Ransomware virus
Moderator: Rathinagiri
- vagblad
- Posts: 174
- Joined: Tue Jun 18, 2013 12:18 pm
- DBs Used: MySQL,DBF
- Location: Thessaloniki, Greece
Ransomware virus
Hello all,
Yesterday my main PC got hacked, from a Cryptowall - like trojan. They encrypted all of my files and now they are asking me to pay them 4 bitcoins to send me the key and the decrypt tool so i can unlock my files.
Unfortunately i don't have everything on backup and the files are crucial for my work. I searched a lot in the internet and apparently this kind of encryption is unbreakable at the moment. You either pay and pray for the hackers to give you the key or you say goodbye to your files. The virus has infected *.doc, *.prg, *.pdf, *.dbf files and many others.
My question is: Has any of you guys had a similar incident? Do the hackers actually send the decrypt tool after getting paid? Another problem is i cannot safely discover what kind of encryption there is on my files? How can i be sure it's a Cryptowall variant using RSA-2048 encryption and not a fake using some other kind? I read about stories were the encryption algorithm was simple XOR.
Thanks in advance.
Best Regards
Yesterday my main PC got hacked, from a Cryptowall - like trojan. They encrypted all of my files and now they are asking me to pay them 4 bitcoins to send me the key and the decrypt tool so i can unlock my files.
Unfortunately i don't have everything on backup and the files are crucial for my work. I searched a lot in the internet and apparently this kind of encryption is unbreakable at the moment. You either pay and pray for the hackers to give you the key or you say goodbye to your files. The virus has infected *.doc, *.prg, *.pdf, *.dbf files and many others.
My question is: Has any of you guys had a similar incident? Do the hackers actually send the decrypt tool after getting paid? Another problem is i cannot safely discover what kind of encryption there is on my files? How can i be sure it's a Cryptowall variant using RSA-2048 encryption and not a fake using some other kind? I read about stories were the encryption algorithm was simple XOR.
Thanks in advance.
Best Regards
Vagelis Prodromidis
Email: vagblad@gmail.com, Skype: vagblad
Email: vagblad@gmail.com, Skype: vagblad
- Rathinagiri
- Posts: 5482
- Joined: Tue Jul 29, 2008 6:30 pm
- DBs Used: MariaDB, SQLite, SQLCipher and MySQL
- Location: Sivakasi, India
- Contact:
Re: Ransomware virus
Oh My GOD!
It looks very bad.
From the info from web, these files are encrypted using Private keys. It is virtually unbreakable.
It looks very bad.
From the info from web, these files are encrypted using Private keys. It is virtually unbreakable.
East or West HMG is the Best.
South or North HMG is worth.
...the possibilities are endless.
South or North HMG is worth.
...the possibilities are endless.
Re: Ransomware virus
One of my clients had the same problem. Only backup can help 
Re: Ransomware virus
Some time ago I had a problem like this and several files are riusciuto to recover.
try to see this guide
http://aiuto-pc.forumfree.it/?t=70654641
good luck
try to see this guide
http://aiuto-pc.forumfree.it/?t=70654641
good luck
- vagblad
- Posts: 174
- Joined: Tue Jun 18, 2013 12:18 pm
- DBs Used: MySQL,DBF
- Location: Thessaloniki, Greece
Re: Ransomware virus
Thanks emzampi.
Unfortunately this is a brand new version of the Crypto-wall virus.It also deletes all the shadow copies from the disk.
It also corrupts all the drives in the system(external etc) plus all the network drives which were mapped. It's a disaster.
I managed to get some files back by using Recuva Prop(recovers deleted files) but only a small part of my work.
I talked with the people from Dr.Web antivirus, send them a copy of an infected file and an original(un-infected) version of that. They said that they couldn't decrypt it.
Also i am talking with some people at the bleeping computers forum.It's a forum specialised in malware.Everyone seems to say that this is a new stronger version of the virus.
