Decryption of The Crypto Locky Virus Files

Status
Not open for further replies.

ITBFDR

Honorable
Aug 9, 2012
3
0
10,510
In addition to my first post i would like to ask if anyone has succeeded to decrypt the encrypted files of the Locky or Crypto virusses as this will make recovery easier Thank You! I tried some programs including some Forensic Programs Talos Decryptor it seems like this virus encrypts the files when its on the PC once removed the files are over written or corrupted
 

Mankar Kameran

Estimable
Jul 13, 2015
38
0
4,610
In my experience with this virus, I used Malwarebytes to get rid of the virus and then I used shadow explorer to get back the files. A system restore would be easier, but that wasn't an option.
 

ZippyPeanut

Honorable
Dec 26, 2012
28
0
10,590


I'm very curious about this. First, I wonder how shadow explorer can get back encrypted files. And why wasn't a system restore an option? (In the past, I have removed non-encryption ransom ware via a simple system restore. But my understanding of cyptolockers is that once the files are encrypted, nothing but the key will unlock them.)
 

trog7777

Commendable
May 14, 2016
1
0
1,510


For a start , some of these encryptor virus actually destroy the restore points, and delete the shadow volume !
So once they hit - you're up the creek without a paddle, if you don't have any recent backups, which weren't connected to the computer at the time of infection ! - because these malicious file destroyers will infect Every drive or usb storage within shouting distance - that is - All and every drive - whether physically connected or networked, even unmapped, Will be corrupted.! ... You can remove the Virus, but getting the files back is very hit and miss.
I have just seen the damage of this nasty on a friends business computer. and No unfortunately they didn't have a recent backup of the essential docs and other files - and No the shadow files were 95% unusable !
 
Status
Not open for further replies.