Jump to content

This is a Cryakl type ransomware. Never click those fake links in your e-mail kids.

 

The only tool that can even remotely rescue your files is this one. If it can't, the files are hosed. 

 

http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip

 

and the manual is here:

 

https://www.nomoreransom.org/uploads/RakhniDecryptor_how-to_guide.pdf

5 minutes ago, AkiTech said:

can it still be called an anti virus for letting this happen. lol :/ 

Well, antivirus software can't protect from stupidity like clicking fake links in e-mails. By the time the antivirus has detected the problem, the files are already encrypted. Free antivirus software (and Windows Defender especially) really don't do this well.

PC Specs - AMD Ryzen 7 5800X3D MSI B550M Mortar - 32GB Corsair Vengeance RGB DDR4-3600 @ CL16 - ASRock RX7800XT 660p 1TBGB & Crucial P5 1TB Fractal Define Mini C CM V750v2 - Windows 11 Pro

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543932
Share on other sites

Link to post
Share on other sites

9 minutes ago, JointedFish said:

Well, you could try access data password recovery program and find some Dictionarys to check them for. If you have the gpu horsepower. But most likely its a big fat no, and paying for it dosn't garentee you'll get your stuff back.

I guess of to reformat then. If it really is a waste of time trying to get help and try to recover these.

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543935
Share on other sites

Link to post
Share on other sites

1 minute ago, NelizMastr said:

This is a Cryakl type ransomware. Never click those fake links in your e-mail kids.

 

The only tool that can even remotely rescue your files is this one. If it can't, the files are hosed. 

 

http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip

Well, antivirus software can't protect from stupidity like clicking fake links in e-mails. By the time the antivirus has detected the problem, the files are already encrypted. Free antivirus software (and Windows Defender especially) really don't do this well.

 

1 minute ago, NelizMastr said:

This is a Cryakl type ransomware. Never click those fake links in your e-mail kids.

 

The only tool that can even remotely rescue your files is this one. If it can't, the files are hosed. 

 

http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip

Well, antivirus software can't protect from stupidity like clicking fake links in e-mails. By the time the antivirus has detected the problem, the files are already encrypted. Free antivirus software (and Windows Defender especially) really don't do this well.

i dont recall clicking links of sort. but I will try what you gave, hope it at least gets most of it :(  

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543941
Share on other sites

Link to post
Share on other sites

2 minutes ago, AkiTech said:

 

i dont recall clicking links of sort. but I will try what you gave, hope it at least gets most of it :(  

It doesn't get on your system by itself. It was either a malicious e-mail, link or software download.

PC Specs - AMD Ryzen 7 5800X3D MSI B550M Mortar - 32GB Corsair Vengeance RGB DDR4-3600 @ CL16 - ASRock RX7800XT 660p 1TBGB & Crucial P5 1TB Fractal Define Mini C CM V750v2 - Windows 11 Pro

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543944
Share on other sites

Link to post
Share on other sites

8 minutes ago, AkiTech said:

I guess of to reformat then. If it really is a waste of time trying to get help and try to recover these.

 

I mean, it dosn't hurt to try, but these kinds of ransomware is a big massiv a hole. Best is to live and learn about the use of regular day to day uses of computers and on the internet. However, being targeted is a whole diffrent story.

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543959
Share on other sites

Link to post
Share on other sites

4 minutes ago, AkiTech said:

I know. It may not be "me" since I'm not the only person using this pc :(

In that case, make sure you use a separate removable disk to store your valuable data on and regularly scan for malware.

PC Specs - AMD Ryzen 7 5800X3D MSI B550M Mortar - 32GB Corsair Vengeance RGB DDR4-3600 @ CL16 - ASRock RX7800XT 660p 1TBGB & Crucial P5 1TB Fractal Define Mini C CM V750v2 - Windows 11 Pro

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543963
Share on other sites

Link to post
Share on other sites

1 minute ago, JointedFish said:

I mean, it dosn't hurt to try, but these kinds of ransomware is a big massiv a hole. Best is to live and learn about the use of regular day to day uses of computers and on the internet. However, being targeted is a whole diffrent story.

I havent slept for like 30+ hours trying to look for something to get these files back. so yeah. "being targeted is a whole different story"  

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543969
Share on other sites

Link to post
Share on other sites

I've read that this Cryakl is fairly new. so would you guys suggest I keep the locked files on a separate drive and wait for a decryptor in the future?? coz I'll be reformatting my pc and make sure that I'll secure it this time and nobody collects malicious stuff that count infect the pc.

