Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

TeslaDecoder released to decrypt


  • This topic is locked This topic is locked
4 replies to this topic

#1 kurosaki01

kurosaki01

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:39 AM

Posted 18 May 2018 - 06:28 AM

Hi members of the site Bleeping Computer  asked you to decode the virus scarab

This is the text of the code 

 

-----BEGIN PERSONAL IDENTIFIER-----
+QIAAAAAAABFbXszHZFLFcAkCAOjlD3AzSzapIpP=RcaQTh1oybf+aphtE=Vb0W8J8w+pXZP7tyZ1eK99ZjLcmqumrU0KnMNf2Xg
VPOpYnsThmM0NgIWUvPWXIUV79X2WWpr2vLYfLSml6ACwTH5Agy3LP1a4BOaupgqIA0aXSiaa7azqhiShkqvUb92KmtRQIEFtEgu
5V0G1MkOySZtCFB9J0l+djNomlcUqY43GpaxhlFNn=p=J=xl+6GhKxtnKBXNGDI0f4zqNWchy8=g4nPt0vIebAvIO=sxSUzL0KDb
T3R9AVpAJCtBRKBKE+SqD4IDvH2jdp2MahMKGiMCclxvl=l94Z4Bzdki4IgwYihBGt1aVijoY43l4PMWNuZiMhcqKKa7VbZtk=uC
hBH6bjdY205Yq2hy9iq0K=2YRnvvAA
-----END PERSONAL IDENTIFIER-----
 

Please help me and you very much

My files have been encrypted and I want to restore them


Edited by hamluis, 18 May 2018 - 09:24 AM.
Moved from Introductions to Ransomware - Hamluis.


BC AdBot (Login to Remove)

 


#2 HarryBaker

HarryBaker

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:12:39 AM

Posted 18 May 2018 - 08:24 AM

Hi mate, what exactly are you asking for here? Are you able to be a bit clearer with what information you are trying to get?



#3 kurosaki01

kurosaki01
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:39 AM

Posted 18 May 2018 - 08:43 AM

Hi mate, what exactly are you asking for here? Are you able to be a bit clearer with what information you are trying to get?

My files have been encrypted and I want to restore them

 

 

 

__________________________________________________________________________________________________

|                                                                                                  |
|                 *** IF YOU WANT TO GET ALL YOUR FILES BACK, PLEASE READ THIS ***                 |
|__________________________________________________________________________________________________|
 
Your files are now encrypted!
 
-----BEGIN PERSONAL IDENTIFIER-----
+QIAAAAAAABFbXszHZFLFcAkCAOjlD3AzSzapIpP=RcaQTh1oybf+aphtE=Vb0W8J8w+pXZP7tyZ1eK99ZjLcmqumrU0KnMNf2Xg
VPOpYnsThmM0NgIWUvPWXIUV79X2WWpr2vLYfLSml6ACwTH5Agy3LP1a4BOaupgqIA0aXSiaa7azqhiShkqvUb92KmtRQIEFtEgu
5V0G1MkOySZtCFB9J0l+djNomlcUqY43GpaxhlFNn=p=J=xl+6GhKxtnKBXNGDI0f4zqNWchy8=g4nPt0vIebAvIO=sxSUzL0KDb
T3R9AVpAJCtBRKBKE+SqD4IDvH2jdp2MahMKGiMCclxvl=l94Z4Bzdki4IgwYihBGt1aVijoY43l4PMWNuZiMhcqKKa7VbZtk=uC
hBH6bjdY205Yq2hy9iq0K=2YRnvvAA
-----END PERSONAL IDENTIFIER-----
 
All your files have been encrypted due to a security problem with your PC.
 
Now you should send us email with your personal identifier.
This email will be as confirmation you are ready to pay for decryption key.
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us.
After payment we will send you the decryption tool that will decrypt all your files. 
 
Contact us using this email address: help@wizrac.com   
 
 
Free decryption as guarantee!
Before paying you can send us up to 3 files for free decryption.
The total size of files must be less than 10Mb (non archived), and files should not contain
valuable information (databases, backups, large excel sheets, etc.).
 
 __________________________________________________________________________________________________
|                                                                                                  |
|  How to obtain Bitcoins?                                                                         |
|                                                                                                  |
| * The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click             |
|   'Buy bitcoins', and select the seller by payment method and price:                             |
|   
| * Also you can find other places to buy Bitcoins and beginners guide here:                       |
|   
|                                                                                                  |
|__________________________________________________________________________________________________|
 
 __________________________________________________________________________________________________
|                                                                                                  |
| Attention!                                                                                       |
|                                                                                                  |
| * Do not rename encrypted files.                                                                 |
| * Do not try to decrypt your data using third party software, it may cause permanent data loss.  |
| * Decryption of your files with the help of third parties may cause increased price              |
|   (they add their fee to our) or you can become a victim of a scam.                              |
|                                                                                                  |
|__________________________________________________________________________________________________|
 


#4 HarryBaker

HarryBaker

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:12:39 AM

Posted 18 May 2018 - 08:48 AM

I see, okay here is a link to TALOS which is owned by Cisco so it is secure and trusted. https://www.talosintelligence.com/teslacrypt_tool

 

As mentioned, it is a test tool so it is used at your own risk. Here is the guide on how to use the decryption tool https://blogs.cisco.com/security/talos/teslacrypt

 

Let me know how you get on 



#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,744 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:39 PM

Posted 18 May 2018 - 10:33 AM

TeslaDecoder was a decryption tool for TeslaCrypt Ransomware., not Scarab.

Dr.Web may be able to decrypt some variants of Scarab Ransomware but they need the ransom note and 3-4 encrypted files as indicated here.

If you have been infected by Scarab Ransomware, please PM Emmanuel_ADC-Soft for assistance.

I am working for Dr.Web support.
Please send a link at www.wetransfer.com with the ransom note and 3-4 crypted files. Kind regards,
Emmanuel (emte@adc-soft.com)

Opening a support request with Dr.Web is free but if you're not a licensed user of a Dr.Web product you will have to pay 150 exc for their services (decrypter/personnal decryption key) if they are able to calculate the decryption key. The fee includes a free two-year Dr.Web Security Space license for 1 computer as noted here.

If Dr.Web cannot assist with the Scarab variant which infected your system, then unfortunately, there is no other known method at this time to decrypt files without paying the ransom. If possible, your best option is to restore from backups, try file recovery software or backup/save your encrypted data as is and wait for a possible solution at a later time.

There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.Rather than have everyone with individual topics, it would be best (and more manageable for staff) if you posted any more questions, comments or requests for assistance in the above support topic discussion...it includes experiences by experts, a variety of IT consultants, end users and company reps who have been affected by ransomware infections. To avoid unnecessary confusion, this topic is closed.

Thanks
The BC Staff
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users