Encrypted Files help needed

Discussion in 'Bulletin Board ARCHIVE' started by Plankton Pete, Jul 27, 2016.

  1. Plankton Pete

    Plankton Pete Well-Known Member

    Joined:
    Jul 19, 2005
    Messages:
    9,297
    Likes Received:
    4,035
    Trophy Points:
    113
    Location:
    In hiding from the lynch mob
    Home Page:
    Style:
    Barnsley (full width)
    Mother in law has somehow downloaded a malicious rogue file that has encrypted all her photographs and documents.

    The file has put a html message in the same folder that essentially asks for money to decode the encrypted files.

    Anyone know any ways to overcome this
    and getting the files back? Clearly paying what is essentially blackmail is not a good idea and a clean reinstall loses all the documents.
     
  2. BarnsleyReds

    BarnsleyReds Well-Known Member

    Joined:
    Apr 28, 2013
    Messages:
    12,163
    Likes Received:
    14,453
    Trophy Points:
    113
    Style:
    XenForo - Xenith Reds
    Any way you could upload one of the files? (obviously one that isnt of a sensitive nature)

    I could have a look at the file and see if i can access it.

    There's a chance it could just be nothing, and they've just made it look like there's something encrypting it, but there's a good chance that they are unrecoverable, unfortunately.
     
  3. BarnsleyReds

    BarnsleyReds Well-Known Member

    Joined:
    Apr 28, 2013
    Messages:
    12,163
    Likes Received:
    14,453
    Trophy Points:
    113
    Style:
    XenForo - Xenith Reds
  4. Plankton Pete

    Plankton Pete Well-Known Member

    Joined:
    Jul 19, 2005
    Messages:
    9,297
    Likes Received:
    4,035
    Trophy Points:
    113
    Location:
    In hiding from the lynch mob
    Home Page:
    Style:
    Barnsley (full width)
    Cheers, will look.
     
  5. ret

    retired red Active Member

    Joined:
    Jul 20, 2014
    Messages:
    509
    Likes Received:
    43
    Trophy Points:
    28
    Occupation:
    retired
    Location:
    cudworth
    Style:
    Barnsley (full width)
    Try system restore
     
  6. JamDrop

    JamDrop Well-Known Member

    Joined:
    Mar 30, 2013
    Messages:
    18,811
    Likes Received:
    19,882
    Trophy Points:
    113
    Location:
    Leeds
    Style:
    Barnsley (full width)
    That's leaves your documents as they are.
     
  7. Plankton Pete

    Plankton Pete Well-Known Member

    Joined:
    Jul 19, 2005
    Messages:
    9,297
    Likes Received:
    4,035
    Trophy Points:
    113
    Location:
    In hiding from the lynch mob
    Home Page:
    Style:
    Barnsley (full width)
    Correct. Sounds like she's stuffed from what I've read.
     
  8. Skryptic

    Skryptic Well-Known Member

    Joined:
    Mar 23, 2015
    Messages:
    3,261
    Likes Received:
    3,560
    Trophy Points:
    113
    Style:
    Barnsley (full width)
    Unfortunately you're probably buggered.
     
  9. Marc

    Marc Administrator Staff Member Admin

    Joined:
    Aug 10, 2012
    Messages:
    28,633
    Likes Received:
    23,963
    Trophy Points:
    113
    Style:
    Barnsley (full width)
    Sounds dodgy Chris mate. Honest advice would be to take it into a shop. There's usually a way to fix these things, if you speak to an expert. Don't start hacking around at it though. Could cause more harm than good.
     
  10. JamDrop

    JamDrop Well-Known Member

    Joined:
    Mar 30, 2013
    Messages:
    18,811
    Likes Received:
    19,882
    Trophy Points:
    113
    Location:
    Leeds
    Style:
    Barnsley (full width)
    Have you informed the police? I doubt that they can get your files back but there must be a way that the hacker will receive the money so perhaps the police can trace them that way?
     
