Jump to content

Fastwind ransomware, need help with decryption

Go to solution Solved by Eigenvektor,

A quick Google suggests that there is currently no decryption tool available. https://www.pcrisk.com/removal-guides/18583-fastwind-ransomware

Quote

Unfortunately, there are no third party tools that are capable of decryption of files compromised by FastWind. Despite this, you are advised against contacting these cyber criminals or paying for any decryption tools. They often do not send any tools even, after payment.

Decryption tools are only possible if the ransomware itself has a vulnerability that can be exploited or the key is made public somehow. When it uses modern encryption algorithms and the key is randomly generated, there's virtually no way to decrypt files without getting access to the key.

Hey !

Our Truenas core at work was infected with ransomware, the IT guys never turned on snapshots聽馃檮聽so we're in a bit of a pickle.

I wanted to ask if any of you has has experience with this particular ransomware and could point me to a decryption tool, I could not find one on Kaspersky, Avast, Emsisoft nor Nomoreransom.

All of our files now have this extension : "DZF2QX5SJ".

Attached is also the message as a picture

Thanks !

rsnwr.PNG

Link to comment
Share on other sites

Link to post
Share on other sites

It's real ransomware, there's no such thing as a secret shortcut decryption tool.

You'll need to pay and pray that they "honour" the payment.

Link to comment
Share on other sites

Link to post
Share on other sites

A quick Google suggests that there is currently no decryption tool available. https://www.pcrisk.com/removal-guides/18583-fastwind-ransomware

Quote

Unfortunately, there are no third party tools that are capable of decryption of files compromised by FastWind. Despite this, you are advised against contacting these cyber criminals or paying for any decryption tools. They often do not send any tools even, after payment.

Decryption tools are only possible if the ransomware itself has a vulnerability that can be exploited or the key is made public somehow. When it uses modern encryption algorithms and the key is randomly generated, there's virtually no way to decrypt files without getting access to the key.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Eigenvektor said:

A quick Google suggests that there is currently no decryption tool available. https://www.pcrisk.com/removal-guides/18583-fastwind-ransomware

Decryption tools are only possible if the ransomware itself has a vulnerability that can be exploited or the key is made public somehow. When it uses modern encryption algorithms and the key is randomly generated, there's virtually no way to decrypt files without getting access to the key.

Welp, that's what I thought, thanks for the help !

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now