Threat level 1
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service.
Threat level 2
The Internet threat alert status is currently raised. At present, a malicious mass mailing or malware sample with previously unknown functionality has been detected.
Threat level 3
The Internet threat alert status is currently high. At present, there is a significant rise in reports of malware that exploits a critical vulnerability in the Windows operating system.
Threat level 4
The Internet threat alert status is currently critical. At present, malware levels are extremely high. Internet usage may be severely disrupted as the epidemic spreads.
06.05.08 14:37 GMT, updated
06.07.08 14:04 GMT
Status : moderate risk
The new Gpcode variant encrypts files with extensions DOC, TXT, PDF, XLS, JPG, PNG, CPP, H etc. on hard drives using an RSA algorithm with a 1024-bit key.
After encrypting files, the virus leaves a text file in the folder next to the encrypted files with following message:
Currently, we detect the new variant, but we are unable to crack the 1024-bit key. Our analysts are continuing to work on both the key and the virus to resolve this issue.
Kaspersky Lab recommends that all Internet users enable maximum protection from malicious code and network attacks on their computers, refrain from executing suspicious programs received from untrustworthy sources and back up any important information on their computers.
Detection of Virus.Win32.Gpcode.ak was added to Kaspersky Anti-Virus signature databases yesterday, on June 4th, at 15:39 GMT. Please make sure to update if you haven’t already.
If you have fallen victim to Gpcode.ak, try to contact us using another computer connected to the Internet. DO NOT RESTART or POWER DOWN the potentially infected machine. Contact us by email stopgpcode@kaspersky.com and tell us the exact date and time of infection, as well everything you did on the computer in the 5 minutes before the machine was infected: which programs you have executed, which websites you have visited, etc. We'll try and help you recover any data that has been encrypted.
For more information about the malicious program, please read our weblog.
Links
Analysis
Weblog
Alerts