Quick CTB-Locker question. Ransomeware?

Compman55

Golden Member
Feb 14, 2010
1,241
0
76
I am working on a computer that got hit by the CTB-Locker ransomeware virus. The hard drive with all the personal data on it got encypted. Would there by any benefit in replacing the hard drive and storing the infected one for some day in the future that a decryption tool becomes avail? The info is not urgent right now, but if within 6 months to a year it could be recovered this would be preferred.

If there is absolutly no chance, I will just reformat.
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
Hitman Pro might be able to recover the encrypted files, I think.

But if that doesn't work then I guess it wouldn't hurt keeping the contents of the drive around.
 

Compman55

Golden Member
Feb 14, 2010
1,241
0
76
What I am trying to get at, is I have two choices, format and reinstall. Or yank the drive and put it on a shelf, and install a new one. I would just like to know if there is likely to be a tool in the future. I do not study up on this stuff, so I don;t know the success rate of tools coming out in the future.
 

compman25

Diamond Member
Jan 12, 2006
3,767
2
81
Hitman-Pro can't decrypt files encrypted by CTB, you might be able to use volume shadow copies of your files to restore them if CTB didn't delete them.
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51

Elixer

Lifer
May 7, 2002
10,376
762
126
I am working on a computer that got hit by the CTB-Locker ransomeware virus. The hard drive with all the personal data on it got encypted. Would there by any benefit in replacing the hard drive and storing the infected one for some day in the future that a decryption tool becomes avail? The info is not urgent right now, but if within 6 months to a year it could be recovered this would be preferred.

If there is absolutly no chance, I will just reformat.

No backups at all ?

Sure, there is always a chance that someone might have a decrypt tool available.
I guess it depends what version of the malware, and if they left a key on the HD already or not.

However, I wouldn't get my hopes up, consider it a lesson learned.
 

MustISO

Lifer
Oct 9, 1999
11,928
12
81
I would format it and let it be a hard lesson for the user. Maybe next time they'll have a proper backup system.
 

Fardringle

Diamond Member
Oct 23, 2000
9,190
755
126
Sandboxie is not a fix for everything, and certainly is not a replacement for a good backup plan.
 

Compman55

Golden Member
Feb 14, 2010
1,241
0
76
CTB-Locker has won this hard drive!

System restore was turned off by default, and there were no previous volume shadow copies. I blame dell for this, it should be turned on by default. Most average users do not know to check this. I am quite certain this would have provided at least a partial recovery.

Hitman po = nothing
Various Cryptolocker decypter tools = nothing
Piriform Reccua = recovered gibberish
Photorec = recovered lots more gibberish

Overall this is the worst one I have worked with, and there are lots of people out there not backing up properly that are going to loose a liftime of data. Other ransomeware, malware, etc are just annoying. This is real!
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |