All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 9 posts ] 
Author Message
 Post subject: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 5th, 2017, 21:10 
Offline

Joined: August 8th, 2007, 6:32
Posts: 1238
Location: inside ROM
Hi Guys

Is there any method in recovering files that have been encrypted by cryptolocker? (docs jpeg with .enc extensions)

thanks


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 6th, 2017, 3:19 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3455
Location: Greece
Hi
email me (or attach here) 2-3 encrypted files AND the ransom note and I'll let you know.
We've found solution for some variants.

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 6th, 2017, 3:24 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 15529
Location: Australia
Unlock systems infected by CryptoLocker :
http://www.hddoracle.com/viewtopic.php? ... 096&p=4987

Malwarebytes Anti-Ransomware Beta:
http://www.hddoracle.com/viewtopic.php? ... 553&p=8436

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 6th, 2017, 3:44 
Offline

Joined: August 8th, 2007, 6:32
Posts: 1238
Location: inside ROM
thank you guys

northwind check PM thanks

fzabkar, tried doesnt work, thank you.


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 6th, 2017, 4:31 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3455
Location: Greece
Got it, working on it, it has good chances. Will let you know :)

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 7th, 2017, 6:39 
Offline
User avatar

Joined: December 8th, 2013, 4:48
Posts: 831
Location: Pakistan
crypt0l0cker has a new variant.
for old variants you need a pair of files both encrypted and decrypted version and decrypted file should be at least 2mb to extract the key.

_________________
Data Recovery Pakistan


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 7th, 2017, 11:44 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3455
Location: Greece
We can do it.

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 7th, 2017, 11:55 
Offline
User avatar

Joined: April 3rd, 2011, 0:19
Posts: 2003
Location: Providence, RI
northwind wrote:
We can do it.


Very interesting. Is this a homebrew solution, or something commercially available?

_________________
Data Medics - Hard Drive, SSD, and RAID Data Recovery Service Company


Top
 Profile  
 
 Post subject: Re: Recovering encryted .enc files infected by CryptoLocker?
PostPosted: February 8th, 2017, 4:18 
Offline
User avatar

Joined: December 8th, 2013, 4:48
Posts: 831
Location: Pakistan
northwind wrote:
We can do it.

:good:

we can also do both old and new variant.

_________________
Data Recovery Pakistan


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 72 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group