Windows 10: TeslaCrypt ransomware now impossible to crack, researchers say

Discus and support TeslaCrypt ransomware now impossible to crack, researchers say in AntiVirus, Firewalls and System Security to solve the problem; Ramsomware has become a large presence on the net. The Locky virus is another example of the new ransomware that has no way to circumvent the... Discussion in 'AntiVirus, Firewalls and System Security' started by Borg 386, Mar 17, 2016.

  1. Borg 386 Win User

    TeslaCrypt ransomware now impossible to crack, researchers say


    Ramsomware has become a large presence on the net. The Locky virus is another example of the new ransomware that has no way to circumvent the encryption. If you want to effectively defend against this, your best defense is to have a back up of your OS & files. Your Anti Virus might stop the ransomware, but there's also a chance it won't.

    Windows has a built in program to make a system image. Or you can use another program of your choice. But not having a back up when this strikes means either loosing your files or paying up & hoping that you do receive the decryption key. Be smart & make a back up before it happens to your PC/Laptop.

    Please note that for your back up to have the best protection, it should be kept on an external HDD that is not normally connected to the computer at all times. The newer variants of this ransomware will seek out any/all disks, back ups & corrupt them.

    TeslaCrypt ransomware now impossible to crack, researchers say | PCWorld

    Free tools for making backups of your system.

    Five free tools for managing partitions - TechRepublic

    System Image - Create in Windows 10 - Windows 10 Forums

    :)
     
    Borg 386, Mar 17, 2016
    #1

  2. Files encrypted by TeslaCrypt (.aaa extension) ransomware

    TeslaCrypt includes several known versions and extension variants...unfortunately
    there is no way to decrypt the newer .aaa, .abc, .ccc variants
    without Tesla's private key. Earlier variants stored the private key as data files on the local disk which enabled victims to decrypt their files with the locally stored private key. These newer variants no longer store any data files
    on the local disk and information stored in the registry as binary data only contains public keys and each shared secret. The only other alternative is to save your data as is and wait for a possible breakthrough...meaning, what seems like an impossibility
    at the moment (decryption of your data), there is always hope someday there may be a possible solution so save the encrypted data and wait until that time.

    QUOTE from
    TeslaCrypt 2.0 disguised as CryptoWall


    "TeslaCrypt 2.0. This version is different from previous ones in that it uses a significantly improved encryption scheme, which means that it is currently impossible to decrypt files affected by TeslaCrypt. It also uses an HTML page instead
    of a GUI. Incidentally, the HTML page was copied from another Trojan – Cryptowall."


    QUOTE from
    TeslaCrypt 2.0 ransomware: stronger and more dangerous


    "First, they’ve adopted the sophisticated elliptic curve encryption algorithm from creators of the famous and very troublesome CTB-Locker ransomware. Secondly,
    they’ve changed the method of key storaging: now they are


    using the system registry instead of a file on disk. Thirdly, TeslaCrypt creators have stolen the web page which victims see after their files have been encrypted from another ransomware family, CryptoWall."
     
    quietman7 - MVP, Mar 17, 2016
    #2
  3. TeslaCrypt V2 ransomware infection

    I'm not 100 % sure but I think you might be infected by TeslaCrypt.

    Please see

    TeslaCrypt and Alpha Crypt Ransomware Information Guide and FAQ

    Quote from above guide:

    Info: There are active TeslaCrypt and AlphaCrypt support topics that contain discussion and the experiences of a variety of IT consultants, end users, and companies who have been affected by these ransomware programs. If you are interested in this
    infection or wish to ask questions about it, please visit either the
    TeslaCrypt support topic
    or
    Alpha Crypt Support Topic
    . Once at the topic, and if you are a
    registered
    member of the site, you can ask or answer questions and subscribe in order to get notifications when someone adds more information to the topic. It is also possible to decrypt earlier versions for free. To learn more about the various versions
    and if you can decrypt your files for free using TeslaDecoder, please read
    this section
    first.


    Cheers,

    J
     
    Jsssssssss, Mar 17, 2016
    #3
  4. altae Win User

    TeslaCrypt ransomware now impossible to crack, researchers say

    Well I'm done telling people to backup their data. No matter what you say they are not going to do it. I just read a story on some news page about a German town that actually paid the ransom to unlock the data on their network because they had no backup *Roflmao2
     
    altae, Mar 18, 2016
    #4
  5. simrick Win User
    Excellent post Dr. Borg. Now, if we could just get people to do the backups, *before* they get hit...instead of learning a hard lesson.
     
    simrick, Mar 18, 2016
    #5
  6. Borg 386 Win User
    I read that too....I couldn't believe it. It was a hospital or some gov office. Unbelievable, that places like that don't take proper actions to guard/back up their data *Rolleyes

    And no matter how long it takes to make an image, it's well worth the time it took.

    Yepperz, that's the trick, getting them to do it BEFORE disaster strikes.
     
    Borg 386, Mar 18, 2016
    #6
  7. The new ransomware encrypts connected storage places like an external HDD as well as cloud backups.
    Anyway, since ransomware is so easy to avoid, I do not even consider it as a threat, just as a scareware.
     
    TairikuOkami, Mar 18, 2016
    #7
  8. OldMike65 Win User

    TeslaCrypt ransomware now impossible to crack, researchers say

    Only if you leave your External drive ON !!! Which you should not.....make your image backup to external drive, turn off....nothing can access that external drive then *Smile
     
    OldMike65, Mar 18, 2016
    #8
  9. Borg 386 Win User
    Exactly. As I mentioned above, keep your backups on a drive that you only use for that purpose. Anytime it's not being used to make a back up, disconnect it.

