We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Held to ransom by Zepto !

Unfortunately my other half opened an e-mail yesterday and opened the door to something i'd never heard of before .........Zepto virus !
Anyway, it has encrypted all the files and left a ransom note like a screensaver, telling me to follow instructions of how to buy bit-coins, and pay for the code, so it can be sent to me in order that her files can be decrypted and everybody's happy.
Well as you can guess..........not a penny is going to be paid to any criminal, but the worst thing is that all her photos of our families and friends........everything, not one left....... all encrypted.
I know that everything should have been backed up, but it's too late now I'm afraid.
Other than paying money for the code ( Which isn't going to happen ) They'd just take the money and run anyway !.....is there any way of retrieving the lost files please ?
HELP !!!!!!!!!!!!!!!!!!!!!!!!!
Thanks for any !
«1345

Comments

  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    Hi,
    Im sorry to be the bearer of bad news - but you have 3 choices here ..


    1. Pay the ransom if your files are worth the demanded amount to you.
    2. Restore from a backup (not much use if you dont have one)
    3. Lose your files


    Hindsight is a b!tch but maybe others can learn a bit here about clicking links in emails or opening attachments.


    I presume all your files have been renamed to something.zepto ?


    As a massive massive longshot, there are imitation "ransomware" out there that only rename the files without encrypting them - So you could try changing the extention to one of them back to what it should be.
    But as i say, it most likely wont work.


    You cant decrypt your files without the private key they have created.
    No way, no how


    They do , however, USUALLY honor the payment and provide you with the relevent key to decrypt your files.
    Not because they are nice people, but because it encourages others to pay.


    Sorry for your loss :(
  • NiftyDigits
    NiftyDigits Posts: 10,459 Forumite
    Before you go to cry in your beer after reading the post above, you should look here
    If that doesn't work look here
  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    And please come back and let us know how that works out for you
  • bloodnok
    bloodnok Posts: 298 Forumite
    Part of the Furniture Combo Breaker
    edited 20 July 2016 at 3:45PM
    Thanks,
    I have looked it up via google and seen a few sites which want you to download God knows what......Am too sceptical to try any until a I know for certain that they are genuine safe sites before going down that road !!
    C'est la vie !
    Let this be a lesson to anyone out there who hasn't backed up everything that they wouldn't want to lose !
    Still, any help will be gratefully accepted.
  • NiftyDigits
    NiftyDigits Posts: 10,459 Forumite
    If you don't like the links provided, then go directly to the source. For instance, Kaspersky for the RannohDecrypter
  • bloodnok
    bloodnok Posts: 298 Forumite
    Part of the Furniture Combo Breaker
    Will passwords etc for online banking etc be compromised by this virus as everything else.... e.g. browsing, e-mails etc seem to be functioning ok.
    The computer is turned off at the moment and disconnected from the router........Oh yes, it's running on windows 10.........using my daughter's mac at the moment.
  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    All these horrible programs do - is to encrypt the files on your machine ..


    BUT ..


    There is nothing to say that the dropper didnt also download other nasties such as credential harvester etc.


    It is unlikely, as their main goal is to get you to pay the ransom (which most likely equates to a small fortune in the country where this will have originated from)


    But if you want to be belt and braces - change all your password for sensitive stuff.
    It cant hurt ..


    Best of luck
    Andy


    Oh, and please do come back if you try one of the decryptor tools and let us know how that goes for you.
    I havent seen any of them work, even once , for the newer strains of this sh1te..
    Hence me not recomending them


    But you never know
  • bloodnok
    bloodnok Posts: 298 Forumite
    Part of the Furniture Combo Breaker
    I will keep you up to date.........let's hope some brain-box comes up with some clever software !
    Thanks for any advice anyone has !
  • forgotmyname
    forgotmyname Posts: 32,946 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Its already infected what can you download thats worse?

    Another virus that encrypts the encrypted files?

    If that happens start again and get a backup drive.

    Our photo's are on a NAS and also on 3 PC's. It would take something catastrophic to wipe all of them out.
    Censorship Reigns Supreme in Troll City...

  • marleyboy
    marleyboy Posts: 16,698 Forumite
    10,000 Posts Combo Breaker
    This is probably too late OP but it is possible to remove the virus and decrypt your files from here..

    https://www.bugsfighter.com/remove-zepto-ransomware-decrypt-zepto-files/

    I strongly recommend you read ALL of it before proceeding, I cannot give a cast iron guarantee of success so do let us all know how you get on.
    :A:dance:1+1+1=1:dance::A
    "Marleyboy you are a legend!"
    MarleyBoy "You are the Greatest"
    Marleyboy You Are A Legend!
    Marleyboy speaks sense
    marleyboy (total legend)
    Marleyboy - You are, indeed, a legend.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.2K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.