Simple clear advice in plain English

Solution for Archiveus ransom virus

Extortionist leaves vital clue in plain sight

A virus that locks users out from the files in their My Documents folder has been cracked.

The Archiveus virus (or more accurately a Trojan ) merges all the files in the My Documents folder into one big password protected file. The original files are then deleted and a text document is created with instructions for recovering the files.

Rather than demand money to return the files the instructions demand that the user goes to an online pharmacy and make an order.

To return the files the user must double click on a file called Demo.als, which will prompt for a password. The password is mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw

Alternatively the following password works if the EncryptedFiles.als is run instead. The password for this is mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw .

The instructions for removal from the security company Sophos warn users not to delete the virus files before entering the password and recovering the files.
Despite claims by the virus that it has encrypted the files, they are merely joined together. For most users the effect is much the same though and the files are inaccessible.

Security site Lurhq claims that the password was actually present in the program file so it was not difficult to find even with "beginner-level reverse-engineering".

One of the email addresses used by the virus is a Yahoo address. We have contacted Yahoo to ask if it is looking into this matter.

Archiveus is not the first virus to try and extort money from users.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Fantasy football virus spreads using Excel files

Soccer virus hits the back of the net

BT offers free online storage space

Digital vault for precious memories

Text messages lure people to internet to download Trojan

SMS offers a date with destiny you don't want

Question & Answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Q.How do I stop Windows 7 search?

> Read the answer

Best deals on the web

img

Apple MacBook Pro (MC724LL/A)

£999.99- Buy it now

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

img

Samsung 300E5A-A01DX

£449.99- Buy it now

Great benefits for subscribers!

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

GIF

Grahics Interchange Format. A type of image file often used on the web, but now largely superseded by...

Great shopping deals from Computeractive