    BTW, something I've been noticing, it's getting harder to find a drive with an off/on switch. I have a couple that have that feature, but the last couple I found didn't have that option, they were on all the time. I fixed that on one of them by putting my own off/on switch in the middle of the power cord. I'll get to the other one soon enough. But still, kind of surprised they went that way. Of course the newer ones don't need an external power cord, they run straight off the USB connect.
     
    Borg 386, Mar 18, 2016
    #9
  10. OldMike65 Win User
    Hi Borg, I just use my external "toaster" it is 3.0 USB, has its on power button, can take Spinner or SSD Here's a pic .


    TeslaCrypt ransomware now impossible to crack, researchers say [​IMG]
     
    OldMike65, Mar 18, 2016
    #10
  11. altae Win User
    In fact it does not really take a lot of time. Ok, you have to setup the backup software once. But after that you just connect your backup drive(s), start the backup, go to bed and in the morning everything is done. There is absolutely no excuse for not backing up. Well at least apart from laziness, ignorance and plain stupidity *Wink

    Today's backup programs even allow system backups while the pc is in use. I'm backing up my system right now and at the same I'm writing this post. It's really a piece of cake. Ransomware? It does scare me as much as I'm afraid of hell... not at all!
     
    altae, Mar 18, 2016
    #11
  12. purplemtn Win User
    Borg 386

    Did you mean to make "Free tools for making backups of your system. " a Link ?
    Your 1st Post above

    Thanks Rick
     
    purplemtn, Mar 19, 2016
    #12
  13. TeslaCrypt ransomware now impossible to crack, researchers say

    The link is working for me if this is what you are asking.
     
    COMPUTIAC Guest, Mar 19, 2016
    #13
  14. derekimo Win User
    The link for those words is just below it,


    TeslaCrypt ransomware now impossible to crack, researchers say [​IMG]


    Which does work as COMPUTIAC pointed out.
     
    derekimo, Mar 19, 2016
    #14
  15. purplemtn Win User
    purplemtn, Mar 19, 2016
    #15
Thema:

TeslaCrypt ransomware now impossible to crack, researchers say

Loading...
  1. TeslaCrypt ransomware now impossible to crack, researchers say - Similar Threads - TeslaCrypt ransomware impossible

  2. minidump research

    in Windows 10 Gaming
    minidump research: Hello,My windows 11 PC started getting BSOD last month, once every few daysI would be happy if anybody could help me with the attached minidumpLink to minidumpThanks https://answers.microsoft.com/en-us/windows/forum/all/minidump-research/ab3c9456-1820-40ee-965d-879010929d34
  3. minidump research

    in Windows 10 Software and Apps
    minidump research: Hello,My windows 11 PC started getting BSOD last month, once every few daysI would be happy if anybody could help me with the attached minidumpLink to minidumpThanks https://answers.microsoft.com/en-us/windows/forum/all/minidump-research/ab3c9456-1820-40ee-965d-879010929d34
  4. Windows Research

    in Windows 10 Gaming
    Windows Research: Hello Everyone,For a while now, the Windows search indexing feature has not been working on my laptop running Windows 11. I've tried rebuilding it, and the system indicates that it may take some time, but despite multiple attempts, it still doesn't function properly.I'm...
  5. Windows Research

    in Windows 10 Software and Apps
    Windows Research: Hello Everyone,For a while now, the Windows search indexing feature has not been working on my laptop running Windows 11. I've tried rebuilding it, and the system indicates that it may take some time, but despite multiple attempts, it still doesn't function properly.I'm...
  6. HoloLens facilitates computer vision research with Research Mode

    in Windows 10 News
    HoloLens facilitates computer vision research with Research Mode: Microsoft HoloLens is the world’s first self-contained holographic computer. Remarkably, in Research Mode, available in the newest release of Windows 10 for HoloLens, it’s also a potent computer vision research device. Application code can not only access video and audio...
  7. Petya ransomware encryption system cracked

    in AntiVirus, Firewalls and System Security
    Petya ransomware encryption system cracked: Petya ransomware victims can now unlock infected computers without paying. An unidentified programmer has produced a tool that exploits shortfalls in the way the malware encrypts a file that allows Windows to start up. In notes put on code-sharing site Github, he said...
  8. Researchers crack new version of CryptXXX ransomware

    in AntiVirus, Firewalls and System Security
    Researchers crack new version of CryptXXX ransomware: Researchers from Kaspersky Lab have developed a method of decrypting files affected with the latest version of CryptXXX, a malware program that combines ransomware and information-stealing capabilities. The good news for users is that Kaspersky's researchers were able to...
  9. TeslaCrypt ransomware victims can now decrypt their files for free

    in AntiVirus, Firewalls and System Security
    TeslaCrypt ransomware victims can now decrypt their files for free: Victims of the widespread TeslaCrypt ransomware are in luck: Security researchers have created a tool that can decrypt files affected by recent versions of the malicious program. Surprisingly, the TeslaCrypt creators themselves helped the researchers. The tool can...
  10. Researchers say Intel's Management Engine feature can be switched off

    in Windows 10 News
    Researchers say Intel's Management Engine feature can be switched off: It seems some government customers can request Intel's always-on Management Engine (ME) 'master controller' for its CPUs to be disabled. That's not an option for the general public, but researchers at Russian security firm Positive Technologies have found a way to use...