CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › IT › IT Support › Ransomware locked my files

Ransomware locked my files

Started by Aaron Chavez8 · · 👁 5 views · 18 replies

📡 Subscribe to replies

Participants Aaron Chavez8William Richardson12Jerry Robinson56shadowlynx102Megan Thomas5placidtinker39Bryan Rivera83James Alvarez63Jack Cook7Drew Perez15
Aaron Chavez8 Aaron Chavez8 NewcomerOP
5 messages
joined Oct 2015
#1 ·
I can't open a single damn file. Look, I’m no tech wizard, but I noticed every single one of my documents has been renamed to a .ccza file. I did some digging online and realized this is some kind of ransomware virus that locks everything down. Can someone who actually knows their way around a computer please help me out? Is there any hope of getting my stuff back??? This is straight-up digital robbery. Is it even possible to track these lowlifes down and make sure they face real justice in an American court???
William Richardson12 William Richardson12 Regular
301 messages
joined Aug 2014
#2 ·
Short answer? Nah. Unless we're talking sensitive business docs or gear worth at least twenty grand... $0.00It’s a lost cause. And catching them? Good luck with that... you looking for some guy from overseas? Who are you even gonna hunt down...

☕
Jerry Robinson56 Jerry Robinson56 Regular
320 messages
joined Apr 2013
#3 ·
File a report with the FBI regarding the cybercrime. It’s a long shot, I realize, but perhaps luck might be on your side. At the very least, you could identify which server was used in the final stages of the breach. There is a negligible probability of a breakthrough, but perhaps such actions are necessary for the sake of future security.
shadowlynx102 shadowlynx102 Active Member
91 messages
joined Oct 2017
#4 ·
You’ve been hit by ransomware. Unless you're willing to cough up a few thousand dollars to get the decryption key they promise, you can basically kiss all your data goodbye. There isn't really another way out of this mess, and honestly, filing a report with the FBI isn't going to do much to get your files back.
Jerry Robinson56 Jerry Robinson56 Regular
320 messages
joined Apr 2013
#5 ·
I must offer a word of caution, though it may be unwelcome... One should never pay—under any circumstances. The developers do not actually send anything out; they merely lease access to their various assistants.
Filing a report on your behalf might feel productive, and it likely won't achieve much, but it will be "archived"...
Megan Thomas5 Megan Thomas5 Active Member
132 messages
joined Jan 2021
#6 ·
Plus, you don't even know if the person who sent you this junk is even alive anymore.

Maybe try checking the Shadow Copy if it hasn't been wiped yet.

https://www.shadowexplorer.com/downloads.html
placidtinker39 placidtinker39 Member
39 messages
joined Nov 2015
#7 ·
Take a look at what they're saying over here
https://www.pcrisk.com/removal-guide...cza-ransomware
shadowlynx102 shadowlynx102 Active Member
91 messages
joined Oct 2017
#8 ·
Jerry Robinson56 said:Sorry, but that’s pretty bad advice... never pay them off... seriously, never. The developers don't actually send you anything—they just rent out access to their helpers.
Reporting it might feel useless, and it probably is, but at least it gets "archived"...

I think you've got it all wrong. I actually know of two companies here in the States that got hit by cryptolocker, and after they paid up, they actually managed to get all their files unlocked. Look, there's definitely a risk that you're just throwing money down the drain, but what else can you do? If you weren't thinking ahead and keeping regular backups, this is really your only shot because there aren't any reliable tools out there to fight cryptolocker.
Bryan Rivera83 Bryan Rivera83 Member
35 messages
joined Jun 2013
#9 ·
Look at this—since that guy is part of the djvu family, you should probably just try messing around with this tool here

Otherwise, you need to figure out the specific strain of the virus and check the No More Ransom site to see if there’s an actual decryptor available
James Alvarez63 James Alvarez63 Newcomer
4 messages
joined Mar 2022
#10 ·
Maybe I can help you out here—there have definitely been instances where people managed to pull data through this site without spending a dime. If anything seems fuzzy or unclear, just give me a shout via DM. We can hop on LogMeIn and get everything sorted out easily 🙂 . In the meantime, take a look at this link: https://id-ransomware.malwarehuntert...php?lang=en_US
Jerry Robinson56 Jerry Robinson56 Regular
320 messages
joined Apr 2013
#11 ·
shadowlynx102 said:Your reasoning is fundamentally flawed. I am personally aware of two instances that prove otherwise. Corporations. They exist as these massive, faceless monoliths that dictate the rhythm of our lives, often without us even realizing we're being steered. It’s a curious thing, really—how much power we cede to these entities in exchange for convenience or the illusion of progress. We trade our data, our privacy, and quite frankly, our autonomy, all to satisfy the bottom line of some conglomerate headquartered in a glass tower in Midtown Manhattan. One begins to wonder if any of it actually serves the individual, or if we are merely fuel for the engine of perpetual growth. It is a weary cycle, one that seems increasingly difficult to escape. A few folks recently fell victim to a CryptoLocker attack. They actually went ahead and paid the ransom, and somehow, they managed to get all their files unlocked. I will admit, there is a massive risk that you are simply throwing money down the drain, but at that point, what choice do you really have? If you weren't thinking ahead and maintaining a proper backup, this becomes your only remaining lifeline. The reality is quite grim: effective tools to combat CryptoLocker simply do not exist.

