Simple clear advice in plain English

Solution for Archiveus ransom virus

Extortionist leaves vital clue in plain sight

A virus that locks users out from the files in their My Documents folder has been cracked.

The Archiveus virus (or more accurately a Trojan ) merges all the files in the My Documents folder into one big password protected file. The original files are then deleted and a text document is created with instructions for recovering the files.

Rather than demand money to return the files the instructions demand that the user goes to an online pharmacy and make an order.

To return the files the user must double click on a file called Demo.als, which will prompt for a password. The password is mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw

Alternatively the following password works if the EncryptedFiles.als is run instead. The password for this is mf2lro8sw03ufvnsq034jfowr18f3cszc20vmw .

The instructions for removal from the security company Sophos warn users not to delete the virus files before entering the password and recovering the files.
Despite claims by the virus that it has encrypted the files, they are merely joined together. For most users the effect is much the same though and the files are inaccessible.

Security site Lurhq claims that the password was actually present in the program file so it was not difficult to find even with "beginner-level reverse-engineering".

One of the email addresses used by the virus is a Yahoo address. We have contacted Yahoo to ask if it is looking into this matter.

Archiveus is not the first virus to try and extort money from users.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Fantasy football virus spreads using Excel files

Soccer virus hits the back of the net

BT offers free online storage space

Digital vault for precious memories

Text messages lure people to internet to download Trojan

SMS offers a date with destiny you don't want

Question & Answer

Q.Why are some of the keys on my keyboard doing strange...

> Read the answer

Q.Is my phone’s Bluetooth any use?

> Read the answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Best deals on the web

img

Apple iMac 21.5" (MC309)

£926.40- Buy it now

img

Dell Inspiron 620 ST Intel Core i3-2100 3.10GHz / 3GB / 500GB / DVDRW / Win 7 Home Premium

£329.00- Buy it now

img

ZooStorm 7877-1023

£386.38- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

Virtual drive

A set of files seen by Windows as a separate hard disk.

Great shopping deals from Computeractive