EKING Ransomware
Decryption & Recovery Service
All our recoveries are guaranteed, no data no charge!
>> Get a FREE Assessment in 1-4 hours>> Get a FREE Assessment
Infected with EKING Ransomware?
Don’t Panic, we guarantee to have your data recovered within 24-48 hours.
Get quick 24/7 help NOW!
If you are reading this page, it’s likely you have been infected with EKING ransomware variant.
Fast Data Recovery has the tools, knowledge and resources to help recover your data within 24-48 hours and help to secure your network.
EKING Ransomware is part of of the PHOBOS ransomware family. PHOBOS ransomware is one of the top 3 ransomware infections circulating on the internet and on average we solve between 20-30 cases per week.
We have been successful in helping thousands of clients recover data from EKING ransomware variants.
- 1No Data No Charge. We guarantee your data recovery.
- 2Worldwide support with 24/7 customer service & recovery.
- 3All our recoveries are undertaken remotely and completed within 24-48 hours.
Fill out the form below and a ransomware specialist will assist with your enquiry.
This form is monitored 24/7
No Data No Charge
Submit a ticket for a FREE assessment or request a call back.
Our engineers are available to assist and recover your data 24 hours / 7 days a week.
>> Watch how we recover from EKING Ransomware <<>> Watch how we recover from EKING Ransomware <<
EKING Recovery Guarantee
We have the tools, knowledge and resources to guarantee the recovery of your data.
Fast Data Recovery
We are available 24/7 for instant response. All recovery processes will begin immediately.
Remote Recovery Service
All recoveries are undertaken remotely on the original infected system or on another computer. No need to send us your data.
Ransomware Experts
Fast Data Recovery is an established and trusted global IT service provider. Our focus is to help clients recover from ransomware and provide cybersecurity to combat any future ransomware attacks.
Expedited Service
Get your data faster. Our data recovery experts will provide a recovery quote after assessing the complexity of your EKING infection within 1-4 hours. If you choose to engage our service we guarantee decryption of your files within 24-48 hours*
Personalized Service
A dedicated member of our team will guide you through every step of recovering your data, provide insight on the attack and help to secure your system.
Frequently Asked Questions
EKING / PHOBOS ransomware is an encryption ransomware Trojan that was first observed on October 21, 2017 (a new variant of Dharma ransomware).
It is a malicious program that is classified as ransomware (aka. malware). Cybercriminals encrypt your files, blocking you from accessing them. They then demand you pay a ransom to access a decryption tool to recover your files. Once the ransom is paid, the cybercriminals rarely send the decryption tool. In most cases, the perpetrator’s email will be blocked or further ransomware demands are made.
PHOBOS ransomware creates a text file called “YOUR FILES ARE ENCRYPTED.txt”, “Files Encrypted.txt” “info.txt” and displays a ransom note in a pop-up window.
This ransomware also renames all encrypted files by adding the “.PHOBOS” extension (together with the victim’s ID and the email address of the .PHOBOS hacker). For example, if a file is named “1.jpg“, then .EKING will rename it to “1.jpg.id-1E857D00-1234.[hacker@email.com].EKKING” and so on.
Each ID will be a unique infection. Please advise us when submitting your quote if you have multiple IDs.
Our team has successfully helped thousands of EKING ransomware clients. We guarantee recovery from ALL EKING ransomware variants and we back our claim with a No Data = No Charge policy.
Submit an online case or talk to our ransomware specialist to assist with EKING Ransomware recovery
RANSOMWARE RECOVERY PROCEDURES
Fast Data Recovery is the market leader in ransomware recovery & cybersecurity services with 24/7 ransomware recovery team.
Our company headquarters is located in Sydney, Australia with a team of 12 engineers working across Australia, the US, the UK & the Philippines.
We have the resources, knowledge, and experience to help you remove and recover from eking ransomware and prevent further attacks.
We understand the value of data and work extremely hard to recover your business data as fast as possible.
- Fast Ransomware data recovery turn around*
- 100% Guaranteed Recovery from eking ransomware.
- No data = No charge policy for peace of mind.
