Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

CryptoSearch - Find Files Encrypted by Ransomware


  • Please log in to reply
69 replies to this topic

#16 vilhavekktesla

vilhavekktesla

  •  Avatar image
  • Members
  • 918 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:07 AM

Posted 25 January 2017 - 08:56 PM

Hmm, sorry I requested features before reading this topic. You have considered a few things and we just need to understand how to use the program. Hopefully a clear and easy to follow instructions file is included in the zip-file.

 

Cool program and I'm amased over your imagination and creativity.

 

Continue the fight and help victims :)


The signature points to post one in each topic. Post one is very important to read.

Now Teslacrypt may be decrypted with Blooddolly's Tesladecoder version 1.0.1b or newer (if needed)

The master key is released so there is no need to pay to get the key.

About 200 550 different ransomwares exist so think safe backups at all time.


BC AdBot (Login to Remove)

 


#17 vilhavekktesla

vilhavekktesla

  •  Avatar image
  • Members
  • 918 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:07 AM

Posted 25 January 2017 - 09:05 PM

Hi Michael

 

With FF 50.1.0 I get from this page:
https://download.bleepingcomputer.com/demonslay335/CryptoSearch.zip
 

I can ignore it as the page is pink not red (as of today)

 

 

Reported Unwanted Software Page!
This web page at download.bleepingcomputer.com has been reported to contain unwanted software and has been

blocked based on your security preferences.

Unwanted software pages try to install software that can be deceptive and affect your system in unexpected ways.

 

 

I have no specific security setting just the normal FF-settings
That is to bad and it will probably not be removed unless you get another download address or you contact Mozilla and tell them to update their bad filters. I guess your SW got this problem from one of the earliest copies you had and that is the reason you chose to password protect the file.

 

Anyway I thought you like to know about it.

 

Best regards


The signature points to post one in each topic. Post one is very important to read.

Now Teslacrypt may be decrypted with Blooddolly's Tesladecoder version 1.0.1b or newer (if needed)

The master key is released so there is no need to pay to get the key.

About 200 550 different ransomwares exist so think safe backups at all time.


#18 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 26 January 2017 - 05:35 AM

Having trouble to unzip and install CryptoSearch. Error when extracting "Unknown method in CryptoSearch.zip" Chrome browser blocks file as Dangerous when attempting to download.

Bleeping Computer's hosted programs for download are trustworthy, safe and malware-free. However, depending on the product, some anti-virus software and other security scanners may flag certain programs as a threat for a variety of reasons when that is not the case. In these instances the detection is a "false positive" and can be ignored.

Most of the well known specialized tools we use against malware are written by experts/Security Colleagues at various security forums like Bleeping Computer, TechSupport, GeeksToGo, Emsisoft and other similar sites so they can be trusted...this includes any program hosted by BC for download. Unfortunately, many of these tools (or their embedded files) are falsely detected by various anti-virus programs from time to time. This in turn sometimes results in an inaccurate site rating/warning of potentially dangerous software when that is not the case.

Rest assured our Security Colleagues are trustworthy and all the programs hosted for downloading here at BleepingComputer are malware-free and perfectly safe to use.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#19 tibor-s

tibor-s

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:07 AM

Posted 08 February 2017 - 12:24 PM

Hi, 

I am infected by Spora Ransomware. I downloaded the latest version of CryptoSearch, the program refreshed the Network, but I can't find Spora in the Ransomware list to search for the Encrypted files.

Can you please advise.

 

Regards



#20 Demonslay335

Demonslay335

    Ransomware Hunter

  • Topic Starter

  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 08 February 2017 - 12:27 PM

Hi, 

I am infected by Spora Ransomware. I downloaded the latest version of CryptoSearch, the program refreshed the Network, but I can't find Spora in the Ransomware list to search for the Encrypted files.

Can you please advise.

 

Regards

 

Spora does not have any file extension or file marker to go by, so I'm afraid CryptoSearch won't be able to help in that case. The program only pulls in ransomware from ID Ransomware that have such indicators.


Edited by Demonslay335, 08 February 2017 - 12:27 PM.

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#21 priteshpatel100

priteshpatel100

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:07 PM

Posted 17 February 2017 - 02:50 PM

the cryptoshield 2.0 virus  with .id and .QBP have word and pdf files encrypted.

