All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog

 
Archive

<< 2010  
Jan Feb  
     
     
     
Virus Alert Danger Levels
Virus Alert Danger Levels

Wonder what the current virus alert means for your computer? Find out more about our Virus Alerts Threat Levels.

Free Removal Tools
Free Removal Tools

The Kaspersky Lab website removal tools section provides free utilities for removing dangerous viruses during an epidemic.

Antivirus Database Updates
Antivirus Database Updates

Kaspersky Anti-Virus users can always find the latest virus definitions in the database updates on the Kaspersky website.

 

  Home / Viruses / Alerts

Virus.Win32.Gpcode.ak

06.05.08 15:37 GMT , updated   06.07.08 15:04 GMT  |  comments (16)

Status : moderate risk

Kaspersky Lab has detected a new version of the ‘malicious blackmailer’ Gpcode - Virus.Win32.Gpcode.ak.

The new Gpcode variant encrypts files with extensions DOC, TXT, PDF, XLS, JPG, PNG, CPP, H etc. on hard drives using an RSA algorithm with a 1024-bit key.

After encrypting files, the virus leaves a text file in the folder next to the encrypted files with following message:

Your files are encrypted with RSA-1024 algorithm.
To recovery your files you need to buy our decryptor.
To buy decrypting tool contact us at: ********@yahoo.com

Currently, we detect the new variant, but we are unable to crack the 1024-bit key. Our analysts are continuing to work on both the key and the virus to resolve this issue.

Kaspersky Lab recommends that all Internet users enable maximum protection from malicious code and network attacks on their computers, refrain from executing suspicious programs received from untrustworthy sources and back up any important information on their computers.

Detection of Virus.Win32.Gpcode.ak was added to Kaspersky Anti-Virus signature databases yesterday, on June 4th, at 15:39 GMT. Please make sure to update if you haven’t already.

If you have fallen victim to Gpcode.ak, try to contact us using another computer connected to the Internet. DO NOT RESTART or POWER DOWN the potentially infected machine. Contact us by email stopgpcode@kaspersky.com and tell us the exact date and time of infection, as well everything you did on the computer in the 5 minutes before the machine was infected: which programs you have executed, which websites you have visited, etc. We'll try and help you recover any data that has been encrypted.

For more information about the malicious program, please read our weblog.

Related links
Analysis
Malicious code evolution: July – September 2007
Blackmailer: the story of Gpcode
Blog
New Gpcode - mostly hot air
Gpcode - here we go again
Another way of restoring files after a Gpcode attack
Gpcode update
Restoring files attacked by Gpcode.ak
Alerts
Virus.Win32.Gpcode.ag
Virus.Win32.GpCode.af
Virus.Win32.GpCode.ae
Virus.Win32.GPCode.ac
Virus.Win32.GPCode.f, .g, .h, .i
 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com