Frenchmen claim cure for WannaCry-infected computers

cyber attack
Credit: CC0 Public Domain

French researchers have released software tools that they claim can restore some of the computers locked up by a global cyberattack that held users' files for ransom.

The researchers said, however, that the tools are not perfect and only if the computers infected with the WannaCry ransomware have not been rebooted after being hit. For that reason, the technique isn't likely to help many people. In addition, companies needing to restore their operations right away likely would have turned to backups, if available, by now.

The developments came Friday, the apparent deadline for owners of some to pay a ransom of up to $600 or lose their files forever. As of Friday, the three accounts known to collect ransom payments had received less than $100,000 worth of the cybercurrency bitcoin, an amount that security researchers say is small compared with how widely WannaCry spread.

The researchers—Adrien Guinet, Matthieu Suiche and Benjamin Delpy—worked separately to find ways to decrypt files scrambled and held hostage by WannaCry.

In his research summary, Guinet—who works for the Paris-based firm Quarkslab—said his software had only been tested to work under Windows XP. He added the software helps recover the prime numbers of the RSA private key that are used by WannaCry.

After Guinet's fix came out, others looked for ways to extend that to other operating systems and have succeeded in applying the technique to the newer Windows 7 system as well.

Chris Wysopal, with the security company Veracode, said that after ransomware attacks, researchers will often infect one of their own machines on purpose to see if the key is somehow left in the memory. That happened here with some systems of Windows.


Explore further

Explainer: What is ransomware?

More information: blog.comae.io/wannacry-decrypt … wi-demo-86bafb81112d

© 2017 The Associated Press. All rights reserved.

Citation: Frenchmen claim cure for WannaCry-infected computers (2017, May 19) retrieved 23 April 2019 from https://phys.org/news/2017-05-frenchmen-wannacry-infected.html
This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no part may be reproduced without the written permission. The content is provided for information purposes only.
223 shares

Feedback to editors

User comments

May 19, 2017
My friend Arthur says to tell the French men that we've already got one...

May 19, 2017
This only works if the machine hasn't been rebooted. It's been a week...
I suppose it was a worthwhile exercise, the technique might help in the future.
@TrollBane, your father smelt of elderberries!

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more