.Do_not_change_the_file_name.cryp File Virus (Restore Files) - How to, Technology and PC Security Forum | SensorsTechForum.com

.Do_not_change_the_file_name.cryp File Virus (Restore Files)

Article created to help you remove the Robert Swat ransomware virus and extension and to restore Do_not_change_the_file_name.cryp files encrypted by it.

A very odd virus has appeared in the wild. The malware is from the file encryption kind and uses the e-mail [email protected] for contant. What is odd about it is that the virus threatens to break the encrypted files on the computers it has infected if the user tries to modify them in any way, like changing their names. In addition to this, the ransomware also demands victims to pay a hefty ransom fee of 400$ in it’s “how_to_decode_files!!!.txt” ransom note to get access to the files that are encoded and no longer openable. In case your system has been infected by the .Do_not_change_the_file_name.cryp ransomware, we advise reading the following article to understand what is the situation and how to react.

UPDATE! A decrypter has been released for the Do Not Change ransomware by researcher demonslay335. Download link can be found on the highlighted text below:
Do Not Change Name Decrypter

Threat Summary

Name

.Do_not_change_the_file_name.cryp Virus

TypeRansomware
Short DescriptionThe malware encrypts users files using a strong encryption algorithm, making direct decryption possible only via a unique decryption key available to the cyber-criminals for the price of $400.
SymptomsThe user may witness ransom notes and “how_to_decode_files!!!.txt” “instructions” linking to an e-mail address where further instructions are sent. Changed file names and the file-extension .Do_not_change_the_file_name.cryp has been used.
Distribution MethodVia an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner.
Detection Tool See If Your System Has Been Affected by .Do_not_change_the_file_name.cryp Virus

Download

Malware Removal Tool

User ExperienceJoin our forum to Discuss .Do_not_change_the_file_name.cryp Virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

.Do_not_change_the_file_name.cryp – How Does It Distribute

To spread, the Robert Swat virus may utilize different techniques. One of those techniques is to spam fake messages via e-mail, that may contain different file types embedded within them as attachments. The messages may be deceptive and aim to lure potential victims into opening the attachments, similar to the example image below:

Besides this technique for spreading, the .Do_not_change_the_file_name.cryp file ransomware, may also take advantage of several other methods such as embedding malicious scripts in spammed web links all over the web and also have loaders posing as game patches, cracks and updates.

.Do_not_change_the_file_name.cryp Virus – Activity

For the activity of this infection, it uses multiple distribution sites, to which it’s loader may connect after already infecting your computer. Then, the loader may drop multiple different types of files. These very files may have the same names as processes that are completely legitimate or completely random names. They may be located in the usually targeted Windows folders, for example:

After the malicious files of this virus are dropped on the computer of the user, they may exhibit different activity on the computer of the user. One of the actions that may be performed by the .Do_not_change_the_file_name.cryp threat is to force delete the shadow volume copies of the encrypted computer. This is usually achievable by executing the vssadmin and bcedit commands in Windows Command Prompt in the background, without the user noticing it is happening:

In addition to this activity, the ransomware infection may also modify the Windows Registry Editor by adding malicious value strings in the Run or RunOnce sub-keys which run it’s malicious executables automatically:

.Do_not_change_the_file_name.cryp Files And Their Encryption

Regarding the encryption process of this ransomware infection, one or more encryption modes may be used. Among the suspected encryption algorithms may be among the following:

  • RSA(Rivest-Shamir-Adleman).
  • SHA(Secure Hash Algorithm).
  • AES(Advanced Encryption Standard).
  • ECDH(Elliptic Curve Diffie–Hellman).
  • Other less sophisticated ciphers.

