Malware Ransomware Grandcrab 5.2

MagicBoo

Member
Jun 3, 2019
5
Dominican Republic
OS
Windows 7
BR
Firefox 67.0
My computer recently became infected with a malware called grandcrab 5.2, it does not bother me to format my computer but I have a portable hard drive that does not want to lose the files, how can I recover my work files

PD. Sorry for my english my language is Spanish
 

Megabyte

New Member
Feb 19, 2019
1
OS
Windows 10
BR
Chrome 74.0.3729.169
You can recover your images anyway - something I found by accident after taking an 82GB hit from Gandcrab 5.2.

I had Google Backup & Sync running in the background, it identified the newly encrypted files (in my case image_name.jpg.vnveni) as images & uploaded them to Google Photos - where they appeared as images. No shit, Google's servers don't recognise Gandcrab encryption.

I was like WTF? & did intend to research this thing, but was a bit busy batting Gandcrab off from my network, recovering from backup then running extra insurance backups across my clientbase. Then I forgot about it. Until now.
 
  • Like
Reactions: ThumperTM

DVDR_Dog

Well-Known Member
Donator
Nov 5, 2018
124
OS
Windows 10
BR
Chrome 74.0.3729.169
Wow that's some great news! Go figure. I would have never guessed. I wonder what processing google does to retrieve the images? I have to admit I have yet to a system with that infection yet.
Thanks for the info Megabyte. Heard it here first.