Please visit How it works? for more information about the process of analysing your ransomware variant and provide a quote for recovery.
CONTACT US
Fast Data Recovery supports clients worldwide.
We are available 24/7 for all your enquiries.
You can contact us via email, our online chat, or if you prefer to talk to a ransomware recovery engineer, feel free to call us on one of the numbers below:
SUBMIT AN ONLINE CASE OR TALK TO ONE OF OUR RANSOMWARE SPECIALISTS TO ASSIST WITH YOUR RANSOMWARE RECOVERY:Get A Quote NowGet A Quote Now
- 100% Guaranteed Recovery from most types of ransomware
- Technicians are available 24/7 to start your recovery immediately
- Priority Data Recovery Service (48 hours recovery time in 90% of cases)
- Australian based with 24/7 Worldwide support
- Free Evaluation or 4-24 hours Priority Evaluation for more urgent cases (most evaluation are completed in 4-8 hours)
- No Obligation Fixed Quotes
- No Data No Charge
- All recoveries are done remotely (no need to send us your data!)
- Ransomware Specialists
- Advanced Ransomware Prevention and Security Audit to eliminate the risk of ransomware
- Established company with over 10 years of data recovery experience
- 1000+s of happy clients
- All International clients are welcome
COMPANY DETAILS
Fast Data Recovery is a registered company based in Sydney, Australia. It is part of the PC Link Professionals Pty Ltd group, which specialises in IT Support, Security and Data Recovery (established in 2008). Due to the exponential growth of demand for ransomware recovery, Fast Data Recovery was established by the PC Link Professionals group in December 2018.
Please visit the Australian Business Register for more information about the establishment of our business:
PC Link Professionals Pty Ltd – https://abr.business.gov.au/ABN/View?abn=20132031826
Fast Data Recovery Pty Ltd – https://abr.business.gov.au/ABN/View?abn=78630597778
CUSTOMER TESTIMONIALS and REVIEWS
We pride ourselves on the quality of work we provide. Customer service is our number one priority and we strive to exceed your expectations. Please read for yourself what other customers are saying about our services:
Google Reviews: https://goo.gl/S7KM9Y
Independent Reviews: https://trustspot.io/store/Fast-Data-Recovery
Clients Written Testimonials: https://fastdatarecovery.com.au/clients-written-testimonials/
We do not recommend paying hackers. It’s a small chance of getting your files back.
Hackers in some instances may release personal information about your company to the public if you contact them and do not meet their ransom demands. Its strongly recommended not to communicate with them. (using an alternate email does not keep your identity safe as each infection has a unique code to identify you)
Scenarios from customer’s feedback who paid the ransom without engaging a ransomware recovery company to recover without paying the ransom or at least negotiate in case we are unable to recover in a timely manner.
1. The hackers may ask you for extra money after you make the first payment (The trend)
2. The hacker’s email usually gets closed down by the email provider (Once the email is reported to the domain webmaster their email will be shut down. Usually thousands of victims are infected at the same time so the likely-hood of this happening is very high)
3. They send you a sample file, take your money and simply stop responding
4. They may recover all/some of your files
In the event where we are unable to recover from your type of ransomware or able to recover in a timely manner, we can use our resources and experience to obtain the decryption at still offer a No Data No Charge for peace of mind
For a risk-free recovery, Submit an online case or talk to our ransomware specialist to assist with PHOBOS Ransomware recovery
At Fast Data Recovery, we serve the needs of both individuals and businesses who wish to have their data recovered after a ransomware attack. We are equipped with the reoucres, experience and knowlodge to perform complete ransomware data recovery.
We also provide ransomware removal and ransomware prevention measures to protect you from future attacks.
RANSOMWARE PREVENTION & SECURITY AUDIT?
Fast Data Recovery offers a comprehensive Ransomware Prevention and Protection service against Ransomware attacks.
If the worst happens and you become infected with a RANSOMWARE, we advise that you disconnect the infected system from the network (we do not advice to shut down your system as this may corrupt your data or system files further and prevent a quick repair).
