Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

TeslaCrypt (ecc, ezz, exx, xyz, zzz, aaa, abc, ccc) Decryption Support Requests


  • Please log in to reply
6354 replies to this topic

#2116 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:07:00 AM

Posted 19 February 2016 - 02:52 PM

That video has been posted before. I have been in contact with the company behind that software, and they confirmed it has to be installed before infection. It also appears to only grab the PrivateKeyFile, so it has to re-do its process anytime the computer is restarted while the infection is still running.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


BC AdBot (Login to Remove)

 


#2117 NightbirD

NightbirD

  •  Avatar image
  • Members
  • 501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Buenos Aires, Argentina.
  • Local time:10:00 AM

Posted 19 February 2016 - 05:28 PM

@Demonslay335

Yes, that happened because his yafu.ini tune was set like a Xeon running in a Linux 64 environment, totally incompatible with his hardware & system.The whole thing was rectified 11hs. ago. Thx Demonslay!


************************************************************************************************************************


Please, start TODAY a BACK UP DISCIPLINE, & try to spread the idea to everyone you know. This way you, & your beloved ones, will keep safe the whole data, & the crypto-criminal activity will turn senseless soon.


#2118 HLR7594

HLR7594

  •  Avatar image
  • Banned
  • Member rank image
  • 18 posts
  • OFFLINE
  •  
  • Local time:03:00 PM

Posted 19 February 2016 - 06:42 PM

 

I'm afected with tesla virus. Please help me to decrypt my fyles. There is one of my afected file. .micro

There is no way of decrypting TeslaCrypt 3.0 .xxx, .ttt, .micro, or .mp3 variants at this time since they use a different protection/key exchange algorithm, a different method of key storage and the key for them cannot be recovered. Support for TeslaCrypt 3.0 is provided in this topic if you have further questions but there is no solution to fix your files.

 

quietman7 is wrong. You can decrypt your files : https://www.sendspace.com/file/nmlg6v



#2119 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:07:00 AM

Posted 19 February 2016 - 06:54 PM

quietman7 is wrong. You can decrypt your files : https://www.sendspace.com/file/nmlg6v


What are you insinuating by sending a Word document about a Shakespeare production? From your previous posts, you were hit by the .vvv variant, which is decryptable. Those with the .xxx, .ttt, .micro, or .mp3 are not decryptable without paying the ransom. I'm unsure the status of your factoring since it is not on factordb.com, but I can only assume you got the factors from VirusD then?


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#2120 HLR7594

HLR7594

  •  Avatar image
  • Banned
  • Member rank image
  • 18 posts
  • OFFLINE
  •  
  • Local time:03:00 PM

Posted 19 February 2016 - 07:01 PM

 

quietman7 is wrong. You can decrypt your files : https://www.sendspace.com/file/nmlg6v


What are you insinuating by sending a Word document about a Shakespeare production? From your previous posts, you were hit by the .vvv variant, which is decryptable. Those with the .xxx, .ttt, .micro, or .mp3 are not decryptable without paying the ransom. I'm unsure the status of your factoring since it is not on factordb.com, but I can only assume you got the factors from VirusD then?

 

 

@Demonslay335 : look at post 1971



#2121 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 65,621 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:00 AM

Posted 19 February 2016 - 07:29 PM

- Added support for TeslaCrypt 3.0.0 encrypted files (.xxx, .ttt, .micro).
...
I am still working on the solution how to recover one of the keys listed above, but currently there is no solution.

@All
The current state of decryption of TeslaCrypt 3 (.xxx, .ttt, .micro) is still the same, we can't recover any of the 7 private keys right now....


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITEUnified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#2122 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 65,621 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:00 AM

Posted 19 February 2016 - 07:39 PM

@HLR7594

The above posting is the most current information we have from BloodDolly.

If there is something new, our crypto-experts will have to confirm and we will advise folks accordingly.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITEUnified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#2123 HLR7594

HLR7594

  •  Avatar image
  • Banned
  • Member rank image
  • 18 posts
  • OFFLINE
  •  
  • Local time:03:00 PM

Posted 19 February 2016 - 07:39 PM

@quietman7

 

Look at post 1971



#2124 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 65,621 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:00 AM

Posted 19 February 2016 - 07:41 PM

I have spoken with Demonslay335 who is already investigating and will get back to me once done.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITEUnified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#2125 HLR7594

HLR7594

  •  Avatar image
  • Banned
  • Member rank image
  • 18 posts
  • OFFLINE
  •  
  • Local time:03:00 PM

Posted 19 February 2016 - 07:42 PM

@quietman7

 

Also you can look at post 1848 and look there : https://www.sendspace.com/file/rhcf3s



#2126 HLR7594

HLR7594

  •  Avatar image
  • Banned
  • Member rank image
  • 18 posts
  • OFFLINE
  •  
  • Local time:03:00 PM

Posted 20 February 2016 - 02:57 AM

 @ quietman7

 

Look a this PM, its interesting no ?



#2127 NightbirD

NightbirD

  •  Avatar image
  • Members
  • 501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Buenos Aires, Argentina.
  • Local time:10:00 AM

Posted 20 February 2016 - 03:05 AM

@HLR7594

I really would like to understand what's going on.

Yes, i know, it's far away from me all that could happen behind a private chat between members/masters/guests..., it's ok, but why to expose that chat here?

 

I would like to know if we can start to help the victims of TC3.0....or, what's going on?


************************************************************************************************************************


Please, start TODAY a BACK UP DISCIPLINE, & try to spread the idea to everyone you know. This way you, & your beloved ones, will keep safe the whole data, & the crypto-criminal activity will turn senseless soon.


#2128 3J Kernel

3J Kernel

  •  Avatar image
  • Members
  • 67 posts
  • OFFLINE
  •  
  • Local time:02:00 PM

Posted 20 February 2016 - 03:18 AM

@HLR7594

I really would like to understand what's going on.

Yes, i know, it's far away from me all that could happen behind a private chat between members/masters/guests..., it's ok, but why to expose that chat here?

 

I would like to know if we can start to help the victims of TC3.0....or, what's going on?

 

yeah,exactly  :bounce:



#2129 BloodDolly

BloodDolly

  •  Avatar image
  • Security Colleague
  • 526 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Slovakia
  • Local time:02:00 PM

Posted 20 February 2016 - 04:22 AM

@HLR7594:

Demonslay335 didn't want to infect you, he just used wrong site for file sharing.
I reuploaded that package to sendspace. Here is the link https://www.sendspace.com/file/b67cig



#2130 viljemt

viljemt

  •  Avatar image
  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:00 PM

Posted 20 February 2016 - 06:31 AM

Hi all!

 

Is it now possible to decrypt v3 .micro, .mp3?

 

 

 

Another thing: I have got one computer with .mp3 infection. I took away network connection. I found exe virus. If I run it, it encrypts all my new files...so...where does it stores the private key, if it does not have internet connection?

Is it possible to get it out the RAM when the virus is running?


Edited by viljemt, 20 February 2016 - 06:31 AM.





5 user(s) are reading this topic

0 members, 5 guests, 0 anonymous users