Ransomware PLEASE HELP

The first version I got also worked slowly. I wrote about this to virus maker and received a second version which is deciphered less than an hour. Write to them and get an update.

I have contacted MoneyPak and altered them to the situation about this guy.  Maybe they'll shut them down.


herman1134 wrote:

Could everyone please, for the sake of sympathy STOP MENTIONING MAKING OR HAVING A BACKUP!!!  It doesn't help anyone, it takes up valuable space on the forum, and it doesnt add to the conversation.  EVERYONE who has this problem was caught unawares and a backup would not have saved everything.  NO ONE is going to back up their systems every day.  This virus also attacks the program files and Windows files and you cant backup those without a reformat.  Furthermore on extrnal drives, some people need them on, connected and running at all times because they need alot of files on them and the boot drive is too small.


I disagree.  While recommendations to backup your data will not help those whose files have already been taken hostage, it will help others to avoid becoming victims of this same sort of disaster in the future.  It is not true that NO ONE backs up their systems every day - in fact, anyone with an ounce of sense who creates important files daily will be backing them up once a day at a MINIMUM.  It all depends on how crucial the information is and what the consequences of losing the data would be.  Daily backup may not be appropriate for everyone, but the frequency of doing backups needs to be proportional to the amount and importance of the data being stored.

 

While backups stored away from the system might not have preserved everything, they would certainly have saved most of it.  Windows files and program files are unimportant because they can always be replaced.  Important photos and documents, once lost, are lost forever.  And, again, ransomware is only one of many things that can wipe out everything you've got stored on your PC.

My point is more than half of this forum post has nothing to do with the virus, and it's just people posting about how I should have backed up my stuff.  IT DOESN'T HELP!!

Hi herman1134,

 

I completely understand what you are saying.  But ransomware is only viable when the files it encrypts are unique and irreplaceable.  If you take that away, ransomware is powerless.  I realize, and am truly sorry, that this isn't particularly helpful to you at this point, but it certainly may help others reading this thread to know that there are ways to minimize the danger of the same thing happening to them. 


herman1134 wrote:

Could everyone please, for the sake of sympathy STOP MENTIONING MAKING OR HAVING A BACKUP!!!  It doesn't help anyone, it takes up valuable space on the forum, and it doesnt add to the conversation. 


Opinion... which is welcome on forums. Obviously it can't be stated enough... even if it is coming across as an "I told you so..." that is human nature. I see this every day, and it is sad... so for myself, this can not be said enough.

 


herman1134 wrote:

EVERYONE who has this problem was caught unawares and a backup would not have saved everything. 


Incorrect... proper backup would have saved everything.

 


herman1134 wrote:
NO ONE is going to back up their systems every day. 

Some do... the companies and individuals I work for do.  Some every 30 minutes depending on how much they value the data and how much it changes.  From photographers and corporate giants down to grandma's hanging on to scans of deteriorated or burned photographs, backup can not be stressed enough.

It is just a choice.

 


herman1134 wrote:
This virus also attacks the program files and Windows files and you cant backup those without a reformat. 

If it can be written to, it can be backed up.

 


herman1134 wrote:
Furthermore on extrnal drives, some people need them on, connected and running at all times because they need alot of files on them and the boot drive is too small.

An accessible real-time external drive is not backup by definition.

As far as the boot drives being too small, that is an easy fix these days... storage is cheap compared to hours spent doing something like restoring your files... and again, connected storage is NOT backup.

 

Not trying to be a jerk here, but as I research this issue, as a professional, the only thing I find annoying, detracting or distracting are people trying to tell everyone else how to act. I was able to ignore all the repeated reinforcements of the importance of backing up... it was this post which ended my patience.

 

I am glad this thread is not just focused on correcting the issue as it is a perfect place to show the importance of backing up your files.

To those who have lost their irreplacable data, I sincerely symapthize.

 

I am glad to see so much "free" help with such a horrible type of exploitation.

 

Thank you to all of those who contributed to this thread.  I am only learning about this particular issue, so I do not plan furthing posting here.

 

MrBlackCat

I dont want this forum to be a debate about the merits of backing things up, can we please get back to the point?

 

To Quads, would you like me to send you the program the virus maker sent me?

Should I delete the HKCU\.... WindowsNT\Winlogon registry key once my files have been decrypted?

 

 

You guys are crazy, ask me a question and there are many messages after.

 

herman1134 Quote

 

I still need it.  I downloaded the program you made, and put it and some encrypted files on a different computer to see if it worked.  It didn't.  Maybe I did something wrong?

