Bitcoin Ransomware


Recommended Posts

Luckily, it seems the encryption keys have been found and there is a tool to decrypt .wallet files and retrieve your data.

 

https://www.bleepingcomputer.com/news/security/wallet-ransomware-master-keys-released-on-bleepingcomputer-avast-releases-free-decryptor/

 

That link will give you the fine details/instructions, here are mine in short form

 

Download this tool: http://files.avast.com/files/decryptor/avast_decryptor_crysis.exe

 

Run it, this will take a while, and hopefully your files are back. There is one point when running the program where there are two check mark boxes, leave both checked when you run the scan.

 

 

Kaspersky also has a tool to decrypt wallet files, http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip I would probably give Kaspersky a shot first, as it is newer, however both should do the job just fine.

Just now, Circaflex said:

Luckily, it seems the encryption keys have been found and there is a tool to decrypt .wallet files and retrieve your data.

 

https://www.bleepingcomputer.com/news/security/wallet-ransomware-master-keys-released-on-bleepingcomputer-avast-releases-free-decryptor/

 

That link will give you the fine details/instructions, here are mine in short form

 

Download this tool: http://files.avast.com/files/decryptor/avast_decryptor_crysis.exe

 

Run it, this will take a while, and hopefully your files are back. There is one point when running the program where there are two check mark boxes, leave both checked when you run the scan.

Is it recommended to wipe / reimage the system after or do tools like malware bytes and the decryption software do a good enough job? 

Just now, Edrick Smith said:

Is it recommended to wipe / reimage the system after or do tools like malware bytes and the decryption software do a good enough job? 

If it were my machine, or a friends, I would wipe and start over, however if you like a good project and are tech savvy enough to replace system files, you can probably fix it enough with Malwarebytes and some manual repair. Totally up to you, everyone values their time differently.

3 minutes ago, Edrick Smith said:

The avast tool is coming back with Invalid Password or decryption key. 

 

it says [[email protected]]-id-BAC_wallet 

Give the Kaspersky tool a try, I believe it was a little newer.

 

http://media.kaspersky.com/utilities/VirusUtilities/EN/rakhnidecryptor.zip

According to that link via the email method as I've stepped away from the computer right now it says based on that email address. However the extensions it list for the BTCWARE don't match my .wallet

 

BTCWare PayDay

 This ransomware has no known way of decrypting data at this time.

It is recommended to backup your encrypted files, and hope for a solution in the future.

Identified by

ransomnote_email: [email protected]

Click here for more information about BTCWare PayDay

Just now, Edrick Smith said:

According to that link via the email method as I've stepped away from the computer right now it says based on that email address 

 

BTCWare PayDay

 This ransomware has no known way of decrypting data at this time.

It is recommended to backup your encrypted files, and hope for a solution in the future.

Identified by

ransomnote_email: [email protected]

Click here for more information about BTCWare PayDay

Did you upload a sample encrypted file?  

ok, you may have the same thing as this poor gent (new BTCWare variant with .wallet extension) ...

 

https://www.bleepingcomputer.com/forums/t/668054/new-btcwware-variant-with-wallet-extension/

 

Which, if it is a newer variant ... according to Bleeping Computer:

"Unfortunately, newer variants of BTCWare are AES-256 versions of the malware which uses a different RSA-1024 key and are not decryptable unless you pay the ransom and get the private AES key from the criminals. There is no way to bruteforce the key for any of these versions."

 

If the encrypted file sample comes back with the same ransomware variant ... yea ... you may want to take a look at Bleeping Computer.  Obviously, don't pay the ransom but you may have to blow up the hard drive.

 

Edit:  I really wish Microsoft would release some sort of preventative measures for this crud.  Not sure how they can ... but dang if this wouldn't tick me off to no end.  Some are getting installed via brute force of RDP.  /rant off

3 hours ago, Jim K said:

I really wish Microsoft would release some sort of preventative measures for this crud.  Not sure how they can ... but dang if this wouldn't tick me off to no end.  Some are getting installed via brute force of RDP.  /rant off

 

Who puts RDP Internet facing? VPN + RDP is the only way I roll.

50 minutes ago, Edrick Smith said:

I've uploaded a file and the txt instruction file and it confirmed it is as listed above and no method of unlocking. 

I don't want to say you're SOL ... but I think you're kinda SOL.  If there isn't a decrypter ... then the only thing you can do is hold out and hope one becomes available or blast the drive (when in doubt ... C4 ...though it might be overkill).  

 

Someone might have a better opinion ... or you could pose the question at Bleeping and see what they say.  But no decrypter=no files.

Hello,

 

Contact the anti-malware company whose software is on the client's box, and explain the situation to them.  They should tell you what artefacts (forensic info like logs, samples of encrypted files,  copy of ransomware note, wallpaper, etc.) that they need in order to tell you whether or not the system can currently be decrypted.  Even if the answer is "no" right now, it may be possible some event in the future allows for decryption in the future.  I'd also suggest removing the drive and putting a new one in, as that leaves the old drive with its encrypted files intact if needed in the for insurance and legal purposes.

 

Regards,

 

Aryeh Goretsky

  • Like 2
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • WildBit Viewer 6.20 released; no further updates planned by Razvan Serea WildBit Viewer is a popular, fast, and extensive image viewer offering a comprehensive suite of tools for photographers, designers, and image enthusiasts. It includes a powerful Viewer, Slide Show, Editor, Search, Profile Switcher, and Multi-Screen Viewer. The Viewer provides blazing-fast folder, file list, and thumbnail navigation with customizable headers, full-screen view, and a shell toolbar to organize favorite folders. It supports all major graphic formats (over 70), including JPEG, TIFF, PNG, BMP, GIF, PCX, TGA, and RAW formats. Detailed Image Info shows EXIF, IPTC, and XMP metadata, with rotation based on EXIF orientation, wallpaper setting, image comparison, geo-tag viewing, color labels, and CMS-aware color management. The Slide Show module offers 176 transition effects, multi-monitor support, custom shows with per-image settings, image marking, zoom, rotate, and desktop hiding for a professional viewing experience. The Editor supports advanced image manipulation, including crop, resize, color adjustments, curves, edge detection, effects, batch processing, retouching, layer support, and printing. Users can apply mass renaming, update or clear metadata, and work with multi-page TIFFs and animated GIFs. Search allows filtering by name, location, date, size, attributes, and metadata, while the Profile Switcher saves and loads custom layouts for all modules. The Multi-Screen Viewer opens multiple windows on available monitors, allowing simultaneous image viewing with independent zoom, pan, and rotation. WildBit Viewer also supports portable operation, 32- and 64-bit versions, Unicode, high-DPI displays, and multiple Windows styling options. With its combination of speed, versatility, and rich feature set, WildBit Viewer is an indispensable tool for managing, editing, and showcasing images efficiently. WildBit Viewer key features: Blazing-fast folder, file list, and thumbnail browsing Supports 70+ image formats including JPEG, TIFF, PNG, BMP, GIF, and RAW Full-screen view with multi-monitor support Explorer-style file handling with customizable headers Thumbnail Browser with sorting, view change, and fast size adjustment EXIF, IPTC, and XMP metadata viewing and editing Automatic rotation based on EXIF orientation Shell toolbar for organizing favorite folders Image Compare to calculate similarity between images Mass renaming and batch metadata updates File List Generator (HTML, CSV, RTF, TXT, Unicode) Rating and color labels, CMS-aware color management Video playback (AVI, MPG, MPEG, WMV) Animated GIF, multipage TIFF, Camera RAW support Slide Show with 176 transition effects and custom settings Editor: crop, resize, rotate, flip, canvas resize, and retouching tools Batch processing and image format conversion Multi-Screen Viewer: multiple windows with independent zoom, pan, and rotate Profile Switcher: save, load, reset, delete module profiles Portable operation, 32-/64-bit support, Unicode, and high-DPI ready WildBit Viewer 6.20 changelog: Viewer, Slide Show, Editor, Search, Profile Switcher & Multi Screen Viewer. Updated ImageEn to 15.0.0 version. Viewer, Slide Show, Editor, Search, Profile Switcher & Multi Screen Viewer. Updated Jedi JCL&JVCL. Viewer - Image Geo Info, OpenStreetMap removed. Slide Show Remote Mode removed. Note! This means that WildBit Slide Show Remote is now officially EOL. Editor - Shortcut keys for Capture removed. Optimized code. Note! This version includes help what supersedes all previous releases. plus Lots of bug fixes and changes, check Readme files for details. WildBit Viewer End‑of‑Life WildBit Viewer has reached its final release with version 6.20. As development comes to a close, no further feature updates are planned. WildBit Slide Show Remote reached End-of-Life on 06 June 2026, while WildBit Viewer will reach End-of-Life on 30 June 2026. Downloads will remain available until the end of July 2026 (possibly extending into early August). After End-of-Life, the software will no longer receive updates, security fixes, or technical support. Download: WildBit Viewer 64-bit | Portable 64-bit | ~70.0 MB (Freeware) Download: WildBit Viewer 32-bit | Portable 32-bit Links: WildBit Viewer Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Thanks for liking it! 😊 That's Arch Linux with Gnome.
    • LOL. Can't even quote and edit a comment correctly. Figures you're a Linux user.
    • It won't perform hugely better than the 3080 unless you're VRAM limited in games. Have you tried putting new thermal pads on them 3080 and giving it a good clean to see if you can regain your temps and overclock?
  • Recent Achievements

    • Week One Done
      Windows Guy earned a badge
      Week One Done
    • Dedicated
      Mark Spruce earned a badge
      Dedicated
    • Collaborator
      conkir earned a badge
      Collaborator
    • Rising Star
      olavinto went up a rank
      Rising Star
    • One Month Later
      lamborghiniv10 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      479
    2. 2
      PsYcHoKiLLa
      252
    3. 3
      Steven P.
      71
    4. 4
      FloatingFatMan
      69
    5. 5
      +Edouard
      69
  • Tell a friend

    Love Neowin? Tell a friend!