Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Kaspersky creates file restoration utility for ransomware victims

  • Email a Friend
  • Print Page
By Dan Kaplan
Jun 17, 2008 9:55 AM
Tags: "kaspersky" | "gpcode" | "1024 | encryption"
Kaspersky Lab announced Monday it has created a free utility to restore files that may have been deleted by a new ransomware variant known as Gpcode.

The downloadable executable "restores original filenames and the full paths of the files recovered," according to the Russian-based anti-virus firm.

Kaspersky was the first to identify earlier this month a new and improved variant of the blackmailing Gpcode trojan.

Researchers admit it will be difficult to create a signature for the dangerous malware, which uses virtually uncrackable 1,024-bit encryption. If infected, a user's files -- including MP3s, photos and Word documents -- are encrypted and the original files deleted.

The only way the victim can regain access to the files is if he or she agrees to pay a fee, which is demanded in a pop-up message, Kaspersky researchers have said.

File-recovery software is the best remedy right now, researchers said. The Kaspersky utility leverages the free PhotoRec utility, but adds the ability to restore exact file names and pathways.

Experts first spotted Gpcode about three years ago, when the author used 660-bit encryption to hold victim's files -- including MP3s, photos, documents -- hostage until the user paid up, experts said. That version of the trojan was eventually cracked.

While the new utility is free, Kaspersky is asking victims to consider donating to the PhotoRec creators, who include Christophe Grenier.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers