Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

eCh0raix Ransomware - QNAPCrypt/Synology NAS (.encrypt) Support Topic


  • Please log in to reply
1210 replies to this topic

#151 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:08:05 AM

Posted 20 July 2019 - 09:04 AM

may i ask how you guys had the network drive show up for the decryption tools? I tried to map the drive and add as network address, both still cannot have RakhniDecryptor list them on the parameter option. sigh...

 

The decrypter probably has to run as administrator, which by default, does not share the same network drives as your actual user account.

 

Try the registry tweak in this article and reboot (under "More Information" at the bottom of the page).

 

https://support.microsoft.com/en-us/help/3035277/mapped-drives-are-not-available-from-an-elevated-prompt-when-uac-is-co

 

After the decryption, files without the .encrypt extension is created, but none of the files can be opened. The files seem to be corrupted.

Any people have alternative ways?

 

A real solution is coming soon. :wink:


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


BC AdBot (Login to Remove)

 


#152 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,119 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:07:05 PM

Posted 20 July 2019 - 01:25 PM

Any people have alternative ways?

 
The company DrWeb too decrypts files a week ago privately (paid service).
I have marked it as decryptable
 
But I have only screenshots in the Russian interface of the program.
Here you can see that the selected file and the other two are decrypted.
 
bYvLsfI.png

Mod Edit by quietman7 to include the following:

 

Dr.Web policy regarding the recovery of ransomware-corrupted files

Opening a support request with Dr.Web is free but if you're not a licensed user of a Dr.Web product already installed at the moment of infection, you will have to pay 150 € exc for their services (decrypter/personal decryption key) if they are able to calculate the decryption key. The fee includes a free two-year Dr.Web Security Space license for 1 computer as noted here. There is nothing to pay if Dr.Web cannot decrypt your files.


Edited by quietman7, 17 April 2023 - 02:39 PM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#153 GerdAlois

GerdAlois

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  

Posted 21 July 2019 - 09:01 AM

HELP!! Hello, I found my NAS yeserday moring hacked with some Ransomware. There was no message or something like that. All files are encrypted by fileextension "encrypt" and the following ransome note in a text file:

 

***

All your data has been locked(crypted).
How to unclock(decrypt) instruction located in this TOR website: http://qkqkro6buaqoocv4.onion/order/16sYqXAncDDiijcuruZecCkdBDwDf4vSEC
Use TOR browser for access .onion websites.
 
 
Do NOT remove this file and NOT remove last line in this file!
HSwJU+LOOQrjwlVsuAdV4VTQVKd8fY5GRoiQsXiNYsSAIDWQgmHegPaEAkjD2qUABxPkGmYQSyzH4sWEeoyGE3YgA2X/EV1VhMYyb8nCCLE/BER6sq4LRngtie4Nwlhq5KMqDGh6SgnoO1pNi+wnOOmUQ4A1wmeeVB6jdhIr4ts=
 
**
 
They want BTC 0.06.... Could not find any help seachring the net. Any ideas?
 
Thank you!
Gerd

Edited by quietman7, 21 July 2019 - 03:27 PM.


#154 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,119 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:07:05 PM

Posted 21 July 2019 - 12:23 PM

Hello, GerdAlois
 
For more than a month we have only seen affected users here using QNAP devices.
You are the first known affected user to us with the Synology device.
 
During this time, it became clear that the files in some cases can be decrypted.
1 way (it helps not always) is free, the victims themselves have found.
2 way (payment after calculating the decryption key) - private decoding by DrWeb specialists.
3 way (free decrypter) - is being prepared for publication, but will not be published until all victims receive help on the forum.

Edited by Amigo-A, 21 July 2019 - 03:17 PM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#155 GerdAlois

GerdAlois

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  

Posted 21 July 2019 - 01:19 PM

thks... would have some more details? 1 way.... or the DrWeb services? and how long is the wiat for 3?

new to this, never had to deal with such an issue...



#156 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,740 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:05 AM

Posted 21 July 2019 - 01:21 PM

Post #152 edited to include the following information.

 

Dr.Web policy regarding the recovery of ransomware-corrupted files

Opening a support request with Dr.Web is free but if you're not a licensed user of a Dr.Web product already installed at the moment of infection, you will have to pay 150 € exc for their services (decrypter/personal decryption key) if they are able to calculate the decryption key. The fee includes a free two-year Dr.Web Security Space license for 1 computer as noted here. There is nothing to pay if Dr.Web cannot decrypt your files.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#157 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,119 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:07:05 PM

Posted 21 July 2019 - 03:14 PM

GerdAlois
Your variant may be newer or similar to the first. I have already added an additional title to the article.
You need to wait for the response of the decryption specialists (3 way, free decrypter). They will need to further examine your case.

Edited by Amigo-A, 21 July 2019 - 03:20 PM.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#158 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,119 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:07:05 PM

Posted 21 July 2019 - 03:16 PM

I ask quietman7 to leave the topic open, that the victims could find it and respond here.


My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#159 hffung

hffung

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:10:05 PM

Posted 22 July 2019 - 12:40 AM

 

HELP!! Hello, I found my NAS yeserday moring hacked with some Ransomware. There was no message or something like that. All files are encrypted by fileextension "encrypt" and the following ransome note in a text file:

 

***

All your data has been locked(crypted).
How to unclock(decrypt) instruction located in this TOR website: http://qkqkro6buaqoocv4.onion/order/16sYqXAncDDiijcuruZecCkdBDwDf4vSEC
Use TOR browser for access .onion websites.
 
 
Do NOT remove this file and NOT remove last line in this file!
HSwJU+LOOQrjwlVsuAdV4VTQVKd8fY5GRoiQsXiNYsSAIDWQgmHegPaEAkjD2qUABxPkGmYQSyzH4sWEeoyGE3YgA2X/EV1VhMYyb8nCCLE/BER6sq4LRngtie4Nwlhq5KMqDGh6SgnoO1pNi+wnOOmUQ4A1wmeeVB6jdhIr4ts=
 
**
 
They want BTC 0.06.... Could not find any help seachring the net. Any ideas?
 
Thank you!
Gerd

 

 

â€

​My Synology DS218J is facing the same situation last Friday, from 0830-1345. Hope to find ways to decrypt. 



#160 arthurchan

arthurchan

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:05 PM

Posted 22 July 2019 - 02:55 AM

My NAS Synology also in same case . Hope to got the solution soon. 

 

Synology DX3615 DSM 6.1.5

 

**********

All your data has been locked(crypted).
How to unclock(decrypt) instruction located in this TOR website: http://qkqkro6buaqoocv4.onion/order/1LZ1VNJfn6mWjPzkCyoBvqWaBZYXAwn135
Use TOR browser for access .onion websites.
 
 
Do NOT remove this file and NOT remove last line in this file!
 
***********
Thanks all, hope to got help.

Edited by arthurchan, 22 July 2019 - 04:03 AM.


#161 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,119 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:07:05 PM

Posted 22 July 2019 - 03:24 AM

arthurchan

 

Write the name of the NAS device following the example of other users in the topic.


My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#162 Christophe29

Christophe29

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:France
  • Local time:04:05 PM

Posted 22 July 2019 - 05:06 AM

Hello,

 

My Synology DS214SE has been encrypted friday 19.07, about 11:00PM, same file .txt as shown above.

Stranger thing, only a directory I created has been crypted, the directories Drive, Music and others hasn't been impacted.

 

Maybe this ransomware use the "owner's creatd directory" to crypt datas ?

 

Another thing, not any of my 2 PCs are infected : I ran a full system scan with BitDefender on all HDD and nothing, so I don't understand how ransomware could reach the NAS ?


Edited by Christophe29, 22 July 2019 - 05:17 AM.


#163 zerocool64

zerocool64

  •  Avatar image
  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:05 PM

Posted 23 July 2019 - 01:53 AM

After the decryption, files without the .encrypt extension is created, but none of the files can be opened. The files seem to be corrupted.

Any people have alternative ways?

 

Could you share one of your file to let us test it.



#164 hffung

hffung

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:10:05 PM

Posted 23 July 2019 - 03:21 AM

​

 

 

After the decryption, files without the .encrypt extension is created, but none of the files can be opened. The files seem to be corrupted.

Any people have alternative ways?

 

Could you share one of your file to let us test it.

 

 

Thank you for your kindness. I have just sent you a private message. 



#165 ICTDuo

ICTDuo

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:05 PM

Posted 23 July 2019 - 11:07 AM

Hi guys,

 

unfortunately the same over here, also with a Synology NAS.

 

All your data has been locked(crypted).
How to unclock(decrypt) instruction located in this TOR website: http://qkqkro6buaqoocv4.onion/order/1N6JphHFaYmYaokS5xH31Z67bvk4ykd9CP
Use TOR browser for access .onion websites.
 
Do NOT remove this file and NOT remove last line in this file!
CncMq/0qAjswZzLwdn45Jro+Qk2D2S1DqKW4zBRoBnorTMJY0Tgum55VcmivsBdqloMpKjyRi0p5qz9oHE29WQlasCFaXaZUGF8UsVKiy0Jvqd54Gm9VdmbrEMQy64t7WmfN/TxLNhDiNM4MDFk++QaV1pSiudrESWsJ4B7bvQI=
 
Would be glad to get some help to get rid of this nasty problem.





6 user(s) are reading this topic

0 members, 6 guests, 0 anonymous users