Follow Us

Kaspersky finds workaround for crypto virus

But there's a catch...

Kaspersky Lab has published advice on recovering files encrypted by the frightening Gpcode.ak virus, but there is a big catch – users must not have turned off their PC first.

A new variant of the malware struck last week, scrambling a variety of files on victims’ PCs using a very strong 1,024-bit RSA encryption key that has so far confounded attempts to crack it. Its creators demand a ransom for the unlock key.

While victims of the malware will be grateful to have any method to recover files, this technique is fraught with problems for the non-technical. Ideally, users need to have a second – and therefore clean - computer with which to download a GPL-licensed utility, Photorec, to start the process.

The biggest barrier of all, however, is that users must employ the file recovery utility without having turned off or rebooted their PC after the infection was first noticed, a fact that will probably reduce the number of people able to use the method to low percentages.

A reboot tends to be the first thing users try when hit by malware, but this risks changing the data on the hard disk, overwriting areas used to store the original files at the point the they were encrypted by Gpcode.ak – that these files still exist on the hard drive is the small oversight by the virus writers that has made the recovery possible in the first place.

Although Photorec is reported to be able to recover files successfully under these conditions, users need to use a separate utility from Kaspersky to relate those files to their real filenames and original directory structure. All in all, the method adds up to a pretty steep crash course in the technical side of a Windows PC.

Meanwhile, a full cure for Gpcode appears no nearer, with Kaspersky admitting it still hasn’t discovered the key with which to unlock files the easy way. But even if the company managed to recover the key, there is nothing to stop the attackers releasing a variant using a new key.

As serious as Gpcode.ak has become – it is effectively a sort of encryption zero day attack for which there is no patch – Kaspersky’s approach has come in for criticism from security researcherDancho Danchev, who has accused the company of mining worry over the malware as a marketing tool. If that’s a valid criticism, then Kaspersky is far from the first to employ such tactics. The whole security alerts business is built on the same premise.

Ordinary users affected by Gpcode, if indeed there are many of those, will simply be happy to have at least one method that offers hope of recovering their files without having to give in to the criminals and pay the ransom demanded.

See recent feature: Ransomware - frightening but thankfully rare






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *