Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-09-2015, 03:16
goku goku is offline
 
Join Date: Feb 2009
Posts: 125
Rept. Given: 30
Rept. Rcvd 34 Times in 15 Posts
Thanks Given: 20
Thanks Rcvd at 4 Times in 3 Posts
goku Reputation: 34
How to decrypt CryptoWall

What does this mean ?
This means that the structure and data within your files have been irrevocably changed, you will not be able to work with them, read them or see them,it is the same thing as losing them forever, but with our help, you can restore them.
How did this happen ?
Especially for you, on our server was generated the secret key pair RSA-2048 - public and private.
All your files were encrypted with the public key, which has been transferred to your computer via the Internet.
Decrypting of your files is only possible with the help of the private key and decrypt program, which is on our secret server.
__________________
hi
Reply With Quote
  #2  
Old 04-09-2015, 03:57
arthur plank arthur plank is offline
Friend
 
Join Date: Jan 2005
Posts: 99
Rept. Given: 28
Rept. Rcvd 22 Times in 14 Posts
Thanks Given: 16
Thanks Rcvd at 52 Times in 20 Posts
arthur plank Reputation: 22
Not sure there is any practical way to decrypt it. Once infected and the infection has done it's damage, you're basically stuffed.

In my opinion, the people involved in this particular activity should be totally and irrevocably removed from society.

http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information
Reply With Quote
  #3  
Old 04-09-2015, 20:09
reversing_solo reversing_solo is offline
Friend
 
Join Date: Apr 2010
Posts: 30
Rept. Given: 2
Rept. Rcvd 9 Times in 6 Posts
Thanks Given: 6
Thanks Rcvd at 31 Times in 13 Posts
reversing_solo Reputation: 9
decryptcryptolocker

Did you try with:

h***s://www.decryptcryptolocker.com/

it's working on old cryptolocker, maybe it can work with your version.

Regards.

Last edited by reversing_solo; 11-02-2017 at 18:22.
Reply With Quote
  #4  
Old 04-15-2015, 16:28
reversing_solo reversing_solo is offline
Friend
 
Join Date: Apr 2010
Posts: 30
Rept. Given: 2
Rept. Rcvd 9 Times in 6 Posts
Thanks Given: 6
Thanks Rcvd at 31 Times in 13 Posts
reversing_solo Reputation: 9
new tool

Also h***s://noransom.kaspersky.com/ has just been relased.

Last edited by reversing_solo; 11-02-2017 at 18:22.
Reply With Quote
  #5  
Old 04-15-2015, 17:40
foosaa foosaa is offline
Friend
 
Join Date: Dec 2005
Posts: 80
Rept. Given: 34
Rept. Rcvd 11 Times in 9 Posts
Thanks Given: 116
Thanks Rcvd at 63 Times in 25 Posts
foosaa Reputation: 11
The noransom.kaspersky.com decryptor works only for the CoinVault ransomware and that too not in all the instances. Like mentioned, invest in a good antivirus once you've got rid of the piece of crap. People who write such stuff should be punished severely.

I'm sure you might have searched, but just some more tips:

http://www.wintips.org/remove-cryptowall-virus-and-restore-cryptowall-files/

But cracking the encryption is next to impossible because of the RSA 2048 bit keys. It is the backbone that is keeping all world's the Certificate Ecosystem alive and protecting all the financial transactions across the globe with the help of TLS/SSL!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 13:14.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX
( 1998 - 2020 )