All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 16 posts ] 
Author Message
 Post subject: Virus changed all files types and extension !!!!!!!!!!!!!
PostPosted: January 22nd, 2015, 7:00 
Offline

Joined: December 23rd, 2013, 9:56
Posts: 144
Location: Saudi Arabia
I have a windows 7 PC for one of my customers with strange problem

ALL Microsoft office files, PDf, pictures,...., almost all personal files

All files extention have changed from .doc to .DOC.jejfpoi and .pdf to .PDF.jejfpoi and so on

I tried to change the files back to original extention but still cannot open it (Microsoft office wont recognize it), I think it been encrypted ???

I did scan using (Symantec 360) but nothing found ???

I have attached 3 files for you to try fixing them.


Attachments:
scan0003.JPG.zip [3.95 MiB]
Downloaded 738 times
Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 7:49 
Offline

Joined: December 23rd, 2013, 9:56
Posts: 144
Location: Saudi Arabia
here is more files
3 docx
3 pdf


Attachments:
pdf.rar [9.52 MiB]
Downloaded 602 times
docx.rar [350.81 KiB]
Downloaded 501 times
Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 8:40 
Offline

Joined: November 24th, 2014, 4:42
Posts: 13
Location: Poland
First of all pleas don't use this kind of font, there is no need.

Second did your client use any antyvirus on his computer?? If no, I think that your client is victim of so called "ransomware". It is "worm/virus" that is encrypts data on drive not whole drive but single files. Then you see the information that if you want to decrypt data you must pay the ransom.

So there is two options first client pay the ransom, and second you try brute-force.

Regards


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 9:14 
Offline

Joined: December 23rd, 2013, 9:56
Posts: 144
Location: Saudi Arabia
samurai7 wrote:
First of all pleas don't use this kind of font, there is no need.

Second did your client use any antyvirus on his computer?? If no, I think that your client is victim of so called "ransomware". It is "worm/virus" that is encrypts data on drive not whole drive but single files. Then you see the information that if you want to decrypt data you must pay the ransom.

So there is two options first client pay the ransom, and second you try brute-force.

Regards


sorry for the font, it just too small i thing :shock:

if the clint pay the ransom ? will it be encrypted ? or he will just loose his money ?

i mean are they trusted after they receive there ransom, did it work before ??


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 9:47 
Offline

Joined: November 24th, 2014, 4:42
Posts: 13
Location: Poland
@LostDataSa

Honestly I don't know ;/ I only know how it works in theory, I never had a chance to check this in practice. And I hope I never will.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 10:28 
Offline

Joined: December 23rd, 2013, 9:56
Posts: 144
Location: Saudi Arabia
i followed the instruction on (Decrypt All Files jejfpoi.txt) which found everywhere on my Clint drive

they are asking for 630 USD

and they gave me the option to decrypt one file only :evil:

I have uploaded the encrypted and the decrypted files together in rar file

the question by comparing the encrypted and the original file, wil it be possible to find the encryption key :?:


Attachments:
compair.rar [15.33 KiB]
Downloaded 507 times
Decrypt All Files jejfpoi.txt [1.24 KiB]
Downloaded 805 times
Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 10:31 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
More than just extensions were altered. Likely a new variant of the encryption-ransom-wares going around. You used to be able to recover files from shadow copies but this is not often the case anymore. Most ransomware's give a short window to pay- paying only guarantees you wont have the money. These criminals may give you the key to decrypt- but sometimes don't as there is nothing you can do about it if you pay. I suggest no one ever pay- then this would stop.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 10:35 
Offline

Joined: December 23rd, 2013, 9:56
Posts: 144
Location: Saudi Arabia
warnerr wrote:
More than just extensions were altered. Likely a new variant of the encryption-ransom-wares going around. You used to be able to recover files from shadow copies but this is not often the case anymore. Most ransomware's give a short window to pay- paying only guarantees you wont have the money. These criminals may give you the key to decrypt- but sometimes don't as there is nothing you can do about it if you pay. I suggest no one ever pay- then this would stop.


I tried using r-studio

i found all the original files deleted but there are almost the same size and non of them working
also tried to repair the recovered files but no luck also

i am saying the only way is to decrypt these file or if we are able to find the key by comparing the encrypted file and the file was decrypted by the hacker website ( they gave me only one file to decrypt) :twisted:


Last edited by LostDataSa on January 22nd, 2015, 10:42, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 10:37 
Offline
User avatar

Joined: December 19th, 2006, 8:49
Posts: 11038
Location: Portugal
Hello.
I can't check now because i'm at work writting by mobile phone and don't have my tools with me.
What is the ransomware name ? It's on the ransom page.
Most likely i can compare the decrypted with encrypted file and get the key.
I will check when i arrive home.
How many files do you need to decrypt ?
Also, are you willing to outsource the job and pay for the decryption ?
I've done a cryptorbit ransomware recovery recently and was very successful. I've posted a thread about it sometime ago.
Some ransomware doesn't even actualy encrypt.
I will check properly when i arrive, on the meanwhile can you provide the ransomware name ?

