Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Xorist (EnCiPhErEd) Ransomware Support Topic - HOW TO DECRYPT FILES.txt


  • Please log in to reply
563 replies to this topic

#31 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:07:15 AM

Posted 31 May 2016 - 05:34 PM

Posting this here to help with victims searching hopefully.

 

Found a new variant of Xorist that uses ".fileiscryptedhard" as extension, and the following ransom note "READ TO DECRYPTIONS_.txt".

 

 

All your data files are crypted.

To decrypt files and gain access to them,
please send 0.5 Bitcoin to adress
194DQmxsSsM4Xp2CozvxatH2WkxA7AnV1f
 
and email to fn1573917917ja@163.com proof
(screen or TransID) of your payment.
 
After receiving the money, I will send you
your password and decrypt instruction via email.
 
You can also send a single crypted file and I 
will send you the decryption for your peace of mind.

 

Fabian's decrypter works with this new variant. :)


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


BC AdBot (Login to Remove)

 


#32 ResonantSolns

ResonantSolns

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:15 PM

Posted 17 June 2016 - 03:39 PM

Hi All,

 

Used the provided tool and an encrypted and non encrypted file to find the key.  So the tool was successful but now what do we do ?

 

Do I need to find the original executable that encrypted the files and run that ? Or is there another solution 

Regards

 



#33 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:07:15 AM

Posted 17 June 2016 - 03:42 PM

If the decrypter found a tool, it will guide you through decrypting your data using the key.

 

Do NOT run the malware again. If the decrypter doesn't work, we may need the malware for analysis. You may submit it here: http://www.bleepingcomputer.com/submit-malware.php?channel=168


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#34 ResonantSolns

ResonantSolns

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:15 PM

Posted 17 June 2016 - 05:28 PM

Yes,  I ran the decryption tool again and once it found the key it decrypted the data. Thank you for the tool and the instructions. 



#35 gospirus

gospirus

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:15 PM

Posted 25 June 2016 - 01:27 PM

i've send my EnCiPhErEd Ransomware sample to http://www.bleepingcomputer.com/submit-malware.php?channel=168

using email contact gospirus@gmail.com

 

thank you for helping



#36 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  •  Avatar image
  • Malware Response Instructor
  • 6,088 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:02:15 PM

Posted 25 June 2016 - 01:32 PM

i've send my EnCiPhErEd Ransomware sample to http://www.bleepingcomputer.com/submit-malware.php?channel=168

using email contact gospirus@gmail.com
 
thank you for helping

Have you tried this decrypter?
 
xXToffeeXx~


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#37 gospirus

gospirus

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:15 PM

Posted 25 June 2016 - 02:27 PM

 

i've send my EnCiPhErEd Ransomware sample to http://www.bleepingcomputer.com/submit-malware.php?channel=168

using email contact gospirus@gmail.com
 
thank you for helping

Have you tried this decrypter?
 
xXToffeeXx~

 

 

 

hello, thank you for fasting reply..

 

ive tried decrypter

 

see this my screenshot

 

Screenshot_17.png

 

Screenshot_16.png



#38 Fabian Wosar

Fabian Wosar

    Authorized Emsisoft Representative


  •  Avatar image
  • Security Developer
  • 744 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:15 PM

Posted 25 June 2016 - 03:25 PM

The screenshots don't show up. Did you select both an encrypted and its unencrypted original version at the same time and drag and dropped it onto the decrypter executable file?
Best regards,

Fabian Wosar [Development]
Emsisoft Team - www.emsisoft.com

#39 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:07:15 AM

Posted 25 June 2016 - 03:37 PM

The second screenshot shows for me. It shows the Xorist decrypter at about 31% - you'll need to just let it run, it may take some time as it states.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#40 gospirus

gospirus

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:15 PM

Posted 25 June 2016 - 03:39 PM

The screenshots don't show up. Did you select both an encrypted and its unencrypted original version at the same time and drag and dropped it onto the decrypter executable file?

 

 

i dont have unencrypted original version file

so i just put like this new screenshot have i uploaded to you again

 

788348f52ce5432fb23acc5a96f58394.png

 

 

d819d3b2e46f4cb0aed19729cd6ea269.png



#41 Fabian Wosar

Fabian Wosar

    Authorized Emsisoft Representative


  •  Avatar image
  • Security Developer
  • 744 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:15 PM

Posted 25 June 2016 - 03:47 PM

i dont have unencrypted original version file

so i just put like this new screenshot have i uploaded to you again


That will not work. It has to be the original. I don't believe you that there is no file on your system where you can't get the original of. Examples: Files you downloaded from the internet that were encrypted, that you can simply download again to get the original, pictures that you shared with friends that they can just send you back, default wallpapers and pictures that were included with your Windows version that you can just get from another system running the same Windows version. There are plenty of ways to get an encrypted with unencrypted file pair.
Best regards,

Fabian Wosar [Development]
Emsisoft Team - www.emsisoft.com

#42 gospirus

gospirus

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:15 PM

Posted 25 June 2016 - 03:47 PM

The second screenshot shows for me. It shows the Xorist decrypter at about 31% - you'll need to just let it run, it may take some time as it states.

 

loading is done buddy, but when i checked again my file still not decrypt :(

 

c67b7f6030364541ba4a8e911428bfb5.png

 

 

93cbc91c757048e7a26b175d7f181f26.png



#43 gospirus

gospirus

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:15 PM

Posted 25 June 2016 - 03:52 PM

 

i dont have unencrypted original version file

so i just put like this new screenshot have i uploaded to you again


That will not work. It has to be the original. I don't believe you that there is no file on your system where you can't get the original of. Examples: Files you downloaded from the internet that were encrypted, that you can simply download again to get the original, pictures that you shared with friends that they can just send you back, default wallpapers and pictures that were included with your Windows version that you can just get from another system running the same Windows version. There are plenty of ways to get an encrypted with unencrypted file pair.

 

 

Well then, I'll try to copy files image original from my mobile phone similar with that encrypt files in my harddisk, and use the software Emsisoft again



#44 Fabian Wosar

Fabian Wosar

    Authorized Emsisoft Representative


  •  Avatar image
  • Security Developer
  • 744 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:02:15 PM

Posted 25 June 2016 - 03:52 PM

Can you upload the encrypted and unencrypted file pair you used as well as some of the files that don't decrypt properly here please? I will look into it tomorrow:

http://www.bleepingcomputer.com/submit-malware.php?channel=170
Best regards,

Fabian Wosar [Development]
Emsisoft Team - www.emsisoft.com

#45 gospirus

gospirus

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:15 PM

Posted 25 June 2016 - 04:02 PM

 

i dont have unencrypted original version file

so i just put like this new screenshot have i uploaded to you again


That will not work. It has to be the original. I don't believe you that there is no file on your system where you can't get the original of. Examples: Files you downloaded from the internet that were encrypted, that you can simply download again to get the original, pictures that you shared with friends that they can just send you back, default wallpapers and pictures that were included with your Windows version that you can just get from another system running the same Windows version. There are plenty of ways to get an encrypted with unencrypted file pair.

 

 

did you mean like this brother...?

http://prntscr.com/bl103b






2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users