June 10, 2008 9:51:03 PM
Also Known As:
GPCoder.i [McAfee], W32/Gpcode.AK [F-Secure], TROJ_GPCODE.AD [Trend], PGPCoder.E [Panda Software]
Infection Length:
8,030 bytes
Systems Affected:
Windows 2000, Windows NT, Windows Server 2003, Windows XP
Trojan.Gpcoder.F is a Trojan horse that encrypts files and then prompts the user to purchase a decrypting tool to decrypt them.

Antivirus Protection Dates

  • Initial Rapid Release version June 6, 2008 revision 032
  • Latest Rapid Release version June 24, 2014 revision 006
  • Initial Daily Certified version June 6, 2008 revision 038
  • Latest Daily Certified version November 25, 2012 revision 006
  • Initial Weekly Certified release date June 11, 2008
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment


  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy


  • Damage Level: Low
  • Payload: Encrypts certain file types on the compromised computer.
  • Releases Confidential Info: May steal sensitive information.


  • Distribution Level: Low
Note: On May 14, 2015, modifications will be made to the threat write-ups to streamline the content. The Threat Assessment section will no longer be published as this section is no longer relevant to today's threat landscape. The Risk Level will continue to be the main threat risk assessment indicator.
Writeup By: Yana Liu
STAR Antimalware Protection Technologies
Internet Security Threat Report