Ransomware attack

Status
Not open for further replies.
Hello Ugyen,

I am Karsten and will gladly help you with any malware-related problems.

Please familiarize yourself with the following ground rules before you start.
  • Read my instructions thoroughly, carry out each step in the given order.
  • Do not make any changes to your system, or run any tools other than those I provided. Do not delete, fix, uninstall, or install anything unless I tell you to.
  • If you are unsure about anything or if you encounter any problems, please stop and inform me about it.
  • Stick with me until I tell you that your computer is clean. Absence of symptoms does not mean that your computer is free of malware.
  • Back up important files before we start.
  • Note: On weekends I might be slow to reply
-------------------------------------------------------------------

The file extension .erif has been used by STOP/DJVU ransomware. STOP/DJVU ransomware variants after August 2019 are only decryptable if an offline key was used. For variants with an online key you cannot decrypt but repair certain file types.

Please upload an encrypted file and a ransom note to id-ransomware to confirm that it is indeed STOP/DVJU ransomware. Tell me the result.

Regarding your DM. Please talk to your cousin. Maybe they have a backup of the files. I know you are probably afraid to tell anyone that this happened, but you have to own up to it.
 
Thank you so much for your wonderful response.
1596479904717.png
Sir ,The image above is the result show in the id- ransomware sir
 
Sir, I already tried using emsisoft decryptor tool but it didn't work showing that the data is encrypted with online key.
What should I do now sir
 
Please ask if there is any backup of the data on the system. Currently there is no way to get it back the way it was before.

Your options without a backup:

1) Recovery: In rare cases ransomware fails to delete shadow volume copies or fails to delete the original files properly. You can try to recover files via shadow volume copies and file recovery software.
2) Repair: Certain file types, mainly video and audio files, can possibly be repaired with tools like MediaRepair. But these files will loose some data.
3) Wait: Backup encrypted files and a ransom note and wait in case a solution comes up later. Maybe law enforcement gets hands on the keys or the criminals publish the keys as it happened with, e.g., GandCrab. I suggest reading the news on this. Emsisoft will update their decrypter if that happens.
4) Pay: There is the option of paying the criminals, but we highly recommend against this step. You will just fund later attacks. You may also pay without getting your files back. These are criminals and as such not trustworthy.

Let me know if you want my assistance in any of these options (except for paying the ransom).
 
Thank you sir your guidance and i shall be glad if sir could assist me to carry out recovery via shadow volume
 
  • Like
Reactions: upnorth
  • Please download Shadow Explorer
  • Right-click on the Shadow Explorer archive, click Extract all.. and confirm to extract the files
  • In the extracted folder, double-click on ShadowExplorerPortable.exe to run the program
  • Now you can see previous versions of the files on the system. Make sure the correct drive letter is selected (usually "C:" )
  • There is a date on the upper bar. Check if there is a date available that was before the ransomware attack. If the date isn't available, you don't have any shadow volume copies from before and recovery is not possible.
  • Within Shadow Explorer, navigate to files or folders you want to recover
  • To recover: Right-click and click Export... then choose a folder to save the files to and click OK
Let me know if this works.
 
  • Like
Reactions: oldschool
Hello Sir, I tried with shadow recovery but it show the date I lost my files. Is there any way that we can repair .pdf files?
 
Hello Sir, I tried with shadow recovery but it show the date I lost my files. Is there any way that we can repair .pdf files?

I am sorry to hear that.
Unfortunately don't know of any way to repair PDF files encrypted by STOP. I suggest making a backup in case something changes in the future.

Do you have any other questions?
 
Closing this as it seems we are done here. If you want to be re-opened, DM me, please.
 
  • Like
Reactions: upnorth
Status
Not open for further replies.