Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

files locked by RSA 2048


  • This topic is locked This topic is locked
4 replies to this topic

#1 zimmermann8

zimmermann8

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:23 AM

Posted 21 May 2015 - 05:44 PM

Is there any way to recover files locked? When I try to open file I get message " could not be found . Check  the spelling ..."

Please Help

 

yes I have some files with xlsx.exx

 

Is there any way to read them?


Edited by zimmermann8, 21 May 2015 - 06:52 PM.


BC AdBot (Login to Remove)

 


m

#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 50,560 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:23 AM

Posted 21 May 2015 - 06:33 PM

CryptoWall, Alpha Crypt & TeslaCrypt and some other ransomware infections encrypts data using RSA encryption...Ransom notes typically indicate "All of your files were protected by a strong encryption with RSA-2048."

Are there any file extensions appended to your files...such as .ecc, .ezz, .exx, .CTBL, .CTB2, .XTBL, .encrypted, .vault, .HA3 or 6-7 length extension consisting of random characters?

Did you find any ransom note? These infections are created to alert victims that their data has been encrypted and demand a ransom payment. Check your documents folder for an image the malware typically uses for the background note. Check the C:\ProgramData (or C:\Documents and Settings\All Users\Application Data) for a random named .html, .txt, .png, .bmp, .url file.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 zimmermann8

zimmermann8
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:23 AM

Posted 21 May 2015 - 06:54 PM

Is there any way to recover files locked? When I try to open file I get message " could not be found . Check  the spelling ..."

Please Help

 

yes I have some files with xlsx.exx

 

Is there any way to read them?

any yes there was a  Ransom notes

yes I have some files with xlsx.exx

 

Is there any way to read them?



#4 zimmermann8

zimmermann8
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:23 AM

Posted 21 May 2015 - 06:57 PM

 

Is there any way to recover files locked? When I try to open file I get message " could not be found . Check  the spelling ..."

Please Help

 

yes I have some files with xlsx.exx

 

Is there any way to read them?

any yes there was a  Ransom notes

yes I have some files with xlsx.exx

 

Is there any way to read them?

 

 

Is there any way to recover files locked? When I try to open file I get message " could not be found . Check  the spelling ..."

Please Help

 

yes I have some files with xlsx.exx

 

Is there any way to read them?

any yes there was a  Ransom notes

yes I have some files with xlsx.exx

 

Is there any way to read them?

 

 

Shadowexplore worked on some old files 4 and 5 years old


#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 50,560 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:23 AM

Posted 21 May 2015 - 07:01 PM

You are dealing with the newer unnamed variant of TeslaCrypt which is for the most part the same as Alpha Crypt. Any files that are encrypted by this variant will have the .exx extension added to the end of the filename.

A repository of all current knowledge regarding TeslaCrypt and Alpha Crypt is provided by Grinler (aka Lawrence Abrams), in this topic: TeslaCrypt and Alpha Crypt Ransomware Information Guide and FAQ

There is an ongoing discussion in this topic: New TeslaCrypt version that uses the .EXX extension.

Information about and support for decrypting files affected by Alpha Crypt & TeslaCrypt ransomware can be found in this topic:
TeslaDecoder released to decrypt .EXX, .EZZ, .ECC files encrypted by TeslaCrypt

Rather than have everyone start individual topics, it would be best (and more manageable for staff) if you posted any questions, comments or requests for assistance in that topic discussion. Doing that will also ensure you receive proper assistance from our crypto malware experts since they may not see this thread. To avoid unnecessary confusion...this topic is closed.

Thanks
The BC Staff
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users