Encryption virus data recovery / R-Studio

MrBojangles

Member
Reaction score
5
I have a client that got hit with an encryption virus and got all their files are locked up. They sent me the computer to see what I can do to recover. They also sent me an external drive that also got locked up.

So I start by imaging the external drive because it's quite old and failing and I manage to extract about 99% of the data with ddrescue.

But I start the data recovery process with the laptop drive which I DONT image because I know that its pretty new and in good shape (checked health) so I figured imaging is a waste of time. Also it's an SSD of about 240gb. When I use R-Studio to scan the SSD drive I can see the files and here's an example below.

j64uLF0.png


It seems in this case that the virus copied the original file, then deleted it and encrypted the copy. However, when I recover the deleted file I cant open it because its damaged. Also if I try to find a previous version of either file it just lists about 17 unrelated files.

Anyone know if there is anything that can be done here or did the virus totally ruin the original files and make data recovery impossible?
 
The process of copying and encrypting and then deleting the old one will write over old and new space. The best option I can think of is recover by file types and maybe you might get more. But they will not be named correctly.
 
Yup...I'm with Mark. You will need to do a full scan with R-Studio and will have to hope that what they are looking for can be found in the Extra Found Files.
 
Thanks guys. Yes the files in "extra found" seems to be recoverable as opposed to the files found in the proper file paths.
 
Back
Top