This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

identifying the ransomware file encryption

2 min read

This thread's last reply is from November 30, 2016, 6:42 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi I have a problem to recognize ransomware that encrypted my files.
I have already used ID Ransomware (but it didn't answer my question) : https://id-ransomware.malwarehunterteam.com/
I have scaned all files by Malwarebytes and as a result it have found:

- Cerber
- Cerber.NSIS
- Locky

But the behavior of ransomware that encrypted my files is not similar to Cerber and Locky so I still don't know what to use to decrypt my files.
So, can you help me to identify which ransomware encrypted my files?

Behavior that I have noticed:
- no file names, and extensions have been changed
- on each disk and on desktop i have found text files: Your "files are locked !.txt", "files are locked !!.txt", "files are locked !!!.txt", "files are locked !!!!.txt", "files are locked !!!!!.txt"
- content of "files are locked !.txt":

Support e-mail: [removed] [removed]

Your personal files encryption produced on this computer: photos, videos, documents, etc.
Encryption was produced using a unique public key RSA-2048 generated for this computer.

To decrypt files you need to obtain the private key.

The single copy of the private key, which will allow to decrypt the files,
located on a secret server on the Internet; the server will destroy the key after 120 hours.

After that nobody and never will be able to restore files.

To obtain the private key for this computer, you need pay 0.2 Bitcoin (~145 USD)


I have no idea how should I identify what ransomware has encrypted my files, because this behaviour, as I read, is not common for Cerber and Locky.
Please help me
If you have uploaded a sample of one of your encrypted files to ... https://id-ransomware.malwarehunterteam.com/ ... and it has failed to identify the variant that has infected your files, it is unlikely we will be able to help you identify it.

The real specialists in this type of work can be found at ... http://www.bleepingcomputer.com/forums/f/239/ransomware-help-tech-support/ ... and I suggest you post details of your problem there.

However, if you do not have backups of your files, it is very probable that there will not be a decryptor available, and recovery them may not be an option.