 

The program works by, when it starts it looks for the registry key I told the users NOT to delete, the program then takes the ID and password in that registry key and then searches the Hard Drive(s) and decrypts the personal files with it.  It can take a lot of time if there are may files.

Why do you think I said not to delete the registry keys??

 

Using the program on a PC to decrypt the files without importing the exact registry key for those files does not work as there is no ID or password to find first. Why do you think I inported the registry key from your PC into my system before running the tool??

 

If you use a different PC like I did to test on Herman's 5 files you have to grab the registry key and import it to the registry of the PC you are going to run the tool on.

So I place Herman's 5 crypted files in a folder on my desktop  I then imported the key Herman also sent me into my registry so my system had his Password and ID added to my Winlogon key.

I then ran the decrypt tool.

The decrypt tool keeps the original .crypt files so after the scan of the Hard Drive the folder with the 5 files went to 10, the 5 originals and the 5 decrypted version.

 

Guys paid the creator for his tool, that just adds, to the evilness as they get money.

What was the point of a small group (2) working out what the Ransomware is and working out the decrypt, then create a program???

That means I have had enough of this thread,   I do not do the work, just to have people give to the evil people I will not be working on Ransiomware again just to have people do that.

 

Quads

Please don't leave... I contacted the guy before I contacted you.  He hasn't answered me yet.  Someone else (unrelated to our conversations) contacted him and got a program, I asked him to give you the program.

So 2 users here have the tool from the ransom creator the guy will be happy more money for him, if he is successful, the person will just go away and create another maybe better Ransomware to release that is harder tio reverse.

 

Actually part of me in the back of my mind hopes he does to prove my point.

 

Give to Dark Knights and evil guys and expect them to create something better, while us White Knights get sick of people giving to them.( feeding them.

 

Quads

I will not have the program I do not feed or give evil any happiness or pleasure by using anything of theirs

 

You guys are feeding him,  Giving him enjoyment

 

I would ony deal with him to give him to law enforcement.

 

Quads

Quads

I have exported my registry key for HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon and have an 'id' but not a 'bdgid'.  The executable availble on bleeping computer did not work for me.  Is there anything else I can do?

-lh

I did!!! I contacted MoneyPak and Yahoo.com to inform them that this guy was doing something wrong.  They told me they are starting an investigation.  Meanwhile my files are still screwed.  I am using your program now, but I don't have that much free space on my HDD, so the duplicating of files is messing it up a it.

 

I think it is very important that this virus should be dealt with regardless if anyone paid him or not.  There are moments in situations like this when people feel there is no choice.  And I remember maybe times when forums like this (not Norton, but others) has totally failed to help.  You in fact have been the first one to help me in a situation like this at all.  I hope you don't just leave.


herman1134 wrote:

I dont want this forum to be a debate about the merits of backing things up, can we please get back to the point?

 

To Quads, would you like me to send you the program the virus maker sent me?

Should I delete the HKCU\.... WindowsNT\Winlogon registry key once my files have been decrypted?

 

 



I have the decrypt tool I played with that myself and the other guy tested I don't need any other tool,   I had it as soon as it was created and was not publicly available.

 

I won't be dealing with the Ransomwaere on thisd thread again,  The hours myself and the otheer guy put into it, just to have the likes of that back

 

Your files successfully decrypt using your ID and password.

 

Quads

 

Quads 


lh wrote:

Quads

I have exported my registry key for HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon and have an 'id' but not a 'bdgid'.  The executable availble on bleeping computer did not work for me.  Is there anything else I can do?

-lh


Take the exported .reg file and add or change the extenstion to reg.txt.

 

Then you can atttach it to a message.

 

Quads

Exported winlogon.txt attached

If you select (highlight) computer at the top of the registry tree on the left hand pane and then have regedit do a search.

 

Have it search for   bdgid

 

Does anything get found.

 

Quads

Quads

I attempted a search for bdgid in the regedit tree and the only place it was found was HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Quick Search\http://userscripts.org/posts/445215.

Yes, I did a google search on it. 

-lh

I have sent the key change on, to see what about when there is no password in that key. Could it have been that it encrypted withoud a password needed, The password is somewhere else (new variant)  or the Ransomware got stopped somehow partway though its process causing the problem.

 

The trouble is that the encryption is AES 256  so brute force to break could or would take Donkies years, longer than the human race has existed.

 

Quads

Quads

I understand.  Let me know if you hear anything or if there is anything else I need to send you.  Thanks for your help.

-lh