Kaspersky Lab Warns of New Ransomware Virus

Kaspersky Lab warns of a new variant of the Gpcode ransomware virus called Virus.Win32.Gpcode.ak.

Archive notice: This article was originally published on June 6, 2008. Links and embedded videos are preserved as part of the historical record.

The new Gpcode encrypts files on hard drives, including those with the extensions DOC, TXT, PDF, XLS, JPG, PNG and CPP, using the RSA algorithm with a 1,024-bit key.

After encrypting the files, it leaves the following message:

Your files are encrypted with RSA-1024 algorithm.

To recovery your files you need to buy our decryptor.

To buy decrypting tool contact us at: ********@yahoo.com

Kaspersky Lab detects the malware itself. At present, however, there is no known way to recover data encrypted by the virus after the event without complying with the extortionist’s demand.

Kaspersky Lab therefore recommends that all internet users take every possible measure to protect their computers against malicious code and ensure their security software is up to date. Virus.Win32.Gpcode.ak was added to Kaspersky Lab’s virus database on the evening of June 4, 2008. Users with current Kaspersky Lab antivirus protection are therefore protected against infection.

If you are affected by the virus, do not restart or switch off your computer. Using an uninfected computer, contact stopgpcode@kaspersky.com and provide the following information:

• Date and time of infection

• Programs run during the five minutes before infection

• Websites visited during the same period.

Kaspersky Lab’s analysts will contact you and attempt to assist with data recovery.

Further information is available through the following links:

  • Virus list
    Blog post