{"id":246,"date":"2013-10-20T18:05:16","date_gmt":"2013-10-20T23:05:16","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=246"},"modified":"2013-10-20T18:08:23","modified_gmt":"2013-10-20T23:08:23","slug":"cryptolocker-undecryptable-file-ransom-how-to-recover","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/security\/cryptolocker-undecryptable-file-ransom-how-to-recover\/","title":{"rendered":"CryptoLocker: UNdecryptable file ransom\u2014How to recover"},"content":{"rendered":"<p>For some time now, malware authors and attackers buying licenses for use of their programs on the black market have been making a killing off of file recovery ransom schemes. \u00a0The most widespread of these was the &#8220;Windows File Recovery&#8221; style rogues that hit a couple of years ago, where a rogue recovery program named something of the sort would appear on an infected system in an attempt to convince the user that they had lost all of their data due to some catastrophic event (i.e., a hard disk failure) and that they would need to pay to have those files retrieved. \u00a0More recently, these were followed up by the still-rampant FBI Moneypak Trojans, which display a message at Windows startup explaining that the FBI has locked the PC due to its use for illegal activities and that the user will need to pay $300 via Moneypak to have it unlocked.<\/p>\n<p>None of these initial attempts were very difficult to thwart unless the user or technician was completely unfamiliar with them. \u00a0The Windows Recovery rogues simply <em>hid<\/em> the files, which could easily be <em>un<\/em>hidden following their removal. \u00a0The most sinister thing they ever did was moved the user&#8217;s shortcuts to a hidden temporary folder. \u00a0The FBI Moneypak is a cinch to kill once you know of its loading points (though it does often come bundled with the ZeroAccess rootkit). \u00a0Some of the later iterations of these ransom rogues took this a step further by actually encrypting the user&#8217;s data, but even these could be beaten with special decryption tools. \u00a0Eventually, they were assigned the title of Ransomware, which technically could be used to classify any of these specimens.<\/p>\n<p>In case you haven&#8217;t heard, there&#8217;s a new form of this malware, however, and it&#8217;s much, much nastier. \u00a0It&#8217;s called CryptoLocker, and it also encrypts the user&#8217;s data\u2014but it does so using a fusion of AES and RSA encryption that is literally impossible to reverse without the possession of a private key. \u00a0That private key resides on a remote server that is only accessible once the user actually pays to have the decryption performed (and it doesn&#8217;t always work, either). \u00a0By the time the user knows they&#8217;ve been infected, all of their precious data has usually already been encrypted. \u00a0Needless to say, this is disastrous, especially for businesses.<\/p>\n<p>Over the course of the past few weeks, I&#8217;ve had two different customers with this infection. \u00a0While it&#8217;s true that there is no possible way to decrypt the data, fortunately, there are still ways to recover some or even all of the data (albeit, slightly older versions of the files) if you know just one simple trick.<\/p>\n<p>Windows Vista and beyond include a little-known feature called <strong>Volume Shadow Copy<\/strong>. \u00a0It&#8217;s closely-related to System Restore, of which many people are familiar already, but most people are not aware of the fact that Volume Shadow Copy (unlike System Restore) actually includes management of <strong>versioned snapshots<\/strong> of the user&#8217;s data as well.<\/p>\n<p>This is a valuable tool in data recovery, of course, provided the system is bootable and the Volume Shadow Copy functionality is accessible\/unbroken. \u00a0But it also happens to work with current versions of the CryptoLocker Trojan.<\/p>\n<p>Here&#8217;s the process you&#8217;d need to follow:<\/p>\n<ul>\n<li>Remove the CryptoLocker Trojan first or all recovered data will also be encrypted.\n<ul>\n<li>This is actually pretty easy to do; you can find a plethora of information about it across the internet. \u00a0The Trojan loads from an executable in the user&#8217;s <strong>AppData\\Roaming<\/strong> folder (<strong>Documents and Settings\\Application Data<\/strong> on XP) which can simply be removed to kill it.