Hacker
A new virus encrypts data and demands money for the key

Ransomware virus uses 1,024-bit key

Give us your money or the data gets it

Written by Iain Thomson

Security specialists are warning of a new virus that encrypts data on infected machines and demands money for the decryption key.

'Gpcode' is thought to access PCs via unpatched browsers. Once active it encodes most of the data on the computer, including .doc, .txt, .pdf, .xls, .jpg and .png files, with a 1,024-bit key.

Advertisement

Once all the files have been encrypted a ReadMe file is left on the machine giving an email address to send money in order to get the decryption key.

The malware is a revision of a previous virus, thought to be from the same author, which appeared two years ago but only used a 660-bit key.

"Virus researchers have been able to crack keys up to 660 bits," said Timur Tsoriev of Kaspersky Labs.

"This was the result of a detailed analysis of the RSA algorithm implementation. If the encryption algorithm is implemented correctly, it could take one PC with a 2.2GHz processor around 30 years to crack a 660-bit key."

We urge infected users not to yield to the blackmailer

Timur Tsoriev Kaspersky Labs

The company has urged users struck by the virus not to reboot or shut down the infected machine.

Instead they should get in contact immediately with the last few websites they visited to determine what, if any, programs were running.

"We urge infected users not to yield to the blackmailer, but to contact us and your local cyber-crime law enforcement units," said Tsoriev. "Yielding to blackmailers only continues the cycle."

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Microsoft

Microsoft plans Silverlight 2.0 announcement

Web application tool revamp promised later today   More...

Stock prices

Security disclosures tip the stock market

Events such as Microsoft's Patch Tuesday could be used for...  More...

Blogs

Analyst predicts Web 2.0 fire sale

Prices for online apps could soon plummet, says Forrester   More...

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Primary Navigation