_________________
1Q9xrDTzTddUXeJAFRn37aqh1Yr6buDCdw - (Bitcoin Donations)
paypal.me/Spildit - (PayPal Donations)
The HDD Oracle - Platform for OPEN research on Data Recovery.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 11:08 
Offline

Joined: December 23rd, 2013, 9:56
Posts: 144
Location: Saudi Arabia
here is another file that is also decrypted for comparing them


Attachments:
compair2.rar [1.71 KiB]
Downloaded 460 times
Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 11:13 
Offline
User avatar

Joined: December 19th, 2006, 8:49
Posts: 11038
Location: Portugal
Needless to say you should first of all plug the client drive on your system and clean it with your AV tools, or run an off-line bootable cleaner like avira rescue cd and make sure the client computer gets clean otherwise the files will end up re-encrypted.

When you scan the encrypted files with AV it will not display any infection because they are just encrypted or messed up files. The true executable code doing the encryption might still be on the system and can as well be rooted (rootkit) so make sure to run multi av tools against the drive but running them from a clean system with the drive attached to it but not booting from it.
I will check your files later today.

_________________
1Q9xrDTzTddUXeJAFRn37aqh1Yr6buDCdw - (Bitcoin Donations)
paypal.me/Spildit - (PayPal Donations)
The HDD Oracle - Platform for OPEN research on Data Recovery.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 14:49 
Offline
User avatar

Joined: December 19th, 2006, 8:49
Posts: 11038
Location: Portugal
Ok, i've just arrived home.

The files are encryped with CTB Locker virus.
I will post more info in a moment.

_________________
1Q9xrDTzTddUXeJAFRn37aqh1Yr6buDCdw - (Bitcoin Donations)
paypal.me/Spildit - (PayPal Donations)
The HDD Oracle - Platform for OPEN research on Data Recovery.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 22nd, 2015, 14:57 
Offline
User avatar

Joined: December 19th, 2006, 8:49
Posts: 11038
Location: Portugal
BAD LUCK :

Is it possible to decrypt files encrypted by CTB Locker?

Quote:
Unfortunately at this time there is no way to retrieve the private key that can be used to decrypt your files without paying the ransom on the CTB Locker Site. Brute forcing the decryption key is not realistic due to the length of time required to break this type of cryptography. Also any decryption tools that have been released by various companies for other malware will not work with this infection. The only methods you have of restoring your files is from a backup, file recovery tools, or if your lucky from Shadow Volume Copies.


http://www.bleepingcomputer.com/virus-r ... nformation

_________________
1Q9xrDTzTddUXeJAFRn37aqh1Yr6buDCdw - (Bitcoin Donations)
paypal.me/Spildit - (PayPal Donations)
The HDD Oracle - Platform for OPEN research on Data Recovery.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 23rd, 2015, 6:43 
Offline
User avatar

Joined: August 13th, 2008, 13:10
Posts: 815
Location: World
LostDataSa wrote:
i followed the instruction on (Decrypt All Files jejfpoi.txt) which found everywhere on my Clint drive

they are asking for 630 USD

and they gave me the option to decrypt one file only :evil:

I have uploaded the encrypted and the decrypted files together in rar file

the question by comparing the encrypted and the original file, wil it be possible to find the encryption key :?:



I do not recommend you pay the extortionist, because it encourages this bad people keep doing the same.

Also I know cases after paying the amount of 3000 eur. customer have not received any key or mode to get data.


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 23rd, 2015, 8:14 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3779
Location: Adelaide, Australia
I don't agree with your theory that paying will encourage them and not paying will discourage them. They will keep doing this because it works. many people pay.

I do agree to not pay them though.. as good Will Hunting said quite eloquently... " Because Fuck them, that's why".

paying them is no guarantee they will give any key or decrypt your files. The best thing you can do is prevent it. Don't leave network drives mapped unnecessarily, don't leave backup drives connected, don't overwrite your backups too quickly.

maybe try some new technology. Recently Palo Alto bought Cyvera. They are developing some really interesting endpoint protection. Basically there are around 20 techniques most malware uses and these guys are researching each one and writing defence for each. listen to the latest Risky Business podcast for an interview with the CTO of PAN http://risky.biz/RB350 , or download and try it https://www.paloaltonetworks.com/products/endpoint-security.html


Top
 Profile  
 
 Post subject: Re: Virus changed all files types and extension !!!!!!!!!!!!
PostPosted: January 15th, 2016, 9:02 
Offline

Joined: January 15th, 2016, 8:44
Posts: 1
Location: Tbilisi
Hello Spildit,

As i am new to this forum, i could not compose new post. but i am trying from here if you get , it would be helpful
Friend of mine has seems to be same problem , seem his work pc been infected by ransomware and , he send me this photo file to check if i could recover this file.
Could you please have a look to this photo file and tell me the details of infection and solution to this problem.
bunch of thanks with big hearth.

Regards
Digu


Attachments:
17115_910526755677816_1016787013723012869_n.jpg.zip [61.22 KiB]
Downloaded 389 times
Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 16 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google Adsense [Bot] and 59 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group