Mr.47 Posted May 19, 2017 Report Share Posted May 19, 2017 Hi Team I need some help with the new amnesia (attached) which I try your tool and still not working. encrypted.zip Link to comment Share on other sites More sharing options...
bruticus0 Posted May 19, 2017 Report Share Posted May 19, 2017 I can't d/l links since I'm just a user. So I don't know your file's extensions. The updated decryptor is for these files extensions: .01, .02, [email protected]_2017, .amnesia, .CRYPTOBOSS, .[[email protected]].SON, .[[email protected]].LOCKED The detailed usage of the Amnesia Decryptor is here . The thread for Amnesia at bleepingcomputer is here, where it looks like most everyone has gotten their files back. Looks like those with the .02 extension might have to be renamed to .amnesia to get it to work. But that was before the decryptor update. You need to use an original file and it's encrypted counterpart to get the key for your system. If excel is encrypted, download the same version and use that as your file pair. Program Readmes, PNGs, and favorites rarely change even across versions. The original doesn't have to come from your own system, just has to be the very same file unencrypted. Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted May 19, 2017 Report Share Posted May 19, 2017 @Mr.47 This is definitely Amnesia. Our Amnesia decryption tool can be downloaded from https://decrypter.emsisoft.com/download/amnesia Usage Guide download https://decrypter.emsisoft.com/howtos/emsisoft_howto_amnesia.pdf 1 Link to comment Share on other sites More sharing options...
Mr.47 Posted May 20, 2017 Author Report Share Posted May 20, 2017 Kevin and bruticus I tried the tool and it cant be crackable using emisoft amnesia tool. Link to comment Share on other sites More sharing options...
bruticus0 Posted May 20, 2017 Report Share Posted May 20, 2017 You're gonna have to give us more to work with than that. The amnesia decrytor seems to work for everyone that's tried it. So let's start from square one. What's your encrypted file extension? Did you go to the RansomID website here and make sure what kind of ransomware you have. Upload a file pair. A "File Pair" is an unencrypted file, and the same file after it has been encrypted. If your Microsoft Excel is encrypted, download the same version of Excel from the internet and use that. Link to comment Share on other sites More sharing options...
Sarah W Posted May 20, 2017 Report Share Posted May 20, 2017 Hi all, We got a sample of a new version of Amnesia, we are currently looking into it. Please be patient. Regards, Sarah Link to comment Share on other sites More sharing options...
Fritz Posted May 24, 2017 Report Share Posted May 24, 2017 Hi all, I've got infected with the .amnesia ransomware. Also it is positively identified as the Amnesia Ransomware by the Ransom ID website. Also I have the original and encrypted files, but the decryptor is not working. I've tried a few files, but stil no luck. Attached some sample files. Any solution yet? Many thanks. COR39_CAB Foods (Pty) Ltd - 15.07.2014 Final.tif d00000000009Hw7KeP8T-iNEjE3+ZCUZ4k+8SLu3FdzsLuv5gGAea7WdgJNKDa1JNA0omTmHcLxXBxBAYH7Yh4cYbUT7wOBo.amnesia 70000000003XqDYIu1r3MUqU37tygXaalMjY9fTa5FmF3SpDWR4FWM.amnesia 4w000000003q+lytC77sYWx+9u36PqkB1VQw+kJexdrj0JBMQATgZg.amnesia HR Manual.docx Link to comment Share on other sites More sharing options...
bezzell Posted May 26, 2017 Report Share Posted May 26, 2017 Sarah W, is there any update on the new iteration of the Amnesia decrypt tool? Link to comment Share on other sites More sharing options...
Fabian Wosar Posted May 26, 2017 Report Share Posted May 26, 2017 There isn't. I have been sick for the past week so it was put off until I got better. I have almost recovered though and will probably look into the new version on Sunday. Link to comment Share on other sites More sharing options...
Fritz Posted May 28, 2017 Report Share Posted May 28, 2017 Hi all, Thanks again for all your help and effort. Attached the "guide.exe" file aswell. Hope this will help. Many thanks, guide.zip Link to comment Share on other sites More sharing options...
Daniel Ekeroth Posted May 30, 2017 Report Share Posted May 30, 2017 Our server was also struck over the weekend by this new version of Amnesia. Have tried the decryptor without success. Attaching sample of file recovered from backup and it's encrypted version. Any help you can provide on this is greatly appreciated as our company's software as a service is now completely still due to KLS Backup creating a corrupt archive (guess I only have myself to blame though for not checking the "Check archive on completion" flag.) If you need more files I have about 200 000 of them ^^ Cheers! 3M000000000XKK5JstF+7IxMHTFnIUl2.amnesia convert.DBF Link to comment Share on other sites More sharing options...
Sarah W Posted May 30, 2017 Report Share Posted May 30, 2017 We just released a new decrypter for this variant, you can find it here. Please make sure to secure RDP, install all Windows updates and make backups of files (disconnected from the system, hopefully). If you appreciate the work we do and need a security solution that can protect against ransomware; we have our own security software Emsisoft Anti-Malware. Regards, Sarah W Link to comment Share on other sites More sharing options...