 

If you pay bitcoin and how do you pay they wanted 2 , will the files open

 

http://www.enigmasoftware.com/cryptoshield20ransomware-removal/

 

they say  can remove with spyhunter, is that true

 

 

How can i remove that. ALL HELP IS APPRECIATED. thanks

 

 

 

 NOT YOUR LANGUAGE? USE http://translate.google.com

 What happens to you files?
 All of your files were encrypted by a strong encryption with RSA-2048 using CryptoShield 2.0. DANGEROUS.
 More information about the encryption keys using RSA-2048 can be found here: https://en.wikipedia.org/wiki/RSA_(cryptosystem)

 How did this happen ?
 Specially for your PC was generated personal RSA - 2048 KEY, both public and private.
 ALL your FILES were encrypted with the public key, which has been transferred to your computer via the Internet.
 Decrypting of your files is only possible with the help of the private key and decrypt program , which is on our secret server.

 What do I do ?
 So, there are two ways you can choose: wait for a miracle and get your price doubled, or start send email now for more specific instructions,
 and restore your data easy way.
 If You have really valuable data, you better not waste your time, because there is no other way to get your files, except make  payment.

 To receive your private software:
 Contact us by email , send us an email your (personal identification) ID number and wait for further instructions.
 Our specialist will contact you within 24 hours.
 ALL YOUR FILES ARE ENCRYPTED AND LOCKED, YOU CAN NOT DELETE THEM, MOVE OR DO SOMETHING WITH THEM. HURRY TO GET BACK ACCESS FILES.
 Please do not waste your time! You have 72 hours only! After that The Main Server will double your price!
 So right now You have a chance to buy your individual private SoftWare with a low price!

 CONTACTS E-MAILS:
 res_sup@india.com - SUPPORT;
 res_sup@computer4u.com - SUPPORT RESERVE FIRST;
 res_reserve@india.com - SUPPORT RESERVE SECOND;



#22 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,818 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:07 AM

Posted 17 February 2017 - 03:59 PM

This is not a ransomware support topic.

You have already posted the above here. Please do not create duplicate postings and be patient until someone is able to answer you.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#23 al1963

al1963

  •  Avatar image
  • Members
  • 1,178 posts
  • OFFLINE
  •  
  • Local time:12:07 PM

Posted 12 March 2017 - 08:54 AM

@Demonslay335,

 

if it became possible,

https://twitter.com/demonslay335/status/840335629397479424

will the Spora Detect be added to the CryptoSearch database?



#24 Demonslay335

Demonslay335

    Ransomware Hunter

  • Topic Starter

  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 12 March 2017 - 11:47 AM

I had to make a special plugin for it on ID Ransomware to calculate the CRC32 and match it against the potentially stored checksum, so it can't pass that behavior automatically to CryptoSearch. I've been thinking of adding it to CryptoSearch, but it will require a lot of work to make a similar plugin system. Maybe in the future though. :)

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#25 matthew9871

matthew9871

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:07 PM

Posted 18 March 2017 - 11:16 PM

thank you will test this out tomorrow.... matrix ransomware got me, I really need help with this as there was no backup. thank you again.



#26 Demonslay335

Demonslay335

    Ransomware Hunter

  • Topic Starter

  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 25 March 2017 - 08:39 PM

I've released v0.9.5.0 that can identify files encrypted by Spora. :)

 

C7zsywUXkAAwrHJ.jpg


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#27 al1963

al1963

  •  Avatar image
  • Members
  • 1,178 posts
  • OFFLINE
  •  
  • Local time:12:07 PM

Posted 27 March 2017 - 07:04 AM

@Demonslay335,

 

What could be the reason?

 

 

Retrieving data from ID Ransomware...
Error retrieving ransomware data from network: The remote server returned an error: (403) Forbidden.
Retrieving data from local filesystem...
Error retrieving ransomware data from filesystem: (2) Не удается найти указанный файл: [\\?\e:\deshifr\Tools\CryptoSearch\cryptosearch-definitions.bin]

 

 



#28 Demonslay335

Demonslay335

    Ransomware Hunter

  • Topic Starter

  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 27 March 2017 - 08:08 AM

The site has been under DDoS attacks recently, so we've had to put CloudFlare into "Attack Mode". Should be temporary here.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


#29 ProfessorExe

ProfessorExe

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:07 AM

Posted 27 March 2017 - 12:50 PM

The site has been under DDoS attacks recently, so we've had to put CloudFlare into "Attack Mode". Should be temporary here.

Any idea on an ETA? 



#30 Demonslay335

Demonslay335

    Ransomware Hunter

  • Topic Starter

  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 27 March 2017 - 01:10 PM

 

The site has been under DDoS attacks recently, so we've had to put CloudFlare into "Attack Mode". Should be temporary here.

Any idea on an ETA? 

 

 

It should be up most of the time, we just periodically have to put it into that mode as needed.


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users