Skip to main content

Kaspersky releases new tool for GPcode trojan victims

posted onJuly 1, 2008
by hitbsecnews

Anti-virus vendor Kaspersky has released StopGpcode2 – a tool which may be able to recover most of the data encrypted by the GPcode.ak trojan. According to the developers, the Windows program requires pairs of encrypted files and unencrypted copies of the same files – the more the merrier. These may be obtainable from backups or by using software such as PhotoRec that can reconstruct files deleted by the trojan from hard disk sectors.

The success rate is said to be up to 80 per cent, but is dependent on unspecified characteristics of the infected system. Affected users may be able to avoid having to buy the 'official' decryption tool offered by the blackmailers. Predecessors of the GPcode.ak trojan such as GPcode.ai and the earlier PGPcode.A could readily be cracked due to their weak encryption systems. The new version uses a hybrid of RC4 and RSA, however, which is taking cryptographers much longer to crack – the trojan creates an RC4 session key for each file from a randomly generated master key. It saves an RSA encrypted version of the master key on the infected system.

Source

Tags

Software-Programming

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th