Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

TeslaDecoder released to decrypt .EXX, .EZZ, .ECC files encrypted by TeslaCrypt


  • Please log in to reply
2251 replies to this topic

#16 neo-harqq

neo-harqq

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:17 PM

Posted 20 May 2015 - 12:04 AM

 

i tried to use this decoder but didn't work on key file storage.bin
warning message :

  • - data file version 4 recognized
  • - descryption key is not present in data file
  • - decryption key was destroyed by teslacrypt
  • - unfortunately this tool can't recover descryption key :-( 

 
nb: i move storage.bin to drive C:\file virus and i load manually use this decoder
 
so how?? any update or something i miss??

It worked, storage.bin was decrypted and checked, but unfortunately your decryption key was already destroyed by TeslaCrypt. TeslaCrypt destroys decryption key when all of your files were encrypted. When this happens I can't recover your decryption key from data file without TeslaCrypt's writters private key.
When decryption key can't be recovered I recommend to backup up all your encrypted files, data file (key.dat or storage.bin) and recovery_key.txt or recovery_file.txt and wait for another solution.

 

Hi BloodDolly

i know what you mean coz i already read it (www.bleepingcomputer.com/forums/t/575875/new-teslacrypt-version-released-that-uses-the-exx-extension/page-3#entry3708349) and i'll follow your recommend to backup all files. i use another HDD to reinstall OS, ( i keep my infected HDD ) and wait another solution..

hope you can found the another solution and post here..

thanks before&after..


Edited by neo-harqq, 20 May 2015 - 12:06 AM.


BC AdBot (Login to Remove)

 


#17 bgd25

bgd25

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 20 May 2015 - 04:12 AM

Hi BloodDolly,

 

where i can find key.dat/storage.bin..  i try search entire c drive using search box..but still can't find it..any suggesstion?



#18 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:17 AM

Posted 20 May 2015 - 05:25 AM

Files associated with unnamed variant of TeslaCrypt:
%LocalAppData%\storage.bin
%LocalAppData%\<random>.exe
%LocalAppData%\log.html
%Desktop%\Save_Files.lnk

Files associated with Alpha Crypt:
%Desktop%\Save_Files.lnk
%AppData%\blburkg.exe
%AppData%\log.html
%AppData%\key.dat = C:\Users\[user name]\AppData\Roaming\key.dat

Files associated with TeslaCrypt:
%AppData%\<random>.exe
%AppData%\log.html
%Desktop%\CryptoLocker.lnk
%AppData%\key.dat = C:\Users\[user name]\AppData\Roaming\key.dat

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#19 2puggles

2puggles

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:08:17 AM

Posted 20 May 2015 - 01:50 PM

Computer got infected May13th, 2015... So when I came across this thread today, I was quite happy to say the least!!

 

I ran the TeslaDecoder, and it came back with the decryption key.

However, I am at a loss for how to actually decrypt the files/folders... or if it's even possible.

345kg7o.jpg

 

Any help or suggestion with what to do next is very much appreciated!


Edited by 2puggles, 20 May 2015 - 01:50 PM.


#20 gotrojans

gotrojans

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:17 AM

Posted 20 May 2015 - 01:56 PM

Cisco Talos indicated that they were going to try using the recovery_file file, and they haven't moved forward on it yet. 

 

Based on what you are saying, I can understand why.

 

Thanks for your response BloodDolly.

 

Ron



#21 MorrisTechSayre

MorrisTechSayre

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:17 AM

Posted 20 May 2015 - 03:07 PM

Here's what I am getting on my screen when trying to use this. Any advice
The top of the image is the bitcoin address that's in the key.dat file.

 

image.png


Edited by MorrisTechSayre, 20 May 2015 - 03:08 PM.


#22 BloodDolly

BloodDolly

  •  Avatar image
  • Security Colleague
  • 526 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Slovakia
  • Local time:02:17 PM

Posted 20 May 2015 - 04:23 PM

Computer got infected May13th, 2015... So when I came across this thread today, I was quite happy to say the least!!

