R E L A T E D   C O N T E N T
ADVERTISEMENT

Solution for Archiveus ransom virus

Extortionist leaves vital clue in plain sight

Tim Smith, Computeract!ve 02 Jun 2006
ADVERTISEMENT

A virus that locks users out from the files in their My Documents folder has been cracked.

The Archiveus virus (or more accurately a Trojan ) merges all the files in the My Documents folder into one big password protected file. The original files are then deleted and a text document is created with instructions for recovering the files.

Rather than demand money to return the files the instructions demand that the user goes to an online pharmacy and make an order.

To return the files the user must double click on a file called Demo.als, which will prompt for a password. The password is mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw

Alternatively the following password works if the EncryptedFiles.als is run instead. The password for this is mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw .

The instructions for removal from the security company Sophos warn users not to delete the virus files before entering the password and recovering the files.
Despite claims by the virus that it has encrypted the files, they are merely joined together. For most users the effect is much the same though and the files are inaccessible.

Security site Lurhq claims that the password was actually present in the program file so it was not difficult to find even with "beginner-level reverse-engineering".

One of the email addresses used by the virus is a Yahoo address. We have contacted Yahoo to ask if it is looking into this matter.

Archiveus is not the first virus to try and extort money from users.

See also:

Anti-virus firm F-Secure to issue 1.6m software licences  26 May 2006
Soccer virus hits the back of the net  08 May 2006
The number of emails carrying viruses has plummeted to fewer than one per cent of all messages sentBut phishing attacks soar  04 May 2006

All Antivirus and Firewall Protection

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
Our noteworthy client in the South West requires a C#.NET Developer to help develop and rewrite their Finance Systems interfaces. The ideal candidate will be available immediately and be a strong developer using C#.NET. You ... more >
| JAM Recruitment
Job Reference: 21307 Job Title: Project Manager (HR amp; Payroll technology transformation? Do you have Project Management experience gained within client facing projects? Are you a forward thinking professional, comfortable with people management? The Background ... more >
| JAM Recruitment
Position: HRIS Specialist Reference: 21191 Salary: c£40-50k + Excellent Benefits Location: West Midlands Contact: Chris Pearson - JAM HR Systems Are you a techno-functional professional with a background in developing and driving HR Information Systems? ... more >
| JAM Recruitment
Position: EMEA HR Systems Manager Reference: 21014 Salary: c£55-65,000 + Bonus + Benefits Location: North London Contact: Chris Pearson - JAM HR Systems Are you a proven HR technology leader with aptitude to drive international ... more >
More job opportunities