Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

BitCryptor ransomware in the wild from the same creators as CoinVault


  • Please log in to reply
34 replies to this topic

#16 JCL31

JCL31

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:21 PM

Posted 14 May 2015 - 11:05 AM

 

edit: never mind just looked at the phto properly, turns out you need a key...


You need a private key for pretty much every Cryptoware. Hence why someone can't just pay the ransom once and give the decrypter to everyone else. Sure, you now have the a decrypting utility for your files, but without the private key used for their encryption, it's useless.

 

Hi, I'm so sorry for my imperfect English, I use Google translation.
I m french.
I was a victim of Bitcryptor.
I managed to remove it, but the damage is done. Many files are encrypted. Part of my Synology also with many important files.
It may be a little early to have solutions.
Kaspersky had managed to find the keys to CoinVault but hackers have probably changed the rules with BitCrypt.
I think I'll wait for a solution to try to save and retrieve my files.
If anyone can help the community would be nice.


BC AdBot (Login to Remove)

 


#17 Aura

Aura

    Bleepin' Special Ops


  •  Avatar image
  • Malware Response Team
  • 19,709 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:21 AM

Posted 14 May 2015 - 12:34 PM

No worries JCL, French is my native language as well so if you ever need something translated to English, let me know :) And as soon as a method to decrypt the files encrypted by BitCryptor, for free, appears, Grinler will update this thread and post a News thread about it right away.

animinionsmalltext.gif


#18 JCL31

JCL31

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:21 PM

Posted 14 May 2015 - 01:23 PM

No worries JCL, French is my native language as well so if you ever need something translated to English, let me know :) And as soon as a method to decrypt the files encrypted by BitCryptor, for free, appears, Grinler will update this thread and post a News thread about it right away.

Ok Aura. !

Merci pour la réponse .... :-)

I remain hopeful because many files are damaged.
For information, the intrusion took place for 2 days, May 12 and May 13
In 5 hours, Bitcryptor examined, the SSD system, my partition dd, my linkstation of 1 to and part of synologie ....
I will be formatted as a precaution, and store my encrypted files believing in miracles.
I use Chrome as browser. I think I'll stop because I had a lot of malware that is installed without my knowledge.
Delta Homes and lately Duilib who settled in App.
A question?
I changed my connection determining my DNS by Open DNS.
Does this provide better protection?
Bye


#19 Aura

Aura

    Bleepin' Special Ops


  •  Avatar image
  • Malware Response Team
  • 19,709 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:21 AM

Posted 14 May 2015 - 01:57 PM

This is what I would do as well, back up all the encrypted files on another storage media, and leave them be until a free decryption method is found, one day. Also, Google Chrome is actually the most secure web browser there is. If you look at the number of exploits found in them, Google Chrome always have the fewest one founds, sometimes, not even one is. So you can keep on using it. You could however strenghten it (and your security) with extesions like Web of Trust, HTTPS Everywhere, Ghostery, uBlock Origin, etc. Also, Google DNS and OpenDNS are both good DNS servers to use. Personally, I use the Google's ones, but OpenDNS ones are good as well.

animinionsmalltext.gif


#20 PuReinSAniTY

PuReinSAniTY

  •  Avatar image
  • Members
  • 432 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:in a basement
  • Local time:10:51 PM

Posted 14 May 2015 - 07:19 PM

good point


they call me te java mayster


#21 Fremont PC

Fremont PC

  •  Avatar image
  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:06:21 AM

Posted 14 May 2015 - 08:59 PM

JCL31 -

 

It's also a good idea to have a sector-by-sector clone or backup of your hard drive, just in case decryption depends on files or registry settings that aren't easily seen. 

 

And as you now know, backup skills are a very worthwhile investment (and a very good skill to share with others).

 

Best of luck to you!


Edited by Fremont PC, 14 May 2015 - 09:17 PM.


#22 Nikhil_CV

Nikhil_CV

    Vestibulum Bleep


  •  Avatar image
  • Members
  • 1,145 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:err: Destination unreachable! bash!
  • Local time:06:51 PM

Posted 16 May 2015 - 07:12 AM

I would recommend JCL to go for using secure DNS servers like Norton Connect safe or Comodo secure DNS for better security while browsing.
Well, more will make this discussion off topic. So, that topic can be made as a new thread in networking subforum.
Regards : CV                                                                                                    There is no ONE TOUCH key to security!
                                                                                                                                       Be alert and vigilant....!
                                                                                                                                  Always have a Backup Plan!!! Because human idiotism doesn't have a cure! Stop highlighting!
                                                     Questions are to be asked, it helps you, me and others.  Knowledge is power, only when its shared to others.            :radioactive: signature contents © cv and Someone....... :wink:

#23 mata1908

mata1908

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 17 May 2015 - 02:08 PM

Hi guys,

 

I got hit by the same virus the other day and because I have some really important files (without a backup unfortunately) it made me pay the ransom.

