Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

0XXX (NAS) Ransomware (.0xxx) Support Topic


  • Please log in to reply
233 replies to this topic

#226 DanniellWebb

DanniellWebb

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  

Posted 31 May 2023 - 08:05 PM

 

 

Hello everyone. I can tell you what I did to recover around 70% of the encrypted files I had (almost 40 TB). You'll need:

  • A clean and ransomware-free operating system where you can run data recovery programs.
  • One or more clean hard drives with a larger capacity than the encrypted files, where you can dump a multitude of files.
  • Lots of patience and some programming knowledge (not too much).

The process I followed to recover the data is as follows:

  1. Scan both the disks with the encrypted files and other disks I had at home where I might have had some of these files, searching for remnants of the original files. This can be done with programs like Recuva (on Windows), Photorec (Linux, and possibly Windows as well), and others (I can provide more information if needed).

  2. These programs will often recover the files, but only partially or with overwritten parts, as well as a multitude of irrelevant files. It's like searching in a giant landfill... However, it is a fundamental step because we can then process them to recover the complete file.

  3. To recover the original files, we need to search for each encrypted file (extension .0xxx) if we can identify the same file among the ones we have recovered, even if it's incomplete. The ransomware only encrypts the first 64 KB, but the rest remains intact. So, if we compare, for example, the 2nd or 3rd block of 64 KB and see that they match, it might be the same file. I have done this using Linux programs coded by myself, very simple ones, but they do the job for me.

It is a process that can take days, weeks, or even months. But some results can be achieved, and there's nothing to lose by trying... If someone is desperate enough to attempt this and needs help, let me know, and I'll see what I can do.

 

Of course, it would be much better if someone manages to decrypt the files properly, but as we can see, that is difficult nowadays...

 

Best regards.

 

This might be a stupid question, but if the first 64KB is currupted and the rest is intact, is it possible to just removed the only encrpted part of the video and have the rest work jsut fine? 

 

Ive recently become a victim, early days, cleaned my machines multiple times with multiple products, taken first look at Nas, made a duplicate of an encrypted mp3 file, renamed that duplicate to original .mp3, no issues playing the track, repeated on the next with the same result?



BC AdBot (Login to Remove)

 


#227 milat2004

milat2004

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:45 AM

Posted 01 June 2023 - 05:05 AM

I changed the encrypted all mp3 files extension as mp3, no problem playing the tracks.



#228 w0rt3x

w0rt3x

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:45 PM

Posted 15 August 2023 - 09:27 AM

Would anyone bother to share the decryptor .exe so that we can tinker with it? Understand that you can make things worse, but it wouldn't hurt to make copies of the already encrypted files and test a few things...



#229 Bokerss

Bokerss

  •  Avatar image
  • Members
  • 137 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indonesia
  • Local time:12:45 PM

Posted 15 August 2023 - 10:21 PM

Before you guys testing or modified the files, please BACKUP all of your encrypted files because you CAN damaged or make the things worse.

 



#230 Draky

Draky

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:45 AM

Posted 29 January 2024 - 06:09 PM

Hello from France.

 

As said previously here : NAS with SMB's 445 port open on the router...

 

Didn't encrypt all files though, as if it were stopped before.

 

Full backup ok 2 days before so lucky...



#231 t0rn4d0

t0rn4d0

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:45 AM

Posted 20 April 2024 - 09:03 AM

Hi all.

Any news about a decryptor for x000 ?

I've 512+ mkvs crypted...

Thanks!



#232 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 20 April 2024 - 09:16 AM

There is nothing new to report that I am aware of.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#233 t0rn4d0

t0rn4d0

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:45 AM

Posted 20 April 2024 - 09:26 AM

There is nothing new to report that I am aware of.

 

Thanks!

I'm an experienced programmer.

Can I have a decryptor to disassemble with IdaPro/Ghidra ?

Cheers



#234 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 61,920 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:01:45 AM

Posted 20 April 2024 - 03:02 PM

We don't have access to a decryptor. Perhaps a previous victim who obtained one will read this topic and offer it to you.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





4 user(s) are reading this topic

0 members, 4 guests, 0 anonymous users