Jun 06

Virus.Win32.Gpcode.ak
06.05.08 14:37 GMT

Status : moderate risk
Kaspersky Lab has detected a new version of the ‘malicious blackmailer’ Gpcode — Virus.Win32.Gpcode.ak.

The new Gpcode variant encrypts files with extensions DOC, TXT, PDF, XLS, JPG, PNG, CPP, H etc. on hard drives using an RSA algorithm with a 1024-bit key.

After encrypting files, the virus leaves a text file in the folder next to the encrypted files with following message:
Your files are encrypted with RSA-1024 algorithm.
To recovery your files you need to buy our decryptor.
To buy decrypting tool contact us at: ********@yahoo.com

Currently, we detect the new variant, but we are unable to crack the 1024-bit key. Our analysts are continuing to work on both the key and the virus to resolve this issue.

We recommend that all Internet users enable maximum protection from malicious code and network attacks on their computers and refrain from executing suspicious programs received from untrustworthy sources.

Detection of Virus.Win32.Gpcode.ak was added to Shield Deluxe signature databases yesterday, on June 4th, at 15:39 GMT. Please make sure to update if you haven’t already.

Comments are closed.