Solved

Savepanda@india.com Ransomware

Posted on 2016-08-29
9
79 Views
Last Modified: 2016-09-20
I have a server currently impacted with the Savepanda@india.com ransomware virus, but am having no luck at all removing the encryption.  I believe I have taken care of the effected PC, but still have a network location full of files that I'm in desperate need of unlocking.  I have followed countless tutorials including using Kaspersky Shade Decryptor to try to remove the encryption, but the app says the encryption doesn't match any of those in the database.  Any assistance would be gratefully appreciated, as we are currently dead in the water.  Long story short, recovery from a backup is not possible, nor is Volume Shadow Copy.
0
Comment
Question by:Kyle Witter
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 61

Accepted Solution

by:
btan earned 300 total points (awarded by participants)
Comment Utility
better to use ID ransomware (https://id-ransomware.malwarehunterteam.com/) or Crypto Sheriff (https://www.nomoreransom.org/crypto-sheriff.php) to identify the ransomware so as to facilitate any available decryptor tool for it.

Likely it belong to the XTBL/CrySiS ransomware which is what I supposed you use the Shade decryptor and there is also no guarantee it works for variation of the ransom family. In fact there is another tool from McAfee too has a "Shade Ransomware Decryptor Tool". http://www.mcafee.com/us/downloads/free-tools/shadedecrypt.aspx

Good to confirm the type. I do suggest the clean build instead of scanning though you can go into the manual removal of the traces of the ransomware as shared in http://sensorstechforum.com/savepandaindia-com-virus-remove-restore-xtbl-files/

As a whole if there is no backup and the decryptor does not readily work, it is quite tough to get back those list of files..even forensic will be challenge as the malware will have securely wipe those files..
0
 
LVL 87

Expert Comment

by:rindi
Comment Utility
Delete the files on the server, then restore them from your backups.
0
 
LVL 1

Author Comment

by:Kyle Witter
Comment Utility
btan,

Thank you for the valueable information.  I'm working through the McAfee software now.. The ransom letter on this particular version does not show a key
0
 
LVL 87

Expert Comment

by:rindi
Comment Utility
Don't waste your time with non existing keys and decryption tools. Just do the restore from your backups and you'll be fine. That's one of the reasons you have backups for.
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 
LVL 1

Author Comment

by:Kyle Witter
Comment Utility
As previously mentioned, there are no backups of this device.
0
 
LVL 87

Assisted Solution

by:rindi
rindi earned 100 total points (awarded by participants)
Comment Utility
Then consider the data lost and start fresh. After all, it can't have been important data if there was no backup.
0
 
LVL 61

Assisted Solution

by:btan
btan earned 300 total points (awarded by participants)
Comment Utility
If you check the guide of the tool, it stated need to to get the private key file
1. Run the command with the User ID:
>shadedecrypt.exe -u F7AB2CA6D04AC4DA110C
You will receive a URL output to the console. Copy this URL into a browser and download the linked text
file. If you get a message such as "404 file not found" or " Cannot find file", then we have been
unable to locate the private key that encrypted the files.
So if that is missing the decryptor tool will not work for McAfee and also Kapersky. This variant may have already evolved to close up the gap and misses in the earlier version. Looks like there are no other means and you just have to move on then ...
http://www.mcafee.com/us/resources/misc/guides/shadedecrypt-readme.pdf
0
 
LVL 26

Assisted Solution

by:Thomas Zucker-Scharff
Thomas Zucker-Scharff earned 100 total points (awarded by participants)
Comment Utility
Generally if there is nothing on nomoreransom.org, then you are out of luck. Backups (versioning only) will help you in the future,  but for now those files may be lost.  Make a backup,  in case a key/ decryptor is made available in the future., then rebuild.
0
 
LVL 61

Expert Comment

by:btan
Comment Utility
As advised.
0

Featured Post

Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

Join & Write a Comment

Resolve DNS query failed errors for Exchange
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now