Tom's Hardware > Forum > Windows XP > Windows XP General Discussion > Documents and music files 'ncrypted' - trying to revert the change

Documents and music files 'ncrypted' - trying to revert the change

Forum Windows XP : Windows XP General Discussion - Documents and music files 'ncrypted' - trying to revert the change

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

I have a customer whos PC has been hit with some form of virus/script/whatever. The end result is that all the document (.doc, .ppt etc) and music files have been changed to an unreadable state.

The initial symptom is that the files are renamed to xxxx.doc.NCRYPTED.NCRYPTED.NCYRPTED.NCRYPTED.ncrypted

Renaming the file to remove the rubbish on the end makes no difference as the file is still unreadable - appears the file header has been altered perhaps?

There is also a text file left behind with the following:

"Some files on your machine are encrypted and your private informations were collected and sent to us.
To decrypt files so you could use them again, you have to buy our decryptor.
After you buy decryptor, your files will be decrypted, and we will destroy your private informations from our system, and help you remove malicious software from your system.
To buy decryptor, contact us at: thankyoumuchos@gmail.com or meloveyoug@yahoo.com
If you dont contact us, your private informations will be shared and you will loose all your data."

Normally, I would just run a format & reinstall the system but in this case the customer is desperate to keep their data since they have no backup.
So far I have run multiple virus scans with NOD32 which has pulled off some 30+ infections. I have also run spyware scans but of course this has had no effect.
Goggle has so far been unable to help and I'm not very confident of being able to get this resolved.

Any ideas or help would be greatly appreciated!

Desperate

Sponsored Links
Register or log in to remove.
- 0 +

First step is to identify which "RansomWare" was detected, some are easy to remove and the decrypting keys can be found by Google, others are almost impossable to remove.

PS: In my humble opinion: To get 30+ infections on a machine with no backup takes a special kind of idiot.

Reply to MrLinux
- 0 +

how to identify which "RansomWare" is it? and how to remove?
Please reply at kwakvk@yahoo.com

Reply to quartz
- 0 +

Most up to date anti-virus tools will detect and identify, you then use Google to see if there any removal tools/instructions available.

Reply to MrLinux
- 0 +

Did anyone figure out which virus this is (leaves .NCRYPTED files)

Reply to amoffit

the Virus i believe is a win32.gpcode virus.
Ive been researching this problem for 2 days now and there isn't much out there.

According to the Kasparsky AV team (they seem to be the only ones on top of this) its a virus that people have modifed so its hard to keep up with. they also state the data is not recoverable... (but give you recommendations on what might work) :S

if anyone has found different i would love to know as i have a client who was rather upset when i told her she had lost everything.
i have followed this guide below with not to much joy but hopefully it will work for one of you.
PhotoRec may do the job, its hard to tell with the amount of data it brings back.

http://www.viruslist.com/en/viruse [...] sid=313444

Good luck and if anyone finds out anything more please let me know.

Reply to ITtech2009
Tom's Hardware > Forum > Windows XP > Windows XP General Discussion > Documents and music files 'ncrypted' - trying to revert the change
Go to:

There are 1073 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them