All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 14 posts ] 
Author Message
 Post subject: Virus Encrypted Flash Drive
PostPosted: December 9th, 2014, 13:57 
Offline

Joined: July 30th, 2012, 3:37
Posts: 308
Location: Fairfield, CT USA
A client sent me a flash drive that he says was encrypted by a virus... any ideas which virus or how to recover?
Every jpeg and doc file starts with the same 16 bytes, all other files are untouched.

Filesystem appears fine otherwise, no FAT table corruption.


Attachments:
Capture.JPG
Capture.JPG [ 50.69 KiB | Viewed 9549 times ]

_________________
Recover My Flash Drive
Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 9th, 2014, 14:41 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 14945
Location: Australia
Upload your file to http://www.virustotal.com.

The file will be scanned by about 40 AV products.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 9th, 2014, 15:43 
Offline

Joined: August 18th, 2010, 17:35
Posts: 3630
Location: Massachusetts, USA
jeremyb wrote:
..all other files are untouched.

Did you mean to say "all other bytes are untouched", in any one file?
If yes, along with the other details, sound like a Ransomware virus of some sort.

_________________
Hard Disk Drive, SSD, USB Drive and RAID Data Recovery Specialist in Massachusetts


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 9th, 2014, 15:52 
Offline

Joined: October 24th, 2009, 15:22
Posts: 843
Location: Poland
viewtopic.php?f=3&t=27348&hilit=cryptolocker
Check this. Maybe it is similar.

_________________
Odzyskiwanie danych


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 9th, 2014, 16:43 
Offline

Joined: July 2nd, 2014, 8:05
Posts: 201
Hi Jeremy,

I've had something similar couple of times, but it was kind of different - alphabet replacement cryptoalgo.
It damaged first sectors of particular file formats (JPEGs, office), file system was just fine.
Found half of alphabet, but gave up because dev didn't worth a time spent.

Image

_________________
VISUAL NAND RECONSTRUCTOR. A big revolution in chip-off data recovery


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 10th, 2014, 10:31 
Offline

Joined: January 8th, 2008, 5:21
Posts: 937
Location: uk
Is there any chance the system the flash drive was plugged in to/used with, has a shadow copy of the files which were present on the flash drive?


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 10th, 2014, 23:16 
Offline

Joined: July 30th, 2012, 3:37
Posts: 308
Location: Fairfield, CT USA
labtech wrote:
jeremyb wrote:
..all other files are untouched.

Did you mean to say "all other bytes are untouched", in any one file?
If yes, along with the other details, sound like a Ransomware virus of some sort.

Let me rephrase, the entire file is filled with random data except the first 16 bytes which are always the same...
It sounds like ransomware.

arvika wrote:
http://forum.hddguru.com/viewtopic.php?f=3&t=27348&hilit=cryptolocker
Check this. Maybe it is similar.


I think you are correct...

Sasha Sheremetov wrote:
Hi Jeremy,
I've had something similar couple of times, but it was kind of different - alphabet replacement cryptoalgo.
It damaged first sectors of particular file formats (JPEGs, office), file system was just fine.
Found half of alphabet, but gave up because dev didn't worth a time spent.


The entire file is modified not just individual bytes

dick wrote:
Is there any chance the system the flash drive was plugged in to/used with, has a shadow copy of the files which were present on the flash drive?

Its not an XOR overlay or USB Error message, the file system is intact, only specific files are targeted. Crypto doesn't appear to be ECB..

I think ransomware is the answer, stupid question but I might as well ask, has anyone ever cracked one?

_________________
Recover My Flash Drive


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 11th, 2014, 9:42 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3779
Location: Adelaide, Australia
yes, there have been solutions for a few variants. Companies such as F-Secure has put out tools.

The criminals are learning though... not leaving keys in registry for example.

some of the more recent variants you are S.O.L.


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 17th, 2014, 18:54 
Offline

Joined: July 30th, 2012, 3:37
Posts: 308
Location: Fairfield, CT USA
I got two more flash drives in with the same encryption.

_________________
Recover My Flash Drive


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 17th, 2014, 19:13 
Offline
User avatar

Joined: April 3rd, 2011, 0:19
Posts: 2020
Location: Providence, RI
I just handled a CryptoWall virus case that encrypted all the images, documents, and even PST files on a businesses computer. The tech then backed up the encrypted files to a USB and reinstalled the OS on the same drive (also wiping out the previous versions option which might have fixed it).

I had to run a RAW recovery just to find the txt file with the link to pay the criminals $500 in bitcoin. Which the customer had no choice but to pay, and the thieves very professionally provided a program to decrypt the data.

I felt bad having to tack my data recovery charge on top of the $500 they already paid the thieves, but business is business.

_________________
Data Medics - Hard Drive, SSD, and RAID Data Recovery Service Company


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 17th, 2014, 19:16 
Offline
User avatar

Joined: April 3rd, 2011, 0:19
Posts: 2020
Location: Providence, RI
Look for a file or link on their desktop/documents folder named something like DECRYPT_INSTRUCTION. It's probably CryptoWall or another variant of it, which will encrypt not only the HDD but also anything USB connected and even mapped as a network drive.

_________________
Data Medics - Hard Drive, SSD, and RAID Data Recovery Service Company


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 18th, 2014, 1:17 
Offline

Joined: September 8th, 2014, 23:59
Posts: 32
Location: China
There is a new version recently. It encrypts all image, txt,rar, office, pdf files. It covers all local, network, usb drives. It encrypts the first 2MB, rest of the file is fine. But 2MB is enough to kill all your important files.
It should be AES128 or AES256, I guess no solution at the moment.


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 18th, 2014, 1:35 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3779
Location: Adelaide, Australia
Not a single person I have warned about this type of malware has changed their behaviour. I just look like a scaremonger, and a bit crazy. I doubt anyone even believes the criminals are making millions of dollars out of this.

still people say yeah I know I have viruses because my computer is slow, but don't do anything about it. Even when I offer to go clean their PC -FOR FREE- it is too much of an inconvenience to stay away from facebook for a few hours.

meanwhile we put aside other work to spend many hours on this rubbish, and get stressed out trying to save crying customers more heartache.

is there any hope for this species??


Top
 Profile  
 
 Post subject: Re: Virus Encrypted Flash Drive
PostPosted: December 20th, 2014, 3:06 
Offline

Joined: March 15th, 2005, 12:49
Posts: 36
Location: Владивосток
Looks some bytes xored 0x08 in Sasha sample. different as Jeremy sample.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 14 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group