This is what truly makes the difference. shadowlynx102 ...
I find myself wondering whether they actually followed through on their end of the bargain—specifically regarding the replacement of the hard drives in both the workstations and the servers once the payment was finalized. One can only hope the execution matched the invoice.
I have yet to encounter anyone who actually managed to recover their data... It would be quite an intriguing exercise to determine exactly who was responsible for the file encryption in the first place. My money is on their own system administrator.
The workstation you utilize for your professional duties should never, under any circumstances, be connected to the internet. I am being quite serious when I say that. Not even once. It is an absolute necessity. Besides, high-end hardware has become laughably inexpensive for a long time now.
The tools are all there, which is fine. The actual bottleneck is the sheer computational power required. Unless you have a supercomputer like Deep Blue tucked away in your basement or some massive Cleveland rig running in a tunnel beneath your house, you’re going to hit a wall. 😁

You are correct on that point; maintaining redundant backups is simply common sense. CDs have become nothing more than trivial trifles in this day and age.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#12 ·
But seriously, what happens when you've got crypto running on something like 500 workstations and maybe 80 servers? 🤣 🤣
Drew Perez15 Drew Perez15 Member
11 messages
joined Jan 2023
#13 ·
Goddamn ransomware, what a complete nightmare.

To be honest, I’m probably not much help here; I went through my own hell about two and a half years ago when my files got encrypted into the .jope format, and even now, I haven't found a way to crack them. I tried those various decryption tools you find floating around online, but nothing worked (I haven't reached out to any professional recovery firms yet—so if anyone actually has a legitimate solution, feel free to shoot me a DM)
. The absolute worst part is that if you move one of those infected files onto another drive, it just spreads like wildfire and turns everything else into ransom. It’s total bullshit, so please, don't even THINK about making that mistake. And whatever you do, don't pay them; why would you expect the same people who screwed you over to suddenly decide to be decent and give your data back?

What I’ll suggest for the future is picking up a program like Acronis Cyber Protect and using it for all your backups. It comes with an integrated Norton Ghost background service that automatically blocks ransomware attacks, ensuring that any backup point you’ve created stays completely untouched even if the rest of your computer gets encrypted. Just make sure you don't go into the settings and disable it...
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#14 ·
The file you just loaded isn't what's actually infecting your PC. (Though, hey, anything is possible!)

It’s more like the app you're already running gets hijacked. It opens up that nasty file, and because the app—or even the OS itself—has a little security gap, the malicious code sneaks right in.

So, the app pulls in the file, the code executes alongside it, and then boom: it starts spreading itself to other files or even digs deep into your MBR or BIOS.
Jerry Robinson56 Jerry Robinson56 Regular
320 messages
joined Apr 2013
#15 ·
Jack Cook7 said:And what happens when that crypto settles itself onto roughly 500 workstations and about 80 servers? 🤣 🤣

Then you head out with your group for some fishing or maybe a round of paintball. ... Though, if I may offer a little trick for protection—not just for you, but for the other members here as well—try changing the extension of any data copies you want to keep relatively secure. You can rename it to just about anything.

However, if hardware replacement becomes necessary, we can certainly reach an agreement 😁

Drew Perez15 said:Damn ransomware, what a cursed thing.

To be perfectly honest, I am not much help here; I ran into my own issues two and a half years ago when my files were encrypted into a .jope format. To this day, I have failed to find a solution. I attempted those decryption tools you find floating around the internet, but none of them worked (I haven't contacted any professional decryption firms—if anyone happens to have a concrete solution, feel free to message me privately).
The absolute worst part is that if you transfer such a file to another drive, it contaminates everything and converts it into ransomware. It is total bullshit, and you should absolutely NOT do that by accident. As for paying them, forget it; do not expect the people who screwed you over to ever return things to normal.

What I recommend for the future is to acquire Acronis Cyber Protect and perform your backups with it. It features a > background service that automatically thwarts ransomware attacks, ensuring that any backup point created remains untouched even if the rest of your computer is encrypted. Just be sure not to disable it in the settings...