 

I ran the TeslaDecoder, and it came back with the decryption key.

However, I am at a loss for how to actually decrypt the files/folders... or if it's even possible.

345kg7o.jpg

 

Any help or suggestion with what to do next is very much appreciated!

Oops, my fault, I will fix it tomorrow. :-)

Hotfixed, download it again and try.


Edited by BloodDolly, 20 May 2015 - 04:43 PM.


#23 ViennaNeedsHELP

ViennaNeedsHELP

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:17 PM

Posted 21 May 2015 - 05:48 AM

Need also help

come from europe/austria/vienna speak "german", very bad english

have laptop with win 7, but as second system "windows XP" ("emuated??") on it (not from me, but from shop i bought laptop

because i would not buy without my Windows XP (i am about 60 years old, i am not able to learn new system, i last work about 8 y on Win XP

congrats to this community, to get a new account worked well!!! so i am here......

to dolly: i do not know dropbox, but i got on your link and came to dropbox. to create an account there misfailed 3 times... do not know why.

 

so i do not know how do get the teslaDecoder she/you offer....

i want to try first before i ask anybody here, but i am even unable to download the programm because of the dropbox problem

 

i am the only one here who is infected in europe?

i am the smalest internet user you can imagine. only some mails every 2 weeks. do not know how i got infection.

my spams are 100x times highter than not-spam mails from family (1-2/week).

 

what can i do to get free from this malware and to see my pictures and word docs again.

 

Pay?????????

 

i think i am not even able to check this and pay, i never payed before in internet.....

 

pls help me, my work of 5 years is otherwise lost (about 1,5 - 2 Mio only private pictures of nature and horse-breeding would be lost

terrible....

 

at this moment local time is 1 pm, and where are you, whats the time there

is anybody here living in europe or germany or austria to help me????

 

thanks and greetings from vienna



#24 x2click

x2click

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:17 PM

Posted 21 May 2015 - 10:11 AM

Hi,

 

Thank you so much for creating this program.  It has helped to save all the files of a pensioner who kept his life's work on his pc and had very little backup when the crypto virus struck - everything was encrypted including the book he has been writing.  The only problem I have encountered so far is that it decrypted around 50% of the jpg files he has just fine and the other half are corrupted in some way (I kept the original encrypted versions of these).  Some of them are scans of really old war photos etc. All the files are on a 32bit xp pc.  When I try to open the corrupted ones in gimp it says:  "Not a JPEG file: starts with 0x87 0x9e" - the files always were jpg files though before the virus.  Can you shed any light on why some of them would get corrupt during decryption (I can provide b4 & after files if required).


Edited by x2click, 21 May 2015 - 10:12 AM.


#25 BloodDolly

BloodDolly

  •  Avatar image
  • Security Colleague
  • 526 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Slovakia
  • Local time:02:17 PM

Posted 21 May 2015 - 10:34 AM

Hi,

 

Thank you so much for creating this program.  It has helped to save all the files of a pensioner who kept his life's work on his pc and had very little backup when the crypto virus struck - everything was encrypted including the book he has been writing.  The only problem I have encountered so far is that it decrypted around 50% of the jpg files he has just fine and the other half are corrupted in some way (I kept the original encrypted versions of these).  Some of them are scans of really old war photos etc. All the files are on a 32bit xp pc.  When I try to open the corrupted ones in gimp it says:  "Not a JPEG file: starts with 0x87 0x9e" - the files always were jpg files though before the virus.  Can you shed any light on why some of them would get corrupt during decryption (I can provide b4 & after files if required).

Probably multiinfection with Tesla/AlphaCrypt. I sent you a PM.



#26 BloodDolly

BloodDolly

  •  Avatar image
  • Security Colleague
  • 526 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Slovakia
  • Local time:02:17 PM

Posted 21 May 2015 - 10:37 AM

Need also help

come from europe/austria/vienna speak "german", very bad english

have laptop with win 7, but as second system "windows XP" ("emuated??") on it (not from me, but from shop i bought laptop

because i would not buy without my Windows XP (i am about 60 years old, i am not able to learn new system, i last work about 8 y on Win XP

congrats to this community, to get a new account worked well!!! so i am here......

to dolly: i do not know dropbox, but i got on your link and came to dropbox. to create an account there misfailed 3 times... do not know why.

