Newsletter:

Skip Navigation LinksHome > News > Security > Ransomware virus uses 1,024-bit key

Ransomware virus uses 1,024-bit key

By Iain Thomson
7 June 2008 11:42AM
Tags: ransomware | virus | uses | 024bit | key

Security specialists are warning of a new virus that encrypts data on infected machines and demands money for the decryption key..

'Gpcode' is thought to access PCs via unpatched browsers. Once active it encodes most of the data on the computer, including .doc, .txt, .pdf, .xls, .jpg and .png files, with a 1,024-bit key.

Once all the files have been encrypted a ReadMe file is left on the machine giving an email address to send money in order to get the decryption key.

The malware is a revision of a previous virus, thought to be from the same author, which appeared two years ago but only used a 660-bit key.

"Virus researchers have been able to crack keys up to 660 bits," said Timur Tsoriev of Kaspersky Labs.

"This was the result of a detailed analysis of the RSA algorithm implementation. If the encryption algorithm is implemented correctly, it could take one PC with a 2.2GHz processor around 30 years to crack a 660-bit key."

The company has urged users struck by the virus not to reboot or shut down the infected machine.

Instead they should get in contact immediately with the last few websites they visited to determine what, if any, programs were running.

"We urge infected users not to yield to the blackmailer, but to contact us and your local cyber-crime law enforcement units," said Tsoriev. "Yielding to blackmailers only continues the cycle."

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6667) -  internet
(6421) -  iinet
(6396) -  copyright
(6396) -  afact
(5993) -  servers
(5993) -  mipi
(4832) -  telstra
(4512) -  broadband
(4459) -  nbn
(2985) -  internode
(2520) -  microsoft
(1888) -  network
(1462) -  data
(1461) -  software
(1369) -  google