I am going to pay them tomorrow hoping that they will actually send me the decrypt tool. I send them a file today and asked them to decrypt it as a proof that they can do it. They did it and send it back.
I will inform you of the outcome.
Just wanted to say to everyone, do backups in the cloud or in an external hard drive and then unplug it.I hope my story here will help others to start backing up regularly!
Best Regards
Unfortunately this is a brand new version of the Crypto-wall virus.It also deletes all the shadow copies from the disk.
It also corrupts all the drives in the system(external etc) plus all the network drives which were mapped. It's a disaster.
I managed to get some files back by using Recuva Prop(recovers deleted files) but only a small part of my work.
I talked with the people from Dr.Web antivirus, send them a copy of an infected file and an original(un-infected) version of that. They said that they couldn't decrypt it.
Also i am talking with some people at the bleeping computers forum.It's a forum specialised in malware.Everyone seems to say that this is a new stronger version of the virus.
I am going to pay them tomorrow hoping that they will actually send me the decrypt tool. I send them a file today and asked them to decrypt it as a proof that they can do it. They did it and send it back.
I will inform you of the outcome.
Just wanted to say to everyone, do backups in the cloud or in an external hard drive and then unplug it.I hope my story here will help others to start backing up regularly!
Best Regards
Vagelis Prodromidis
Email: vagblad@gmail.com, Skype: vagblad
Email: vagblad@gmail.com, Skype: vagblad
- Rathinagiri
- Posts: 5482
- Joined: Tue Jul 29, 2008 6:30 pm
- DBs Used: MariaDB, SQLite, SQLCipher and MySQL
- Location: Sivakasi, India
- Contact:
Re: Ransomware virus
It is really sad to go our hard work in vein and that too by the criminals. 
East or West HMG is the Best.
South or North HMG is worth.
...the possibilities are endless.
South or North HMG is worth.
...the possibilities are endless.
Re: Ransomware virus
Hi all
yesterday a customer have the same problem
i'm writing on this configuration, windows 7 pro 64, but probably could work with vista or above
probably could be a solution, not perfect, but verified on the field.
first you have to clean all your hard drive, with classical methods, scan with kaspersky rescue distro, than tdsskiller, rkill, jrt, combofix, adwcleaner,panda cloud cleaner, malwarebytes
second put all your cryptofiles in a folder
third ( this is the utility that can save your data... ) use shadow explorer portable
this is the link http://www.shadowexplorer.com/
good luck
Domenico
yesterday a customer have the same problem
i'm writing on this configuration, windows 7 pro 64, but probably could work with vista or above
probably could be a solution, not perfect, but verified on the field.
first you have to clean all your hard drive, with classical methods, scan with kaspersky rescue distro, than tdsskiller, rkill, jrt, combofix, adwcleaner,panda cloud cleaner, malwarebytes
second put all your cryptofiles in a folder
third ( this is the utility that can save your data... ) use shadow explorer portable
this is the link http://www.shadowexplorer.com/
good luck
Domenico
- serge_girard
- Posts: 3420
- Joined: Sun Nov 25, 2012 2:44 pm
- DBs Used: 1 MySQL - MariaDB
2 DBF - Location: Belgium
- Contact:
Re: Ransomware virus
NEWS AGGIORNAMENTO GENNAIO 2016
Ransom TESLACRYPT(estensione dei files .xxx .ttt .micro)
Al momento non è possibile una soluzione per la decriptazione dei files
AGGIORNAMENTO DICEMBRE 2015
Ransom TESLACRYPT(estensione dei file .vvv .ccc .abc .aaa .ecc .exx .ezz .zzz )
http://aiuto-pc.forumfree.it/?t=70654641
Ransom TESLACRYPT(estensione dei files .xxx .ttt .micro)
Al momento non è possibile una soluzione per la decriptazione dei files
AGGIORNAMENTO DICEMBRE 2015
Ransom TESLACRYPT(estensione dei file .vvv .ccc .abc .aaa .ecc .exx .ezz .zzz )
http://aiuto-pc.forumfree.it/?t=70654641