 

so i do not know how do get the teslaDecoder she/you offer....

i want to try first before i ask anybody here, but i am even unable to download the programm because of the dropbox problem

 

i am the only one here who is infected in europe?

i am the smalest internet user you can imagine. only some mails every 2 weeks. do not know how i got infection.

my spams are 100x times highter than not-spam mails from family (1-2/week).

 

what can i do to get free from this malware and to see my pictures and word docs again.

 

Pay?????????

 

i think i am not even able to check this and pay, i never payed before in internet.....

 

pls help me, my work of 5 years is otherwise lost (about 1,5 - 2 Mio only private pictures of nature and horse-breeding would be lost

terrible....

 

at this moment local time is 1 pm, and where are you, whats the time there

is anybody here living in europe or germany or austria to help me????

 

thanks and greetings from vienna

You don't have to be registered on dropbox to download my decoder. When a signup window popups you can close it by clicking on light blue X on the right top corner.



#27 2puggles

2puggles

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:08:17 AM

Posted 21 May 2015 - 05:16 PM


Oops, my fault, I will fix it tomorrow. :-)

Hotfixed, download it again and try.

 

 

Worked Great!! Thank you :-)



#28 kilikibi

kilikibi

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:17 PM

Posted 22 May 2015 - 06:19 AM

Hello,

Thank you for your help.

I was touched by the decryption .EXX   May 17
I installed a Windows 8.1 image by symantec immediately. But I still have the backup hard drive completely coded .EXX

Is there a way of doing something?

 

I have an idea: I can try to find the encryption key by "photorec" "under the installed image."

But what kind of key I'll get? what form does it?

Thank you very much again.

Kind regards,
kilikibi
Grenoble
France


Edited by kilikibi, 22 May 2015 - 09:42 AM.


#29 BloodDolly

BloodDolly

  •  Avatar image
  • Security Colleague
  • 526 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Slovakia
  • Local time:02:17 PM

Posted 22 May 2015 - 01:06 PM

Hello,

Thank you for your help.

I was touched by the decryption .EXX   May 17
I installed a Windows 8.1 image by symantec immediately. But I still have the backup hard drive completely coded .EXX

Is there a way of doing something?

 

I have an idea: I can try to find the encryption key by "photorec" "under the installed image."

But what kind of key I'll get? what form does it?

Thank you very much again.

Kind regards,
kilikibi
Grenoble
France

You need to find storage.bin in %localappdata% folder. Load this key into TeslaDecoder and you will see if decryption key is still in this file. If decryption key was destroyed, there is no way how my tool can decrypt your files and you have to wait for another solution. The new storage.bin is encrypted with AES, so it is not an easy task to search for it on raw disk.



#30 crisis2k

crisis2k

  •  Avatar image
  • Members
  • 121 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:17 PM

Posted 22 May 2015 - 08:10 PM

 

Computer got infected May13th, 2015... So when I came across this thread today, I was quite happy to say the least!!

 

I ran the TeslaDecoder, and it came back with the decryption key.

However, I am at a loss for how to actually decrypt the files/folders... or if it's even possible.

345kg7o.jpg

 

Any help or suggestion with what to do next is very much appreciated!

Oops, my fault, I will fix it tomorrow. :-)

Hotfixed, download it again and try.

 

 

 

Nice 0.0.53! BloodDolly i gratitude for your marvelous service.

will you keep upload newest version on https://www.dropbox.com/s/abcziurxly2380e/TeslaDecoder.zip?dl=0 sustainedly?


Edited by crisis2k, 22 May 2015 - 08:12 PM.

:welcome: My Name is Philip You Can Call Me Phil
Thank You I'll be there anytime you need help :rolleyes:





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users