Mitigation tool 'CryptoSearch' finds files encrypted by Ransomware, moves them to new location

Parsh

Level 25
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
The mentioned Windows app that has been developed by security researcher Michael Gillespie is not any kind of a decryptor tool. Rather, it provides solace by lending more time to the victim to decrypt his files, by automatically moving/copying them to a safe location.
This can be particularly useful in case of timer-based Ransomware infections and other dangerous Randomware families.

The tool identifies files encrypted by several types of ransomware families and provides the user with the option to copy or move the files to a new location, in hopes that a decrypter that can recover the locked files will be released in the future.

Gillespie developed the app as a recovery and cleaning utility for computers that have been infected by undecryptable ransomware strains.

In these cases, it is impossible for PC owners to recover locked files, so the best course of action is to move all the encrypted data to a backup drive and wait until security researchers find a way to break the ransomware's encryption.

6D3ftd5.jpg


Find the link to the entire article here.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top