![]() |
#1
|
|||
|
|||
![]()
Hello, my computer system was attacked by unknown guys online iguess.
i cant open my data on the computer. "Don't worry, you can return all your files! All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key." any Help Please ? BR |
#2
|
||||
|
||||
That sounds more like you opened an infected program, pdf, etc. and got hit with ransomware. If you know what version/variant of ransomware you got hit with you can look around online for any known decryptor tool that was already made for it. (Typically for the shittier versions that used a similar key/code that could be determined or pulled from your system.)
__________________
Personal Projects Site: https://atom0s.com |
The Following User Says Thank You to atom0s For This Useful Post: | ||
mariam3 (06-01-2023) |
#3
|
|||
|
|||
Quote:
In 2015(maybe 2016) my friend's notebook was also hit by TeslaCrypt ransomware. I was able to decrypt my friend's data! First you should define what/which ransomware (ransomware variant) you ware hit by. Then you can search for a decryptor. If you cannot find a decryptor, you then reverse the malicious binary to create a decryptor. And If you are lucky you can rip out the decryption key (if it is in binary) |
#4
|
|||
|
|||
As blue_devil said, identify the ransomware and search for its decryptor. Many ransomware was found with weak implementations therefor easy way to decrypt it.
Use this ID Ransomware, upload a ransom note and/or sample encrypted file to identify the ransomware that has encrypted your data. hXXps://id-ransomware.malwarehunterteam.com After that you will a have clue on what to search for |
The Following 2 Users Say Thank You to sh3dow For This Useful Post: | ||
blue_devil (06-02-2023), niculaita (06-03-2023) |
#5
|
|||
|
|||
And don't use the infected anymore directly,as said identify the ransomware,with a bootable usb key antivirus distro like Kaspersky,eset etc..and keep it even months later a decryptor can come.
I wish you'll recover data.
__________________
I like this forum! |
The Following User Says Thank You to bolo2002 For This Useful Post: | ||
niculaita (06-03-2023) |
#6
|
|||
|
|||
Well, it depends if your data is valuable enough.
Most modern ransomware are a part of RaaS (Randomware as a Service), and authors are relatively "trustable", so you can pay them and get your files back. Nowadays it's basically impossible to crack a ransomware, because most flaws have been fixed, and those who cannot well encrypt your files are nearly all upgraded (unless you infected from a sample during 2016-2017. I helped a few companies solving their ransomware issue back in 2015. One case I had dealt is having its private key XORed under C:\Temp\ntuser.dat (weird name, haha). Another case I had managed to do is solved by using the dump file, because the victim is a driver developer, and the ransomware incorrectly encrypted her configuration file for the device driver, so the kernel crashed in WinDBG. However, modern ransomware can make correct assumption of which file should be encrypted, and carefully design their key function, so low hanging fruits have gone. Nowadays, all companies claiming they can solve the file, are mostly fraud. Good luck ![]() |
![]() |
Thread Tools | |
Display Modes | |
|
|