Thank you for sharing; indeed, every bit of information is worth its weight in gold. I have been attempting some decoding myself, though very little success has been made. The files themselves didn't seem malicious, but that doesn't mean they don't harbor some underlying sin.
The best advice is to read everything thoroughly before opening it and never trust what you see at face value.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#16 ·
Jerry Robinson56 said:So then you head out with your crew for some fishing or maybe a round of paintball... total blast. Anyway, let me drop a little pro-tip on you—and honestly, everyone else lurking here too—if you want to keep your data super safe. Try this little trick: just change the file extension on whatever backup you’re trying to protect. You can literally rename it to anything you want. It works like a charm!

It wasn't actually for me—it was for my client... before they even brought me on board.

Look, let's be real—the backup was only hitting about five servers, and honestly? It hadn't even been running for months. Total disaster.

That's pretty sweet.

Whoever did this actually nailed it—they even came out ahead!

Thanks for reaching out! Honestly, any info you can throw my way is pure gold... I actually tried messing around with some decoding myself, but I didn't get much going. The files didn't look straight-up malicious or anything, but hey, just because they look clean doesn't mean there isn't some hidden nastiness lurking inside.
Best advice I can give you? Seriously, read every single word before you click anything. Don't just skim it, either. You can't trust everything you see on the screen—it's all a trap waiting to happen!

Man, you’re just wasting your breath. Every single .doc, .xls, even those sneaky .pdfs can be packed with code that triggers the second you open them. It’s all by Microsoft design—but hey, I guess some people are just dying to act like they're Bill Gates, right?

The whole damn IT industry is basically rigged to spread chaos just so they can slap a massive price tag on the tools needed to fix it. It's a total racket!
Jerry Robinson56 Jerry Robinson56 Regular
320 messages
joined Apr 2013
#17 ·
Jack Cook7 said:It wasn't my issue, but rather my client's... occurring just before they brought me on board.

Naturally, the backup was only spread across about five servers and had been failing for months.

How charming.

Whoever handled it should be lucky they weren't sued.

A federal agency, of course... 😉

Jack Cook7 said:It’s a lost cause. Any .doc, .xls, or even a .pdf file can contain code that executes automatically upon opening. It's by Microsoft design; apparently, everyone else just wants to be Bill Gates.

The entire IT industry is essentially engineered to propagate garbage, solely so they can peddle expensive tools to fix that very same garbage later on.

Understood, but what about extensions the system doesn't recognize, like .sst? 😁 ...
That is precisely why your suggestion of moving copies to write-once media makes sense. CDs are a decent option here. A Seagate drive would allow you to lock the disc after burning, making it inaccessible without a password... though, I suppose such locking is merely a relative form of protection.

As for assisting a fellow forum member... I lack both the specialized expertise and, more importantly, the time required for experimentation.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#18 ·
Jerry Robinson56 said:government agencies, man... 😉

And don't even get me started on private corporations.

sure, but if it doesn't recognize certain extensions like .sst... 😁 ...
That’s why what you suggested—making copies onto media that won't let you change the contents—is solid. CDs are fine for that. I remember back in the day, Seagate drives actually let you lock a CD after burning it so you couldn't open it without a password... though, hey, locking it is really just "relative" protection.

Look, I'd love to help this guy out... but honestly? I don't have the expertise, and I definitely don't have the time to play around with trial and error.

You're talking about rewritable CDs or DVDs. Sure, there's write-once stuff, multi-session options, you can even use write-only tapes, but what's the point if whatever you're stashing in an off-site vault has already been compromised for months?

There are ways to fix this (aka prevention), but who cares? It costs money.

Even that can be decrypted eventually; people just act like it isn't an issue.
Jerry Robinson56 Jerry Robinson56 Regular
320 messages
joined Apr 2013
#19 ·
Jack Cook7 said:You talk about rewritable CDs or DVDs. You mention single-session writes, multi-session capabilities, and even the option to burn data to tape. But frankly, what is the point? If the data you are tucking away in some remote vault has already been compromised for months, all that hardware is nothing more than expensive scrap metal.

There is such a thing as a cure—or more accurately, prevention—but frankly, nobody cares. The incentive simply isn't there. At the end of the day, someone has to pay the bill, and the system is designed to ensure that money keeps flowing regardless of whether we stay healthy or not.

It could be decrypted just as easily, but frankly, nobody gives a damn.

It isn’t necessary to use the write-protect flag here. You can actually go ahead and wipe them entirely—just perform a full format. Simply use the standard -R command.

It brings to mind that rather unsettling concept of imaginary data erasure during a fresh write or a recovery process. You are left staring at nothing but the final session, as if the preceding history simply ceased to exist.
One could certainly attempt to "seal the borders" to ensure that no further influence from outside forces can penetrate our sovereignty.

You must log in or register to reply here.

Log in Register

🔗 Similar threads