  11. Wat

    Watcher_Of_The_Skies Well-Known Member

    Joined:
    Aug 12, 2011
    Messages:
    9,487
    Likes Received:
    5,368
    Trophy Points:
    113
    Location:
    Leeds
    Style:
    Barnsley
    Run a system scan with a piece of anti-virus software.
     
  12. Marc

    Marc Administrator Staff Member Admin

    Joined:
    Aug 10, 2012
    Messages:
    28,633
    Likes Received:
    23,963
    Trophy Points:
    113
    Style:
    Barnsley (full width)
    Probably a western union payment to anywhere in the world. Not a chance.


    Sent from my iPhone using Tapatalk
     
  13. Red

    RedMonk Well-Known Member

    Joined:
    Aug 8, 2011
    Messages:
    2,255
    Likes Received:
    1,838
    Trophy Points:
    113
    Style:
    Barnsley (full width)
    There is a program called Shadow Explorer portable that searches for shadow copies of your files. It takes snapshots of your files at certain dates that should have remained unaffected. Once you select the date of the files you want you can extract and save them somewhere else.
     
  14. JamDrop

    JamDrop Well-Known Member

    Joined:
    Mar 30, 2013
    Messages:
    18,811
    Likes Received:
    19,882
    Trophy Points:
    113
    Location:
    Leeds
    Style:
    Barnsley (full width)
    I was just about to suggest that which can be downloaded here (hopefully the virus hasn't already deleted them): http://www.shadowexplorer.com/downloads.html

    A video of how to use it here: [video=youtube;oaXtQ6rbvxA]https://www.youtube.com/watch?v=oaXtQ6rbvxA[/video]

    Or Recuva which will recover deleted files (the virus may have copied your files, encrypted them and then deleted the original).

    You can get a free version here: https://www.piriform.com/recuva

    A video of how to use it here: [video=youtube;LeEICG0zWqY]https://www.youtube.com/watch?v=LeEICG0zWqY[/video]
     
  15. Marc

    Marc Administrator Staff Member Admin

    Joined:
    Aug 10, 2012
    Messages:
    28,633
    Likes Received:
    23,963
    Trophy Points:
    113
    Style:
    Barnsley (full width)
    Well Chris, what a massive coincidence. Just opened my tech journal app and low and behold, this was the first article!! Seems like you're not alone.

    I'd recommend having a good read of this, before pressing any buttons!

    How can I remove a ransomware infection? - the guardian
    https://apple.news/AQG8MQPjJQN2h11zfn5lHeg


    Sent from my iPhone using Tapatalk
     
  16. tingleytyke

    tingleytyke Well-Known Member

    Joined:
    Dec 7, 2011
    Messages:
    3,731
    Likes Received:
    1,019
    Trophy Points:
    113
    Occupation:
    Used to be Shift Engineer
    Location:
    Tingley
    Style:
    Barnsley (full width)
  17. Plankton Pete

    Plankton Pete Well-Known Member

    Joined:
    Jul 19, 2005
    Messages:
    9,297
    Likes Received:
    4,035
    Trophy Points:
    113
    Location:
    In hiding from the lynch mob
    Home Page:
    Style:
    Barnsley (full width)
    Cheers Marc - I don't have her PC with me, but I know she sat on the problem for about a month before she asked me about it (I'm her go to tech guy), but I'd never seen anything like it. I've passed it on to an IT company I know, but they've said the only sure way to deal with it is a clean install. I'd back up the encrypted files first. It's mainly photographs that have been encrypted and I think she has copies on CDs etc. so it's not as desperate as it could have been.
     
  18. Plankton Pete

    Plankton Pete Well-Known Member

    Joined:
    Jul 19, 2005
    Messages:
    9,297
    Likes Received:
    4,035
    Trophy Points:
    113
    Location:
    In hiding from the lynch mob
    Home Page:
    Style:
    Barnsley (full width)
    Think the latest version of the ransom virus deletes these, I understand infection happened in June, she's stuffed.
     
  19. Gloria Stitts

    Gloria Stitts Active Member

    Joined:
    Aug 14, 2011
    Messages:
    2,309
    Likes Received:
    12
    Trophy Points:
    38

Share This Page