Daniel Ekeroth Posted May 30, 2017 Report Share Posted May 30, 2017 2 hours ago, Sarah W said: We just released a new decrypter for this variant, you can find it here. Please make sure to secure RDP, install all Windows updates and make backups of files (disconnected from the system, hopefully). If you appreciate the work we do and need a security solution that can protect against ransomware; we have our own security software Emsisoft Anti-Malware. Regards, Sarah W Thank you! I downloaded it and will test - turns out for the backup archives it worked by just renaming the extension to .zip again and do a repair in WinRAR - all good with getting things back in order! Link to comment Share on other sites More sharing options...
Daniel Ekeroth Posted May 31, 2017 Report Share Posted May 31, 2017 Just wanted to report back and let you know that the new version of the decryptor is working fine - slow and steady process of recovering a few files that were lost in the backups. Link to comment Share on other sites More sharing options...
Fritz Posted May 31, 2017 Report Share Posted May 31, 2017 Thank you Sarah W and your team. I have managed to decrypt some files successfully with the new decryptor. I'm going to decrypt some folders this weekend, but so far all seems to be working! I will be in contact next week with your security team @ Emsisoft for advise on purchasing and implementing your products for my corporate clients here in South Africa. Many thanks! Link to comment Share on other sites More sharing options...
ITHell Posted June 3, 2017 Report Share Posted June 3, 2017 Hi, I have been hit with the Amnesia virus but the decryptor does not seem to work. I have used the online identifier and get the result: This ransomware is decryptable! Identified by custom_rule: Encrypted size marker [0x00 - 0x08] 0x0400100000000000 Click here for more information about Amnesia2 However when I use the amnesia2 tool it says it cannot find the key. it does not even try the error comes back after 1 second. The email on my ransom note is [email protected] - not sure if it is a new version, the infection happened 3 days ago. I am trying to decrypt the files on another PC rather than the infected one. Don't know if that matters. Any help would be great. Thanks. Link to comment Share on other sites More sharing options...
ITHell Posted June 4, 2017 Report Share Posted June 4, 2017 19 hours ago, ITHell said: Hi, I have been hit with the Amnesia virus but the decryptor does not seem to work. I have used the online identifier and get the result: This ransomware is decryptable! Identified by custom_rule: Encrypted size marker [0x00 - 0x08] 0x0400100000000000 Click here for more information about Amnesia2 However when I use the amnesia2 tool it says it cannot find the key. it does not even try the error comes back after 1 second. The email on my ransom note is [email protected] - not sure if it is a new version, the infection happened 3 days ago. I am trying to decrypt the files on another PC rather than the infected one. Don't know if that matters. Any help would be great. Thanks. The Amnesia2 decryption tool is working fine. I had version 0.41 that was not working however the latest version 0.43 is working. Link to comment Share on other sites More sharing options...
zee666 Posted June 5, 2017 Report Share Posted June 5, 2017 Amnesia2 decryption tool .43 keeps crashing. ID ransomware identified it as Amnesia2. Have uploaded the originals after comparing file sizes the encrypted file and ransom note. Please assist....... Z bg000000000g5[email protected]decrypt_files2017 HOW TO RECOVER ENCRYPTED FILES.TXT Counter Intelligence POS - Held Sales.mdf Link to comment Share on other sites More sharing options...
DrJekyll_XYZ Posted June 5, 2017 Report Share Posted June 5, 2017 Hi All, We have been hit by ransomware. I do not have any original files to pair up with. The ransomware is detected as Amnesia2 however the program consistently crashes on me from 2 different machines. It infected a server and also targeted the backups on the NAS. I get a read access error flagged up on one machine and on the other the program just closes after 5 minutes without an error. Im at a loss, Im going to take a copy of the server and the NAS and put them into a test environment. If anybody needs anything from me for this just let me know. Any assistance is greatly appreciated 6g000000000wuHHXeap9yoTc8IInxXjM8IJj4+BrESY-LXTIhJTE+M.amnesia HOW TO RECOVER ENCRYPTED FILES.TXT Link to comment Share on other sites More sharing options...
Naad Posted June 5, 2017 Report Share Posted June 5, 2017 Hi All, We have been hit by ransomware. The ransomware is detected as Amnesia2 on id-ransomware. Tried the Amnesia2 decryptor but the program keeps crashing. Even tried to rename some files to have .amnesia extension however the program consistently crashes on me from 2 different machines. It infected a server and also the backups. Any assistance is greatly appreciated 6g000[email protected]gmx.us 8M000000002nHwaw1k+bLX4aqw[email protected]gmx.us HOW TO RECOVER ENCRYPTED FILES Link to comment Share on other sites More sharing options...