After that the software started to decrypt the files but unfortunately it turned out that not all the files were successfully decrypted. When open a .pdf file for example it says that it can't open because the file might be damaged.

I tried to manually decrypt the files with the key I received by the software mentioned above, but unfortunately this did not help either.

 

Does any of you have an idea how to fix this big problem?

 

Thanks in advance.

 

Kind regards,

 

Mathijs



#24 JCL31

JCL31

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:21 PM

Posted 18 May 2015 - 02:02 PM

Hi guys,

 

I got hit by the same virus the other day and because I have some really important files (without a backup unfortunately) it made me pay the ransom.

After that the software started to decrypt the files but unfortunately it turned out that not all the files were successfully decrypted. When open a .pdf file for example it says that it can't open because the file might be damaged.

I tried to manually decrypt the files with the key I received by the software mentioned above, but unfortunately this did not help either.

 

Does any of you have an idea how to fix this big problem?

 

Thanks in advance.

 

Kind regards,

 

Mathijs

Hi!
You're not lucky, you either.
Be affected by this virus poses big problems for everyone.
You say you paid the ransom?
I think all hope is not lost!
Regarding the help that you ask, it would be useful to provide maximum information to the board administrator.
Maybe they need your software, the key and an attached file to work on him?
They could compare the two software, to provide solutions to all those affected by Bitcryptor?
Your gesture could also serve the victims of these scams.
Maybe you do not want because you paid?
But it would be an important action to help those who are in the same situation as yours, have the means or are afraid to pay.
It would be a blow to their business.
It's up to you.
Good luck anyway, and if you succeed to thank you for sharing those expectations solutions.
Bye.
Jean-Christophe


#25 Mike726

Mike726

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:51 PM

Posted 20 May 2015 - 07:35 AM

Hi, I got hit by BitCryptor. I have removed it but the damage has been done. I hope there will be a solution for the encrypted files soon.

 

There were 2 malicious processes that were running in my OS:

C:\Users\<PROFILE>\AppData\Roaming\Microsoft\Windows\bitcrywin.exe

C:\Users\<PROFILE>\AppData\Roaming\Microsoft\Windows\consoleh.exe



#26 Aura

Aura

    Bleepin' Special Ops


  •  Avatar image
  • Malware Response Team
  • 19,709 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:21 AM

Posted 20 May 2015 - 07:37 AM

Hi Mike :)

If you didn't delete these executables yet, it would be a good idea to upload them on BleepingComputer so the Security Experts here can take a look at them.

http://www.bleepingcomputer.com/submit-malware.php?channel=3

animinionsmalltext.gif


#27 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:21 AM

Posted 20 May 2015 - 02:09 PM

Hi, I got hit by BitCryptor. I have removed it but the damage has been done. I hope there will be a solution for the encrypted files soon.

BitCryptor encrypts files using AES 256 encryption and is unbreakable. At this time there is no fix tool and no way to retrieve the private key that can be used to decrypt your files without paying the ransom. The only other alternative is to save your data as is and wait for possible updates...meaning, what seems like an impossibility at the moment (decryption of your data) there is always hope someday there may be a breakthrough or possible solution so save the encrypted data and wait until that time.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#28 JCL31

JCL31

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:21 PM

Posted 21 May 2015 - 01:34 PM

Hi !

in my file

\ Users \ <PROFIL \ AppData \ Roaming \ Microsoft \ Windows \ filelist.locklst

 

encrypted files end for True

C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7_64\International\NVI2\btn_primary_180.png|True

 

Is that the word,True, means that they could have used TrueCrypt ?

 

I also found in \ AppData the file by Notepad

fingerprint=DD64-2A4B-D82B-0642-3613-6CC6-8585-8221 of May 12, 2015

 

and in

fingerprint=DD64-2A4B-D82B-0642-3613-6CC6-8585-8221 of May 13, 2015

 

Dates during which they have encrypted my files.

Is this is the public key ?

 

If it helps you.



#29 mata1908

mata1908

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:21 PM

Posted 25 May 2015 - 03:37 PM

I have send the "Bitcryptor Support" an email as I have paid and received the key.

Unfortunately as you can read in my previous post not everything got decrypted, this is the reply I received:

 

Please send us some files that didn't decrypt.
Please also fill in this form:
IP: (from whatismyipaddress.com)
Computername:
Username:
Your KEY:
Your IV:

If you can't find everything, that is no problem.
We will have a look at your problem.
--
BitCryptor Support Team

 

What do you guys think? Should I reply to this or will this make me even more vulnerable and are they never going to help someone out?

 

 

Kind regards,

M



#30 JCL31

JCL31

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:21 PM

Posted 07 September 2015 - 12:26 PM

Hello,
it seems that Bitcryptor is won. :flame:
No movement or solution has therefore been found? :radioactive:
 
Bye JC





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users