In addition to those ciphers an encryption mode known as RC4 may or may not be employed. For the process, the .Do_not_change_the_file_name.cryp virus targets specific files to encode. Among those files may be the following file types:

→ “PNG .PSD .PSPIMAGE .TGA .THM .TIF .TIFF .YUV .AI .EPS .PS .SVG .INDD .PCT .PDF .XLR .XLS .XLSX .ACCDB .DB .DBF .MDB .PDB .SQL .APK .APP .BAT .CGI .COM .EXE .GADGET .JAR .PIF .WSF .DEM .GAM .NES .ROM .SAV CAD Files .DWG .DXF GIS Files .GPX .KML .KMZ .ASP .ASPX .CER .CFM .CSR .CSS .HTM .HTML .JS .JSP .PHP .RSS .XHTML. DOC .DOCX .LOG .MSG .ODT .PAGES .RTF .TEX .TXT .WPD .WPS .CSV .DAT .GED .KEY .KEYCHAIN .PPS .PPT .PPTX ..INI .PRF Encoded Files .HQX .MIM .UUE .7Z .CBR .DEB .GZ .PKG .RAR .RPM .SITX .TAR.GZ .ZIP .ZIPX .BIN .CUE .DMG .ISO .MDF .TOAST .VCD SDF .TAR .TAX2014 .TAX2015 .VCF .XML Audio Files .AIF .IFF .M3U .M4A .MID .MP3 .MPA .WAV .WMA Video Files .3G2 .3GP .ASF .AVI .FLV .M4V .MOV .MP4 .MPG .RM .SRT .SWF .VOB .WMV 3D .3DM .3DS .MAX .OBJ R.BMP .DDS .GIF .JPG ..CRX .PLUGIN .FNT .FON .OTF .TTF .CAB .CPL .CUR .DESKTHEMEPACK .DLL .DMP .DRV .ICNS .ICO .LNK .SYS .CFG”Source:fileinfo.com

The encryption process consists of replacing portons data from the original files with data from the cipher being used. After encryption, the files may appear like the following:

The encrypted files may also be encoded with a mode that is set to break them when they are modified, for example with changed filenames. The other scenario is if the cyber-criminals are just claiming this in the ransom note as a scare tactic, not to try and decrypt the encoded files. The ransom note opened after the encryption process has finished is called how_to_decode_files!!!.txt and has the following content:

*******************************************************************************
ATTENTION!!! Changing the file name makes the restore process impossible!
*******************************************************************************
Your data is encrypted.
To receive a program of decoding, You need to pay ~ $ 400 and
You need to send the personal code:
{UNIQUE PERSONAL CODE HERE}
To the email address [email protected]
Then you will receive all the necessary instructions.
Attempts to decipher independently will not lead to anything, except irretrievable
loss of information.
We respond to all emails, if there is no answer within 10 hours, duplicate your
letter other email services.
Thank you for your attention and have a good day.
*******************************************************************************
ATTENTION!!! Changing the file name makes the restore process impossible!
******************************************************************************* Source:Pastebin

Remove .Do_not_change_the_file_name.cryp Virus and Try To Recover Encrypted Files

Before removing malicious files belonging to this ransomware infection, recommendations are to focus on backing up the encrypted files first, just in case. For the removal process of this ransomware, we advise using the removal instructions in the end of this article. In case you are having difficulties in manually removing files encrypted by this virus, experts advise using an advanced anti-malware program which will take care of the removal process for you automatically and ensure future protection as well.

After having successfully removed this ransomware infection, reccomendations are to focus on restoring files encrypted by it using multiple alternative methods, like the ones we have suggested below in step “2. Restore files encrypted by .Do_not_change_the_file_name.cryp Virus”. These methods are not 100 percent guaranteed to work but they may be of use for restoring at least some of the encoded files.

Manually delete .Do_not_change_the_file_name.cryp Virus from your computer

Note! Substantial notification about the .Do_not_change_the_file_name.cryp Virus threat: Manual removal of .Do_not_change_the_file_name.cryp Virus requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove .Do_not_change_the_file_name.cryp Virus files and objects
2.Find malicious files created by .Do_not_change_the_file_name.cryp Virus on your PC

Automatically remove .Do_not_change_the_file_name.cryp Virus by downloading an advanced anti-malware program

1. Remove .Do_not_change_the_file_name.cryp Virus with SpyHunter Anti-Malware Tool and back up your data
2. Restore files encrypted by .Do_not_change_the_file_name.cryp Virus
Optional: Using Alternative Anti-Malware Tools

Vencislav Krustev

A network administrator and malware researcher at SensorsTechForum with passion for discovery of new shifts and innovations in cyber security. Strong believer in basic education of every user towards online safety.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.