Recommended Posts

A customer of mine, his son has a PC which got infected with this damn malware. I know there was a version 1 and 2 and that decryption keys where then made available after some time.

This version is fairly new so I dont know if those keys are out yet. This really sucks you know..

If anyone can pass along some info on this I would appreciate it.

Link to comment
https://www.neowin.net/forum/topic/1245590-cryptowall-30-decryption-possible/
Share on other sites

As far as I know,  it's ACTUALLY using good encryption. I heard you have one of 4 options with this one

 

1) Loose all your files

2) Restore from a backup (that was not connected to your machine at the time of infection)

3) MAYBE restore from volume shadow copies

4) Pay them.

actually, didnt even think either key had been made available.   I thought a site had been setup that would decrypt individual files for ver1, but that was all i thought it was possible.

 

sorry i am not more helpful.


As far as I know, they fixed it now were it's ACTUALLY using good encryption. I heard you have one of 4 options with this one

 

1) Loose all your files  Correct

2) Restore from a backup Correct

3) MAYBE restore from volume shadow copies Nope, they got smart, Shadow Copies get erased after infection.

4) Pay them. Correct, and I truly hate those bastards.

Wow. There is nothing I can do then. This is terrible

 

The worst part is your are lucky if anyone backs up. if they do it's usually connected to the computer. Which in this case also would have gotten encrypted. Nobody ever backs up let alone has off site backups . If they had a network drive mapped to that machine with full write access. Its gone too.

 

If this were to happen to me, at worst I'd loose a few files. I have a backup in my safety deposit box that gets swapped monthly, which contains important files from ALL my drives in my system and server. But sadly that's not normal :(

  • Like 3

The worst part is your are lucky if anyone backs up. if they do it's usually connected to the computer. Which in this case also would have gotten encrypted. Nobody ever backs up let alone has off site backups or ones that are connected to the computer. Or shared network drives on other PC's in the house with full write access. They are gone too.

 

If this were to happen to me, at worst I'd loose a few files. I have a backup in my safety deposit box that gets swapped monthly, which contains important files from ALL my drives in my system and server. But sadly that's not normal :(

Yes you are not the norm and I wish more were like you. They had an external disc connected to the machine with just files and all those got encrypted also.

Ohhh boy! :s

The hard lesson of not having a backup!  What I would do is wipe their machine for them, and show them how to perform a backup.  Either get them an external backup disk, get them with one of the online backup services.  Both prob better idea!!

 

Keep in mind only critical files really need backup.. Stuff you can not recreate or get again, etc.  This would include pictures and home videos mostly..  Pretty much everything can be gotten again..

 

Depending on amount of these types of files your backup might be a couple of thumbdrives..

 

If you want to do the community and your customers a real service in IT.. Backup Backup Backup!!  Every customer you deal you should be asking them how they backup up their critical files - sorry but that video of Kevin's fist steps are not something you can get again.  Those pictures of trip to Cabo, same thing..

  • Like 3

Actually BudMan I do ask the majority and I stress to them backups and a UPS system in case the power goes out. Here in Florida that can happen often.

I leave it up to them though as I cannot force anyone to do something and there have been times when I had to say I told you so. They had to learn the hard away unfortunately.

The hard lesson of not having a backup! 

Well technically, its a hard lesson of not having an offsite, or one you don't keep connected to the computer backup. Which Even if a person has, because it's not being done automatically they tend to forget about it and not keep that backup current. In my case I turn it into a routine where the disconnected 2TB drive in my office and the one in my safety deposit box gets swapped on the last Friday of every month.

 

I will agree with you a cloud service would be a good choice, especially one which offers versioning such as carbonite.

Actually BudMan I do ask the majority and I stress to them backups and a UPS system in case the power goes out. Here in Florida that can happen often.

I leave it up to them though as I cannot force anyone to do something and there have been times when I had to say I told you so. They had to learn the hard away unfortunately.

 

I had one person ask me if I could transfer some stuff off of a desktop PC that wasn't working. I said what do you want me to put them on? I think it was a bunch of photos, music and stuff .. it was a bunch. So I said, well why don't you go buy an external hard drive I can put them on that and you can hook that up to your new computer. Then you can use that as a backup drive seeing how you dont' have one. Because at the moment the only copy of her stuff was on that PC, I told her, had that drive died you would have lost it all.

 

So then I backed up her files onto one of my spare drives, and was able to resurrect her PC. Then she said "oh well maybe i'll buy that external some day" ..I cant remember what she said exactly, but she was really trying to get out buying the drive....I was like ... oh whatever, I give up.

 

You can lead a horse to water but you can't make it drink.

You can try one thing... reverting to previous version of files...

 

It'll hopefully let you go to a version of the file that was there before the CryptoWall files... I did this at work and it worked amazing..

 

Go to a file that you know was affected, Right click, Properties, Previous Version tab.. hopefully there's something there.

Cryptowall versions past 1.0 you're pretty screwed without backups.

The news of CW 3.0 is why I started backing up everything into the cloud

SOMETIMES it apparently fails to delete the Shadow Copies, but often not.

NFVF5rW.png

Hello,

One thing you might want to do is check with your anti-malware vendor:  They may have some suggestions, tips or tricks to help recover files that they're not broadcasting in order to make it harder for the criminal gang behind this malware to fix any flaws in it.

 

Regards,

 

Aryeh Goretsky

  • 2 months later...

Hello, new to this forum.  I have now had 4 clients hit with this virus.  One was saved with Carbonite -104 GB of server data -it took a week but we restored to a previous version.  One we reformatted and two I am working on but it is looking more like reformat is the only option.  

 

I have found that Bitdefender has an immunization utility that runs on Windows startup and prevents the Ransom viruses (all of them) from encrypting anything.  After you run/install it -make sure you turn on all the features and the IMMUNIZATION.   Bitdefender is a leader in this field so I have to trust that this utility really works.

 

http://labs.bitdefender.com/projects/cryptowall-vaccine-2/bitdefender-offers-cryptowall-vaccine/

 

Good Luck.

 

John

  • 6 months later...
This topic is now closed to further replies.
  • Posts

    • One of the strangest galaxies in our Universe could help answer some long overdue questions by Sayan Sen Image by Pixabay via Pexels | Not representative An international team of astronomers led by the Department of Astronomy at Tsinghua University has discovered an unusually metal-poor galaxy that may contain signs of first-generation star formation. The galaxy, named Metal-Pristine Galaxy COSMOS Redshift 3 (MPG-CR3), or CR3, was identified using observations from the James Webb Space Telescope (JWST), the Very Large Telescope (VLT), and the Subaru Telescope. The findings, published in The Astrophysical Journal Letters, describe CR3 as the most metal-poor galaxy known from the period known as "cosmic noon," around 11.5 billion years ago. Cosmic noon refers to a period when the universe was producing stars at its highest rate and galaxies were growing rapidly. In astronomy, "metals" refers to all elements heavier than helium, including oxygen, carbon, and iron. Because CR3 contains so few of these heavier elements, researchers say it closely resembles what scientists expect the earliest galaxies in the universe may have looked like. The discovery is significant because it could offer clues about Population III (Pop III) stars, the first generation of stars thought to have formed after the Big Bang. These stars are believed to have formed from gas made almost entirely of hydrogen and helium, before heavier elements were created inside stars and spread across the universe through supernova explosions. Hence this is why CR3 has been referred to as a "living fossil." Scientists have long believed that Population III stars existed only in the very early universe. As more generations of stars formed and died, they enriched surrounding gas with heavier elements, making the conditions needed for metal-free star formation increasingly rare. Because of this, researchers expected the formation of such stars to have largely ended after the epoch of reionization, a period when radiation from the first stars and galaxies transformed the neutral hydrogen filling the universe and made it largely transparent to ultraviolet light. CR3 appears to challenge that idea. The galaxy was observed at a redshift of z = 3.193 ± 0.016. Redshift measures how much light from a distant object has been stretched as the universe expands and helps astronomers determine how far back in time they are looking. In this case, the redshift corresponds to roughly 11.5 billion years ago during cosmic noon. Although the universe was already several billion years old by that point, CR3 shows characteristics more commonly associated with much earlier galaxies. Observations revealed exceptionally strong emissions from hydrogen and helium, including Lyα, Hα, and He I λ10830. Lyα, or Lyman-alpha emission, is a specific wavelength of light produced by hydrogen and is widely used to study distant galaxies. Hα emission is another hydrogen signature commonly used to trace active star formation, while He I λ10830 is produced by helium and can indicate the presence of very hot, young stars. The measured equivalent widths of EW₀(Lyα) = 822 ± 101 Å and EW₀(Hα) = 2814 ± 327 Å are among the highest ever observed in star-forming galaxies. Equivalent width is a measure of the strength of an emission line relative to the surrounding light, and such large values are typically associated with intense and very recent star formation. At the same time, researchers found no statistically significant detections of metal emission lines, including [O III] λλ4959, 5007 and C IV λλ1548, 1550. Emission lines act as chemical fingerprints that reveal which elements are present in a galaxy. Oxygen and carbon lines are commonly seen in galaxies that have already undergone significant chemical enrichment. Their absence in CR3 suggests an unusually pristine environment. Using abundance calibration methods developed with JWST observations, the team placed a 2σ upper limit on the galaxy's gas-phase metallicity of 12+log(O/H)<6.52, corresponding to less than 0.7% of the Sun's metallicity (Z < 7 × 10⁻³ Z⊙). Gas-phase metallicity measures the abundance of heavy elements in a galaxy's gas. A 2σ upper limit indicates that the true value is very unlikely to be higher than the quoted threshold. Even when accounting for uncertainties in the calibration methods, the most conservative limit remains 12+log(O/H)<6.95, making CR3 the most metal-poor galaxy identified at cosmic noon. The galaxy also appears to contain very little dust. Researchers measured a Lyα/Hα flux ratio of 13.9 ± 2.5, a result that suggests negligible dust attenuation, meaning very little of the galaxy's light is being absorbed or scattered by cosmic dust. Because dust is usually produced by earlier generations of stars, this finding further supports the idea that CR3 has experienced very little chemical enrichment. Further analysis using spectral energy distribution modelling, a technique that compares observed light with theoretical models, suggests that CR3 contains an extremely young stellar population only around 2 million years old. The modelling, which used Population III stellar templates, also indicates the galaxy has a stellar mass of approximately 6.1 × 10⁵ M⊙. The symbol M⊙ represents one solar mass, or the mass of the Sun. One of the key questions raised by the discovery is how such a chemically primitive galaxy could exist in a universe that had already spent billions of years producing heavier elements. To investigate this, the researchers examined CR3's surroundings. Their analysis suggests the galaxy may lie in a slightly underdense environment, with a density contrast of roughly δ ≈ −0.12. An underdense region contains less matter and fewer galaxies than average. The team suggests that this relative isolation may have helped preserve pockets of pristine gas. Metal-rich material expelled from nearby galaxies may never have reached CR3, while the lower rate of galaxy mergers and interactions could have slowed the mixing of enriched gas into the system. If future observations confirm these findings, CR3 could provide some of the strongest evidence yet that first-generation star formation continued well after the epoch of reionization. Such a result would challenge the conventional view that pristine star formation ended by z ≳ 6 and suggest that small pockets of metal-free gas survived much longer than previously thought. Researchers stress that more observations will be needed to determine the galaxy's true nature. Future spectroscopic studies with higher resolution and better signal quality could help confirm whether CR3 is genuinely hosting Population III star formation. The discovery is also expected to encourage searches for other similar galaxies, which could help astronomers better understand how the first stars formed and how galaxies evolved in the early universe. Source: Tsinghua University, IOPscience This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
    • "I think in the immediate absence of a partner to apply relief" In the words of Sterling Archer... "Phrasing!"
    • For me, the fundamental problems with these "smartglasses" is that they really don't work well for people with significant prescriptions and massively up the price if you use attached lenses if they have displays, and if they don't, then they're not actually "smart" anything, rather just connecting to your phone and relaying voice to an AI. In a few cases like this, they throw in small cameras to feed video to the AI. All around, these feel like both a solution looking for a problem, and the problems it tries to solve seem more easily solved by different approaches and designs. Oddly, if the rumours are true, Apple may actually have invented something for once and it kind of does this right: put cameras in ear buds and manage the interface to AI exactly as most of us do: tapping on an ear bud and saying "Hey Google" or "Hey Siri." That makes them compatible with almost everyone, can double up as a hearing assist device, an impaired vision assist device, a "smart" device... and answer your phone and play music. That just seems like a better solution all around.
    • Usually the bigger ones with many fixes/changes take a few, theyre an exception to the rule most likely
    • If you don’t get lucky with Valve’s Steam Machine reservation system, you can make your own Steam Machine instead. Valve says that “starting with the SteamOS 3.8 release, you can put together your own Steam Machine using whatever PC parts you want.” SteamOS 3.8.10 launched last week with a slew of updates, including “improved compatibility with recent Intel and AMD platforms.” Alongside that improved compatibility, Valve is giving gamers the green light to install SteamOS on their own desktops. In an interview with The Verge, Valve’s Pierre-Loup Griffais said Valve has been “rolling out improvements to [SteamOS] so it’s more compatible with desktop hardware,” including eventual support for Nvidia graphics. Griffais says Valve has “a growing team” working on Nvidia driver support for SteamOS, adding, “We’re collaborating with Nvidia very closely.” While he mentioned that Nvidia support might not come this year, Griffais emphasized that “it’s certainly something that we’re working on in the background.”     Subscription not needed: https://archive.fo/Tssfc Subscription needed: https://www.theverge.com/games/953411/valve-steamos-desktop-nvidia
  • Recent Achievements

    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      452
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      107
    4. 4
      Michael Scrip
      84
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!