labtech wrote:
jeremyb wrote:
..all other files are untouched.
Did you mean to say "all other bytes are untouched", in any one file?
If yes, along with the other details, sound like a Ransomware virus of some sort.
Let me rephrase, the entire file is filled with random data except the first 16 bytes which are always the same...
It sounds like ransomware.
arvika wrote:
http://forum.hddguru.com/viewtopic.php?f=3&t=27348&hilit=cryptolocker
Check this. Maybe it is similar.
I think you are correct...
Sasha Sheremetov wrote:
Hi Jeremy,
I've had something similar couple of times, but it was kind of different - alphabet replacement cryptoalgo.
It damaged first sectors of particular file formats (JPEGs, office), file system was just fine.
Found half of alphabet, but gave up because dev didn't worth a time spent.
The entire file is modified not just individual bytes
dick wrote:
Is there any chance the system the flash drive was plugged in to/used with, has a shadow copy of the files which were present on the flash drive?
Its not an XOR overlay or USB Error message, the file system is intact, only specific files are targeted. Crypto doesn't appear to be ECB..
I think ransomware is the answer, stupid question but I might as well ask, has anyone ever cracked one?