Results 1 to 13 of 13

Thread: Ransomware problem

  1. #1
    Member
    Join Date
    Aug 2006
    Posts
    198
    Thanks
    5
    Thanked
    14 times in 14 posts

    Ransomware problem

    Hi, would appreciate some advice please.
    A relative's computer was recently infected with ransomware (Spora). Whilst the machine has been cleared of the virus, a large number of files (mainly photographs) have been left presumably with the header overwritten - normal viewing programs don't recognise the type although the file extension is for example jpg. Does anyone know of a program or utility that might return these files to their previous 'normal' setting?

  2. #2
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Ransomware problem

    Ransom ware usually encrypts the files -which would also change the header.

    The header for a jpg file is FF D8 FF E0 so if you have a hex editor, you can manually set those values and see if the file springs to life.

    Sadly I fear you may be disappointed.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  3. #3
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Ransomware problem

    I'm not familiar with ths ransomware, is it the cryptographic type where you need to pay for a decode key, or has it just nobbled the files by removing parts of them?

    If it's the former, you may be stuck - depending on if you have the decode key or not. The latter you might be able to salvage as long as it is just file header/metadata that has been removed.

    In the case of JPGs, the compression means that there generally isn't much binary data in there that you can change without ruining the whole file (or a good chunk of it). Do you have an example damaged file that we could take a look at?

  4. #4
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Ransomware problem

    Did you try the Trend Micro Decrypter ?
    https://www.bugsfighter.com/remove-s...pt-your-files/
    Society's to blame,
    Or possibly Atari.

  5. #5
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Ransomware problem

    I do not believe that works with Spora

    http://blog.trendmicro.com/trend-mic...yptor-updated/

    It isn't listed.
    throw new ArgumentException (String, String, Exception)

  6. #6
    Member
    Join Date
    Aug 2006
    Posts
    198
    Thanks
    5
    Thanked
    14 times in 14 posts

    Re: Ransomware problem

    Virtuo - cryptographic I'm afraid. Phage & TheAnimus, thanks.

    Is one of the Linux recovery programs likely to work?

  7. #7
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Ransomware problem

    Googling for solutions throws up a few free tools. Have you tried them ?
    Society's to blame,
    Or possibly Atari.

  8. #8
    Member
    Join Date
    Aug 2006
    Posts
    198
    Thanks
    5
    Thanked
    14 times in 14 posts

    Re: Ransomware problem

    Yes, but Google generates a) paid for adverts and b) unreliable sources. Who do you trust? - why Hexus of course

  9. #9
    Guy
    Guy is offline
    HEXUS.social member
    Join Date
    Aug 2006
    Location
    Hampshire, UK
    Posts
    5,175
    Thanks
    406
    Thanked
    413 times in 297 posts

    Re: Ransomware problem

    If it's a Spora outbreak then they're (currently) unrecoverable.

    Ask me how I know...

    Fortunately it was a fairly minor work system and everything is kept in near enough real time backup, redundant copies, multiple revisions of each file. Still an absolute pain to go through.

  10. #10
    Be wary of Scan Dashers's Avatar
    Join Date
    Jun 2016
    Posts
    1,079
    Thanks
    40
    Thanked
    137 times in 107 posts
    • Dashers's system
      • Motherboard:
      • Gigabyte GA-X99-UD4
      • CPU:
      • Intel i7-5930K
      • Memory:
      • 48GB Corsair DDR4 3000 Quad-channel
      • Storage:
      • Intel 750 PCIe SSD; RAID-0 x2 Samsung 840 EVO; RAID-0 x2 WD Black; RAID-0 x2 Crucial MX500
      • Graphics card(s):
      • MSI GeForce GTX 1070 Ti
      • PSU:
      • CoolerMaster Silent Pro M2 720W
      • Case:
      • Corsair 500R
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Philips 40" 4K AMVA + 23.8" AOC 144Hz IPS
      • Internet:
      • Zen FTTC

    Re: Ransomware problem

    Can highly recommend readonly snapshots for protecting your data from encryption. Although I appreciate that the horse has bolted already.

    Windows does file history or volume shadow copies - this should protect you against anything working at the file-level.

  11. #11
    OilSheikh
    Guest

    Re: Ransomware problem

    Wipe and reinstall, I am afraid.

  12. #12
    Ngt
    Ngt is offline
    Registered+
    Join Date
    May 2017
    Posts
    21
    Thanks
    0
    Thanked
    1 time in 1 post

    Re: Ransomware problem

    Still no decrypter available for this but it may happen eventually, it has done for a few others recently.

  13. #13
    Registered+
    Join Date
    Jun 2017
    Posts
    2
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Ransomware problem

    Quote Originally Posted by Dashers View Post
    Can highly recommend readonly snapshots for protecting your data from encryption. Although I appreciate that the horse has bolted already.

    Windows does file history or volume shadow copies - this should protect you against anything working at the file-level.
    the first thing they do before messing with the files is run the command to delete all shaddow copys and then turn off backup (unless the back up is disconnected from the PC then your good just dont plug it back into that PC or mite wipe all the backups)

    recommand crashplan (can be used for free if you have another PC or just a external HDD that you plug in once a week)
    windows 7/8 backup works well and win 10 file history seems to work fine as well (but must use a external HDD that you Dont leave plugged in or it just encrypt them as well)

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •