Endpoint Protection

 View Only
  • 1.  Is there a Fixtool to Recover Files Encrypted by Ransomware?

    Posted Feb 02, 2015 01:06 PM

    Just creating a thread to answer a question that is frequently asked here on Connect:

     

    Q: Does Symantec provide a fixtool to recover files that have been sabotaged by a Cryptolocker threat like CBT-Locker or CryptoWall?

    A: No, it is not possible to create fixtools that decrypt files files damaged by threats like Trojan.Cryptolocker.G.  Recover the files from a known good backup.

     

    Some news articles have given the impression that one security vendor or another has made available such a tool.  These reports are not accurate.

    Symantec urges any affected companies not to pay the ransom.  Doing so only provides Research and Development money to those responsible for creating and spreading this malware.  Paying is unlikely to actually get your files decrypted- those who caused such damage are not known for business ethics. 

     

    Here are additional articles on the subject of ransomlockers, cryptolockers and how to stay safe from them.  Please take action now:

     

    Support Perspective: CTB-Locker and other forms of Crypto malware
    https://www-secure.symantec.com/connect/blogs/support-perspective-ctb-locker-and-other-forms-crypto-malware
     

    Recovering Ransomlocked Files Using Built-In Windows Tools
    https://www-secure.symantec.com/connect/articles/recovering-ransomlocked-files-using-built-windows-tools

    Ransomcrypt: A Thriving Menace (aka Cryptolocker: A Thriving Menace)
    https://www-secure.symantec.com/connect/blogs/ransomcrypt-thriving-menace  

    Cryptolocker Q&A: Menace of the Year
    https://www-secure.symantec.com/connect/blogs/cryptolocker-qa-menace-year  

    First Response to: Cryptolocker \ Ransomcrypt\ Encryptor
    https://www-secure.symantec.com/connect/articles/first-response-cryptolocker-ransomcrypt-encryptor

    The Day After: Necessary Steps after a Virus Outbreak
    https://www-secure.symantec.com/connect/articles/day-after-necessary-steps-after-virus-outbreak

    And:

    A good Connect forum thread on how to protect yourself: https://www-secure.symantec.com/connect/forums/cryptolockercryptodefense-defenses

     

    With thanks and best regards,

    Mick



  • 2.  RE: Is there a Fixtool to Recover Files Encrypted by Ransomware?

    Posted Jun 12, 2015 07:21 PM

    Actually there are ways to decrypt SOME of these ransomware variants. Cisco Talos uses the ransomware's own key file to decrypt. Without the key no decryption can occur. Backup your data, educate your empoyees, and read this article.

    http://blogs.cisco.com/security/talos/teslacrypt

     

     

     

     



  • 3.  RE: Is there a Fixtool to Recover Files Encrypted by Ransomware?

    Posted Jun 18, 2015 11:21 AM

    Many thanks, jc2it!

    Once is a very long while, some victims do get lucky.  Unfortunately as soon as someone writes a tool or releases details about how to recover the files, the malware authors react by changing their code.

     

    Prevention remains the best defense! &: )