<\/li>\n<li>However, CryptoLocker also has been bundled with Zbot very frequently, so also be sure to check for a randomly-named folder in AppData\\Roaming or AppData\\Local as well containing a single randomly-named executable and remove it as well.<\/li>\n<\/ul>\n<\/li>\n<li>Either right-click on a folder and choose <strong>Restore previous versions\u00a0<\/strong>in Windows 7 to reveal dated snapshots of the contents of that folder, or in\u00a0<em>any\u00a0<\/em>version of Windows (XP SP2 and beyond), download <a title=\"ShadowExplorer\" href=\"http:\/\/api.viglink.com\/api\/click?format=go&amp;key=59ca95b761b973f7093283b921e56892&amp;loc=http%3A%2F%2Fwww.bleepingcomputer.com%2Fforums%2Ft%2F506924%2Fcryptolocker-hijack-program%2Fpage-26%23entry3165383&amp;v=1&amp;libId=9e4514c1-77f8-4281-910a-d105ed0671ef&amp;out=http%3A%2F%2Fwww.shadowexplorer.com%2Fdownloads.html&amp;ref=http%3A%2F%2Fblog.malwarebytes.org%2Fintelligence%2F2013%2F10%2Fcryptolocker-ransomware-what-you-need-to-know%2F&amp;title=Cryptolocker%20Hijack%20program%20-%20Page%2026%20-%20General%20Security&amp;txt=Shadow%20Explorer&amp;jsonp=vglnk_jsonp_13823098289977\" target=\"_blank\">ShadowExplorer<\/a> to assist in the browsing and copying of these versioned copies.<\/li>\n<li>Copy the data from the most recent unencrypted snapshot to a safe location.<\/li>\n<\/ul>\n<p>If you need help locating all of the files which were encrypted, you can download <a title=\"ListCrilock\" href=\"http:\/\/api.viglink.com\/api\/click?format=go&amp;key=59ca95b761b973f7093283b921e56892&amp;loc=http%3A%2F%2Fwww.bleepingcomputer.com%2Fforums%2Ft%2F506924%2Fcryptolocker-hijack-program%2Fpage-26%23entry3165383&amp;v=1&amp;libId=9e4514c1-77f8-4281-910a-d105ed0671ef&amp;out=http%3A%2F%2Fdownload.bleepingcomputer.com%2Fgrinler%2FListCrilock.exe&amp;ref=http%3A%2F%2Fblog.malwarebytes.org%2Fintelligence%2F2013%2F10%2Fcryptolocker-ransomware-what-you-need-to-know%2F&amp;title=Cryptolocker%20Hijack%20program%20-%20Page%2026%20-%20General%20Security&amp;txt=http%3A%2F%2Fdownload.bleepingcomputer.com%2Fgrinler%2FListCrilock.exe&amp;jsonp=vglnk_jsonp_13823098993328\" target=\"_blank\">ListCrilock<\/a> from Grinler, which is a tool that lists the contents of the\u00a0<strong>HKEY_CURRENT_USER\\Software\\CryptoLocker\\Files<\/strong> registry key (the location CryptoLocker records the files it has encrypted).<\/p>\n<p>While this is a very fortunate oversight by the authors of the malware, I wouldn&#8217;t expect it to last. \u00a0All that would need to be added is a quick routine to clear all restore points or the contents of the System Volume Information folder to prevent this recovery from taking place, and the authors know this\u2014something which is probably in the works already as this solution has begun to spread throughout the security communities. \u00a0Ultimately, what this should do is remind everyone of the importance of regular (preferably versioned) backups offsite or to a drive <em>which is disconnected in between backups<\/em> (to prevent the files from being encrypted upon the next connection).<\/p>\n<p><em>Thanks to Grinler for <a title=\"BleepingComputer.com\" href=\"http:\/\/www.bleepingcomputer.com\/forums\/t\/506924\/cryptolocker-hijack-program\/page-26#entry3165383\" target=\"_blank\">much of the information used to assemble this post<\/a>, for his excellent tool, and for running a terrific website in the process.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For some time now, malware authors and attackers buying licenses for use of their programs on the black market have been making a killing off of file recovery ransom schemes. \u00a0The most widespread of these was the &#8220;Windows File Recovery&#8221; &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/security\/cryptolocker-undecryptable-file-ransom-how-to-recover\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,135],"tags":[11,170,143,171,173,49,172,174],"class_list":["post-246","post","type-post","status-publish","format-standard","hentry","category-security","category-recovery","tag-malware","tag-ransom","tag-recovery-2","tag-shadow-copies","tag-system-restore","tag-trojan","tag-volume-shadow-copy","tag-vss"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=246"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/246\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}