Ifx2g-how-to-decrypt.txt - Ransomware Identification

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fluffmeister, May 29, 2019.

  1. Fluffmeister

    Fluffmeister Private E-2

    Hi All

    Anyone know a tool to help un-encrypt files locked with extension ifx2g ?
    ANd file in directory "ifx2g-HOW-TO-DECRYPT.txt"

    Regards
    Fluff
     
  2. Replicator

    Replicator MajorGeek

    Unfortunately you would be very lucky to find one!

    As with most modern Ransomware, its my guess that the encryption process generates an RSA-1024 pair per run and encrypts the private key with a hard-coded RSA-2048 public key.
    Without the master private RSA key that can be used to decrypt your files, decryption is impossible.

    My advice would be to submit (upload) samples of encrypted files, ransom notes and any contact email addresses or hyperlinks provided by the cyber-criminals to ID Ransomware for assistance with Identification and confirmation of the infection.

    Your best bet old mate would be to restore from a backup or restore point (if you have one), try some file recovery software, or backup and save the encrypted data, then wait for a possible solution at a later time.

    I would ignore all Google searches which provide links to bogus and untrustworthy removal/decryption guides.
    They just want your money for doing squat.

    This is why all the Majorgeeks here continue to advise every member to make backups of their data and store it on an external drive, offline.
    Many take no notice until its too late.......

    Sorry dude, but you've been fluffed :(
     
    Eldon likes this.
  3. Eldon

    Eldon Major Geek Extraordinaire

    We need to know the name of the ransomware using that extension.
    My searches have turned up nothing so far.
    Witty. :D
     
  4. Fluffmeister

    Fluffmeister Private E-2

    Thanks for reply. I've submitted examples to ID Ransomware, see if anything comes of it. Looks like it got in through an old server i setup for testing dev ops solutions, Jenkins/Jira web server had flaw i think.

    No real loss, except one drive had some Family photos on its a shame to lose. Nothing of any physical value.

    Ive def been F.......d
     
  5. Replicator

    Replicator MajorGeek

    Hold tight....there is still hope!
    Keep your encrypted files on a USB stick if you decide to format, and let us know here what comes back from ID Ransomware. ;)
     
  6. Imandy Mann

    Imandy Mann MajorGeekolicious

    Several security and maleware related sites are always coming up with de-crypts for various crypto schemes. If data is important a new drive and media creation tool could allow to save the infected disk until a de-crypt becomes available.
     
  7. Replicator

    Replicator MajorGeek

    Not many know about the range of McAfee Free Tools (Anti-Malware & Encryption) for security industry researchers!

    In particular Mr2, which may or may not be pertinent for the OP.

    Securing Tomorrow may also be helpful reading.

    ;)
     
    Last edited: May 30, 2019
  8. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    I can't stress enough: spend time learning how to create images outside of Windows.

    If you get hit with anything, restore the latest image and you'll only lose a few files since the image was created. Of course if you regularly also save copies off the computer, you won't lose anything. You'd be up and running usually in under an hour.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds