All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 13 posts ] 
Author Message
 Post subject: File extension changed
PostPosted: January 30th, 2015, 14:17 
Offline

Joined: July 20th, 2011, 9:02
Posts: 91
Hello ,

All excel/word/zip/pdf are changed as following
Doc1.DOCX.tvmpzfh
Eng..PDF.tvmpzfh
Expenses.XLSX.tvmpzfh

i tried changing extension but no use .File size seems ok like 1.2 MB .

Is this cryptowall virus? i tried uploading file to https://www.decryptcryptolocker.com/ but saying no encrypted file.
In pc3000 raw recovery dont show these files.

Any one faced similar issue or any solution

Thanks in advance


Attachments:
Eng..PDF.zip [2.34 MiB]
Downloaded 355 times
Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: January 30th, 2015, 15:05 
Offline
User avatar

Joined: February 13th, 2014, 12:13
Posts: 167
Location: Isfahan
Information on malware known as Ransomware:
http://www.sophos.com/en-us/support/kno ... 19006.aspx

5 stages of crypto-ransomware staying safe:
http://www.sophos.com/en-us/medialibrar ... 000KbqSAAS

_________________
Phoenix Computer Forensic Laboratory
http://www.databack.ir


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: January 30th, 2015, 17:25 
Offline

Joined: November 29th, 2006, 10:08
Posts: 7855
Location: UK
Had a client with similar issue, theirs was something like .mtvoish

Client was a dealer who eradicated the malware without noting what it was exactly. They said it was "crypto something or other" ... Helpful!

_________________
PC Image Data Recovery
http://www.pcimage.co.uk

New!! HDD-PCB.COM for all your PCB and donor HDD requirements!


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 2nd, 2015, 12:44 
Offline

Joined: July 20th, 2011, 9:02
Posts: 91
Observed 2-3 more cases with same issue.
Virus get removed but Asking 500 or 1000usd to decrypt and asking deposit amount in given bank details which account is unknown .


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 2nd, 2015, 15:52 
Offline

Joined: November 24th, 2014, 4:42
Posts: 13
Location: Poland
I'm assuming that you are victim of ransomware called CTB-Locker. For now is no other way than brute force or pay the ransom.


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 3rd, 2015, 4:05 
Offline

Joined: September 7th, 2012, 16:37
Posts: 178
Read this, it's a very helpful guide http://www.bleepingcomputer.com/virus-r ... nformation
and you can decrypt your files using https://www.decryptcryptolocker.com/


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 3rd, 2015, 4:26 
Offline
User avatar

Joined: January 9th, 2007, 11:12
Posts: 397
Location: Romania
sosrecup wrote:
and you can decrypt your files using https://www.decryptcryptolocker.com/

This is wrong, of course.

_________________
www.datasave.ro


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 3rd, 2015, 5:47 
Offline
User avatar

Joined: December 19th, 2006, 8:49
Posts: 11038
Location: Portugal
sosrecup wrote:
Read this, it's a very helpful guide http://www.bleepingcomputer.com/virus-r ... nformation
and you can decrypt your files using https://www.decryptcryptolocker.com/


This will only decrypt files encrypted with CRYPTOLOCKER, it will NOT WORK to decrypt files encrypted with CTB.

_________________
1Q9xrDTzTddUXeJAFRn37aqh1Yr6buDCdw - (Bitcoin Donations)
paypal.me/Spildit - (PayPal Donations)
The HDD Oracle - Platform for OPEN research on Data Recovery.


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 3rd, 2015, 6:38 
Offline

Joined: July 20th, 2011, 9:02
Posts: 91
Read this, it's a very helpful guide http://www.bleepingcomputer.com/virus-r ... nformation
and you can decrypt your files using https://www.decryptcryptolocker.com/

Saying sample file is not encrypted..........................................:-(


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 3rd, 2015, 6:56 
Offline
User avatar

Joined: December 19th, 2006, 8:49
Posts: 11038
Location: Portugal
DRCP wrote:
Read this, it's a very helpful guide http://www.bleepingcomputer.com/virus-r ... nformation
and you can decrypt your files using https://www.decryptcryptolocker.com/

Saying sample file is not encrypted..........................................:-(


I told you.
That site will only decrypt files encrypted with cryptolocker, it will not decrypt files encrypted by other ransomware.

_________________
1Q9xrDTzTddUXeJAFRn37aqh1Yr6buDCdw - (Bitcoin Donations)
paypal.me/Spildit - (PayPal Donations)
The HDD Oracle - Platform for OPEN research on Data Recovery.


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 11th, 2015, 11:08 
Offline
User avatar

Joined: August 24th, 2012, 8:15
Posts: 142
Location: Dominican Republic
So right now there's only cryptolocker and CTB?

_________________
Data Recovery in the Dominican Republic
https://www.recuperamidata.com/


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 11th, 2015, 11:24 
Offline
User avatar

Joined: January 9th, 2007, 11:12
Posts: 397
Location: Romania
And CryptoWall 2.0/3.0

_________________
www.datasave.ro


Top
 Profile  
 
 Post subject: Re: File extension changed
PostPosted: February 11th, 2015, 17:01 
Offline

Joined: November 24th, 2014, 4:42
Posts: 13
Location: Poland
LoboX wrote:
So right now there's only cryptolocker and CTB?

I think this is only matter of time when other new modification will appear. And I think this will be when CTB-Locker will be busted.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 13 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google Adsense [Bot] and 59 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group