Encrypted files

Discussion in 'Malware Analysis Archive' started by Palanca, Oct 6, 2015.

  1. Palanca

    Palanca New Member

    Oct 5, 2015

    I am sorry if I have posted in the wrong forum...

    I have stumbled upon a problem. I have not found a source executable but have alot of encrypted files. The encrypted files has an email appended to the filename. I have found the source user because his user folder has encrypted files. But I can't find any ransom instructions!

    Files encrypted has the following file extensions txt, xls, pdf, sql, jpg, mp3, wmv, doc, ppt, gho, xlsm, zip, spf, avi, rar, sldprt, mdb, iso, xml, pdb, rtf (probably more).

    What kind of malware could this be?
    Spawn likes this.
  2. frogboy

    frogboy Level 61

    Jun 9, 2013
    Heavy Duty Mechanic.
    Western Australia
    Windows 10
    upnorth, LabZero and Spawn like this.
  3. jamescv7

    jamescv7 Level 61

    Mar 15, 2011
    Web and FileMaker Developer
    Windows 10
    @Palanca : Any malware that can be related to Cryptolocker or others cause the number one main attack landscape is by encrypted the common file extensions.
    LabZero likes this.
  4. Spawn

    Spawn Administrator
    Staff Member Content Creator

    Jan 8, 2011
    Windows 10
  5. Palanca

    Palanca New Member

    Oct 5, 2015

    I posted in that forum but it was moved here. (I think)
  6. LabZero

    LabZero Guest

    Hello, presumably it could be a ransomware.
    Maybe you don't find the .exe file because it may have been removed by the antivirus but it is only a hypothesis, not knowing the facts.
    Unfortunately there is no guarantee that you will be able to recover the files.
    The only prevention is the backup plan.
    frogboy likes this.
Similar Threads Forum Date
New ransonware encrypted my files to .aac "Learn how to recover your files.txt" Malware Removal Assistance For Windows Jul 25, 2017
Malware Alert The Locky Ransomware is Back and Still Adding OSIRIS to Encrypted Files News Archive Apr 22, 2017
Add-on It is possible to decrypt files encrypted with Trojan.Encoder.10465 Dr Web Apr 15, 2017
  • About Us

    Our community has been around since 2010, and we pride ourselves on offering unbiased, critical discussion among people of all different backgrounds about security and technology . We are working every day to make sure our community is one of the best.
  • Need Malware Removal Help?

    If you're being redirected from a site you’re trying to visit, seeing constant pop-up ads, unwanted toolbars or strange search results, your computer may be infected with malware. We offer free malware removal assistance to our members in the Malware Removal Assistance forum.
  • Quick Tip

    Without meaning to, you may click a link that installs malware on your computer. To keep your computer safe, only click links and downloads from sites that you trust. Don’t open any unknown file types, or download programs from pop-ups that appear in your browser.