DO NOT TRY TO REMOVE THE RANSOMWARE. By running Antivirus or Malware removal software you may cause further damage and make the encryption irreversible.
Ransomware removal and the recovery of your valuable data should always be left to an experienced ransomware recovery expert.
Fast Data Recovery has the knowledge, resources and expertise to recover your data and completely remove all known forms of ransomware and malware. In most cases, we manage to recover 100% of our customer’s encrypted data.
Our data recovery process is quick, simple and entirely focused on restoring your valuable data and getting your business back on track as quickly as possible.
Fast Data Recovery offers a comprehensive Ransomware Prevention and Security Audit to secure your network from further attacks
- Find the source of the attack to better protect your network
- Find & Destroy the ransomware on your server
- Find and destroy ransomware time-bomb, backdoor, key-logger trojans implemented by the perpetrators
- Full protection against all current know types of ransomware attacks.
- Protect your server from other common attacks used by hackers
- Check Registry for changes made by hackers
- Deep level scan from common hackers practices.
- Complete network and security audit to minimise risk – A full list of any recommendation will be sent in a detailed report to further prevent future attacks from other computers/devices on your network
- Best practices and solutions for protecting businesses from ransomware downtime
- Check your current backups and advise on best backup practices
- Check if your antivirus has adequate ransomware protection. Most antivirus’ fall short in protecting against Ransomware.
- Group Policy and Passwords audit and recommendations
- General IT recommendations if we feel it will improve your overall system/processes.
- (Optional but highly recommended) Full scan and prevention on your computers/laptops
It is no longer a matter of if, but rather when your organisation will become the target of a data breach. As the threat landscape continues to expand, more doors have opened for threat actors to explore and attack putting businesses at risk of unauthorised access and loss of critical data.
The Phobos ransomware family is fairly common ransomware and has been spotted in early 2019.
Phobos and its all its variant are a part of the Dharma/Crysis ransomware.
It has continued to push out new variants and evolve attack methods, but also frequently change the extension name of encrypted files in past variants.
Phobos victims have often complained that they were cheated by the attacker of Phobos by not restoring files.
What does Phobos ransomware does to a network?
- Entry Point
Phobos has 24 known entry points and if you are reading this, you most likely a victim of phobos ransomware - Execution
Once the payloader has been executed a second (two step) process is executed
The first group of commands are listed below with my added comments:vssadmin delete shadows /all /quiet – Deletes all of the volume’s shadow copies.
wmic shadowcopy delete – Deletes shadow copies from local computer.
bcdedit /set {default} bootstatuspolicy ignoreallfailures
bcdedit /set {default} recoveryenabled no – Disables the automatic startup repair feature.
wbadmin delete catalog –quiet – Deletes the backup catalog.
exitBy deleting the shadow copies that the Windows system makes for system restore, the victim is not able to use it to restore the encrypted files. It also prevents the victim from restoring files from an automatic startup repair or from a backup catalog.The commands of the second group turn off the Windows Firewall on the infected system, as shown below.netsh advfirewall set currentprofile state off – For Windows 7 and later versions.
netsh firewall set opmode mode=disable – For Windows XP, Windows 2003 versions.
exit3. Adding Auto run items
The malware decrypts the string “Software\Microsoft\Windows\CurrentVersion\Run” (index number is 0x11), which is the registry subkey path, from the encrypted configuration block. It then creates an auto-run item to the same subkey of both root keys, HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER. The screenshot of the added auto-run item under the root key “HKEY_CURRENT_USER”.
Other than adding this item into the auto-run group in the system registry, it also copies “cs5.exe” into two auto startup folders: “%AppData%\Microsoft\Windows\Start Menu\Programs\Startup” and “%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup”. Figure 4.2 shows the ASM code snippet of copying “cs5.exe” into the two start-up folders.
See What our Clients Say about Us
Get Ransomware Help Now!
We offer worldwide support with 24/7 customer service & recovery.
Here are some ways to contact us.
Talk to an Expert
chat with a ransomware specialist for free to recover your data now!
Get Help Now
We are waiting to help you and your business – so don’t hesitate to reach out!