Jump to content

De_Frog_disk

Members
  • Posts

    4
  • Joined

  • Last visited

Posts posted by De_Frog_disk

  1. 7 minutes ago, Marcos said:

    Unfortunately it's not clear what you mean by hashed files. The file names are same as if you booted Windows, just the path is slightly different.

    I do not think $ROJ4EGY.exe is a normal name. All the other files had similar names. also none of them could be opened. when I booted windows again and looked through the same folder, all the files had their normal names. 

    wierd_hash_filename.png

  2. Do you know what encryption method they are using? if its AES then there is Nothing you can do. other forms of encryption have some successful methods of attacking them. if its a legitimate piece of ransomware they probably did use AES. if not and the attackers were just lazy when writing the virus then they possibly could have just encoded the file with base64 or something and are trying to trick you. if this is the case the files can be easily recovered, if not then there is a problem.  could you please send a sample of some of the text from one of the encrypted files. you can do this by opening it with notepad.

×
×
  • Create New...