FBI virus with encryption of MS docs

Discussion in 'Application Software' started by computercenterhanover, Oct 1, 2013.

  1. computercenterhanover

    May 3, 2012
    10
    2
    0
    Hi Group: working on a buisness customer that has all his word & excel files encrypted by the FBI virus. I have removed the virus ok but still can not de-crypt his data. Any sugestions? thanks
     
  2. Paiva

    Paiva MDL Developer

    Apr 9, 2011
    1,275
    1,591
    60
    #2 Paiva, Oct 1, 2013
    Last edited by a moderator: Apr 20, 2017
  3. Myrrh

    Myrrh MDL Expert

    Nov 26, 2008
    1,511
    627
    60
    I had one of these a few days ago. As far as I have been able to determine, it's a strong encryption with the key stored on the server owned by the author of the virus.

    Hope they have a good backup.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. sid_16

    sid_16 MDL Giveaway Organiser

    Oct 15, 2011
    2,494
    5,362
    90
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. EFA11

    EFA11 Avatar Guru

    Oct 7, 2010
    8,719
    6,741
    270
    #5 EFA11, Oct 2, 2013
    Last edited by a moderator: Apr 20, 2017
  6. Myrrh

    Myrrh MDL Expert

    Nov 26, 2008
    1,511
    627
    60
    Before wiping my Customer's drive and reinstalling from the recovery media, I grabbed a copy of the partition just in case in the future a method of decryption is found.

    So I will check out this new information and see if I might actually be able to retrieve anything.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. EFA11

    EFA11 Avatar Guru

    Oct 7, 2010
    8,719
    6,741
    270
    I am interested to hear the results. Good luck.
     
  8. computercenterhanover

    May 3, 2012
    10
    2
    0
    I have tried useing the decrypt_mblock.exe in the link above with no sucess. I did download spyhunter and that sucessfully removed the virus but not the encryption of the files. I sent them an email and they sent the same info in the above post. No sucess I have informed customer they are out of luck. I also saved the encrypted files if a future solutio comes out..