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11543993
Share on other sites

Link to post
Share on other sites

34 minutes ago, AkiTech said:

I've read that this Cryakl is fairly new. so would you guys suggest I keep the locked files on a separate drive and wait for a decryptor in the future?? coz I'll be reformatting my pc and make sure that I'll secure it this time and nobody collects malicious stuff that count infect the pc.

 

If the files are important to you then there is no harm to keep them and then decrypt them in the future.

But ill also recommend keeping your important stuff on an external hdd/ssd, and disconnecting it when others are using the computer.

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11544105
Share on other sites

Link to post
Share on other sites

1 hour ago, AkiTech said:

can it still be called an anti virus for letting this happen. lol :/ 

Right. :) I'm just saying that everyone tells how important is to have AV installed, while it's not true. Virus creators have access to that software too, so it's just waste of CPU to use software that gives you nothing except false feel of being secure. I'm using only Comodo Firewall and while it does not scan my files against viruses, it report me every program that wants to connect to internet, so this way i found more dangerous stuff than any AV crap. The only you can get using AV is lot of false positives while viruses works like they want.

 

And it's not true that AV was too slow. AV doesn't work that way. Before any file will be executed, is first scanned (that is the main reason why AV slows down computers). So, your AV just let virus to encrypt your files. Try to not install that piece of #$_& next time - effect will be the same except faster windows. Install Comodo Firewall, select custom mode, disable file analysis (you should decide, not program) and any predefined entries and settings and enjoy.

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11544168
Share on other sites

Link to post
Share on other sites

15 minutes ago, wasab said:

So glad I'm on Linux. Hahaha

If Office 365 was a thing on Linux, I'd use it both at home and at work lol, but alas.

PC Specs - AMD Ryzen 7 5800X3D MSI B550M Mortar - 32GB Corsair Vengeance RGB DDR4-3600 @ CL16 - ASRock RX7800XT 660p 1TBGB & Crucial P5 1TB Fractal Define Mini C CM V750v2 - Windows 11 Pro

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11544244
Share on other sites

Link to post
Share on other sites

On 7/17/2018 at 11:37 PM, Teddy07 said:

You need to find out which program encrypted your files. I think there is only a very small chance to get your files back

I gave up, so now I came back with a "reformatted" PC *sigh* hope I could build a desktop already.

 

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11549744
Share on other sites

Link to post
Share on other sites

On 7/17/2018 at 10:25 PM, homeap5 said:

Right. :) I'm just saying that everyone tells how important is to have AV installed, while it's not true. Virus creators have access to that software too, so it's just waste of CPU to use software that gives you nothing except false feel of being secure. I'm using only Comodo Firewall and while it does not scan my files against viruses, it report me every program that wants to connect to internet, so this way i found more dangerous stuff than any AV crap. The only you can get using AV is lot of false positives while viruses works like they want.

 

And it's not true that AV was too slow. AV doesn't work that way. Before any file will be executed, is first scanned (that is the main reason why AV slows down computers). So, your AV just let virus to encrypt your files. Try to not install that piece of #$_& next time - effect will be the same except faster windows. Install Comodo Firewall, select custom mode, disable file analysis (you should decide, not program) and any predefined entries and settings and enjoy.

I would like to hear more about this "Comodo Firewall". It could help a lot since using this computer felt like it came back from its grave (I went to the trouble of reformatting it) and I don't think its just a simple virus and I think someone or something is really trying to take over my computer. 

You see even thought its reformatted, it didn't repair the audio issue I was having along with the ransomware. Could it be that the "one" trying to take over my computer is just making me feel like I'm in control again, I dunno? so yeah. Tell me about it, hit me a dm :)

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11549762
Share on other sites

Link to post
Share on other sites

Firewall is a firewall - you can read about it on many forums, including Comodo forum.

 

Basically it controlls all network traffic and, in case any program wants to use internet (sends or receive anything) you have notification - you may allow, block, block and terminate process, you can also know what process wants to connect, so it's easy to find dangerous program location. Depends on settings, firewall may be more annoying (asking for every connection, until you answer that you want to remember your answer) or using predefined filters and asks only when program or process is unrecognized. You may install Firewall only or firewall with basic cloud av protection. Also extra options like HIPS for monitoring filesystem.

 

It has also options to run any process in sandbox or even run sandboxed desktop (so every program you run in that mode will be harmless to your system).

 

It's up to you if you want to use it or not. Install, check yourself and I hope you'll be safer.

Link to comment
https://linustechtips.com/topic/948807-encrypted-files/#findComment-11550366
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×