Fritz Posted June 5, 2017 Report Share Posted June 5, 2017 Hi All, I had no problems with the "previous" version of decryptor. I was also infected with the amnesia2 ransomware and are busy decrypting files, thanks to Emsisoft team. Also remember decrypting is a long process.This is what I have done and hopefully it may help: - Copied the encryption files on external harddrive. - Copied the decryptor file on a "clean" pc on desktop. - Right click on decryptor icon and under properties I checked the following "boxes": - Run as administrator & Compatibility mode: Windows 7 - Closed all programs as decryptor will use 100% cpu resources. Regards, Link to comment Share on other sites More sharing options...
Fabian Wosar Posted June 5, 2017 Report Share Posted June 5, 2017 Published a new version (1.0.0.45) that should fix the crash. If it doesn't, please let me know. Link to comment Share on other sites More sharing options...
Naad Posted June 5, 2017 Report Share Posted June 5, 2017 Works now with 1.0.0.45, thanks Link to comment Share on other sites More sharing options...
Fabian Wosar Posted June 5, 2017 Report Share Posted June 5, 2017 Glad it is working now Link to comment Share on other sites More sharing options...
ITHell Posted June 5, 2017 Report Share Posted June 5, 2017 26 minutes ago, Fabian Wosar said: Glad it is working now I am using the latest amnesia2 tool to decrypt a lot of data (25k files). Probably 90-95% is doing fine but there are some files that the tool just skips past. Its like it does not recognize they are encrypted by the malware and cannot see them. If I put some of these files in a folder the program just comes up "finished". It seems to happen with different extensions too. I have seen it skip PDFs, Jpegs and XLS files. Would it be helpful for me to send some of these to you to help improve the tool? Thanks for your help. Link to comment Share on other sites More sharing options...
Fabian Wosar Posted June 5, 2017 Report Share Posted June 5, 2017 Sure, feel free to submit one or two of those files. Link to comment Share on other sites More sharing options...
Mark.Redhead Posted June 6, 2017 Report Share Posted June 6, 2017 we have been hit by the Amnesia virus. The email on the ransom note is [email protected]. I have tried using the de-encryption tool version 1.0.0.45. When I drag the 2 files over it immediately goes through to the Licence terms page, if I carry on through to try to decrypt it just hangs on the first file it finds. I have tried various sets of files and get the same result. I would appreciate any help possible. I have also tried older versions decryptor but none work. thanks Link to comment Share on other sites More sharing options...
Mark.Redhead Posted June 6, 2017 Report Share Posted June 6, 2017 Ignore the above post, it's working. I was just being impatient. thanks for your help Link to comment Share on other sites More sharing options...
NiglKam Posted June 11, 2017 Report Share Posted June 11, 2017 Hello! A week ago our server was sifrovane. The majority of the files we managed to decipher. However, another 400 files are encrypted. An example of the Encrypted and the original file in the attached files. https://id-ransomware.malwarehunterteam.com recognize as Amnesia. However, Amnesia and Decrypter for Decrypter for Amnesia2 not help. Please help to decrypt files. 5w000000003Zo9ppJkzGhjVY0Rjnkvl-QZXiQ5u3c3MI+VF5kr04+0.[[email protected]] 6w000000001XOuXH1aFZCNEEfbv6Nmf0BBJkZd4dfLHTK0Yr+gJZ2g.[[email protected]] БДР факт 2013.xlsx Список участников.docx Link to comment Share on other sites More sharing options...
TechSup11 Posted June 15, 2017 Report Share Posted June 15, 2017 (edited) ID-Ransomware identified this variant as Amnesia2. Ransom note also looks like Amnesia2. None of the files are registered as Amnesia2 by the Decrypter. currently tested on 1.0.0.46Sample files and ransom note: https://www.sendspace.com/filegroup/F%2F8DiwJfaYUI6sQYeowRuy9ELSFy8hQf Matching pair - https://www.sendspace.com/filegroup/%2FAdVpeaoBYWdGdbwHkf33g Edited June 15, 2017 by TechSup11 Found a matching pair. Thought it might assist in recovery Link to comment Share on other sites More sharing options...
Demonslay335 Posted June 15, 2017 Report Share Posted June 15, 2017 2 hours ago, TechSup11 said: ID-Ransomware identified this variant as Amnesia2. Ransom note also looks like Amnesia2. None of the files are registered as Amnesia2 by the Decrypter. currently tested on 1.0.0.46Sample files and ransom note: https://www.sendspace.com/filegroup/F%2F8DiwJfaYUI6sQYeowRuy9ELSFy8hQf Matching pair - https://www.sendspace.com/filegroup/%2FAdVpeaoBYWdGdbwHkf33g I'm afraid the Amnesia2 identification is false-positive due to the email address. It does not match the hex pattern, and is thus not encrypted by Amnesia2 (or Amnesia1 or any other Globe variant). The ransom note pattern is actually GlobeImposter 2.0, you can tell by the ID being hex with spaces. It is not decryptable. Link to comment Share on other sites More sharing options...
Recommended Posts