MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 8 posts ] 
Author Message
 Post subject: All file extension converted to .ba91 - Virus? Ransomware?
PostPosted: November 14th, 2016, 0:32 
Offline

Joined: January 2nd, 2009, 4:18
Posts: 74
Good day,

All file extension in this HDD had converted to .ba91 when the user tried to open up a .cab file that he downloaded from email.

I tried Google it, find nothing about .ba91. Is there a way for me to know whether this is a computer virus or ransomware?
Thanks


Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 14th, 2016, 5:41 
Offline
User avatar

Joined: December 8th, 2013, 4:48
Posts: 838
Location: Pakistan
in case of ransomware there should be a ransom note (readme or something like this) text or htm file in each folder. most likely a ransomware.

_________________
Data Recovery Pakistan


Last edited by MindMergepk on November 14th, 2016, 5:55, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 14th, 2016, 5:50 
Offline

Joined: January 8th, 2008, 5:21
Posts: 927
Location: uk
Have you tried the obvious? Rename a sample from the photos to .jpg or documents to .docx etc


Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 15th, 2016, 21:10 
Offline

Joined: December 6th, 2012, 8:49
Posts: 291
Location: espaƱa
....10 random characters and a random 4 character extension ....

is CERBER V4


Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 15th, 2016, 23:13 
Offline

Joined: January 2nd, 2009, 4:18
Posts: 74
Hi guys,

Yea it is ransomware. We found README.hta in every sub-folder.

Hi Spildit,
What can we see from hex editor? Sorry, this is the first time I receive ba91 file don't really know how to deal with it.

"The extension ba91 is not allowed." received this message when I tried to attach a sample file here

Thanks


Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 15th, 2016, 23:19 
Offline

Joined: January 2nd, 2009, 4:18
Posts: 74
colanco wrote:
....10 random characters and a random 4 character extension ....

is CERBER V4


Hi colanco, I noticed Trend Micro has the decryptor but do you think it works for Cerber v4 (it mentioned Cerber V1 on the website)

Is there any other way to decrypt the files other than paying for ransom (did anyone even get it decrypted after paying the ransom, I wonder) ..?

Gosh, this is so malicious..


Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 16th, 2016, 3:29 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3547
Location: Greece
It is Cerber 4 and unfortunately there is no way to decrypt :(

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: All file extension converted to .ba91 - Virus? Ransomwar
PostPosted: November 16th, 2016, 3:38 
Offline

Joined: January 2nd, 2009, 4:18
Posts: 74
northwind wrote:
It is Cerber 4 and unfortunately there is no way to decrypt :(


OK.
Thanks northwind.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 112 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group