  2. Dear Support, What do you think about adding this option to the Behaviour Blocker? Auto resolve, notifications for threats only for USER DECISION. (Not will be quarantined in 10s) I think this option helps to reduce false and improve user experience.
  4. Okay this is getting worse,, apparently my fathers laptop was infected by the StopDjvu, and all the files were locked with a .PEZI extension , BUT here is the think, the ransomware jumped into my computer through the INTERNET!!! I swear i am so lucky , i mean i was literally sitting in front of my computer seeing the process start and do the enryption, i was viewing photos on my disk E and it started the encyrption process from disk E! in front of my eyes as i watched seeing my files get locked , the only possible and smart thing to stop the process i could think of was to removing the LAN connection(internet) to my pc, THANKFULLY the encryption stopped after encrypting all the 16 useless files , those files were of no use . So yeah i got a little too lucky there.So what should i do now? i switched the mode to safe mode and i aint going back to regular windows until and unless i create a backup!
  5. This is a newer variant of STOP/Djvu, and your ID is an online ID, so there is currently no way to decrypt your files. There is more information at the following link:
  6. Hello! I agree that reinstalling is unlikely to help😔 Apparently, I have to wait ... Thanks for the desire to help! The only question is: does EAM really protect my system now? despite these problems? can i wait calmly?
  7. No key for New Variant online ID: 1CoHryxZeK8s4RJ1QhBXkC9I8KxujFFaRX6aslQ1 Notice: this ID appears to be an online ID, decryption is impossible please help me, I get virus .nlah I tried using it but it didn't work
  8. It's theoretically possible that law enforcement of some sort may gain access to the servers run by the criminals, however there's no way to know for sure if or when this may happen.
  10. Did you upload file pairs for every type of file you want to decrypt? Is the decrypter now able to decrypt anything it wasn't able to before?
  11. I'd say turning it either on or off is optional, however Microsoft does seem to think that computers would be more secure with this option turned on.
  12. I would believe that @Frank H sent you a private message to ask you to try something. Don't worry about filling me in on how it's going, as Frank should do that himself.
  13. I mean everyone's cloud scanning is not effective against certain types of threats. There are technical limitations to cloud scanning technology that make it ineffective against certain types of threats. Databases are compressed, encrypted, and are occasionally cleaned and consolidated to reduce the size without reducing effectiveness. The performance reduction of Anti-Virus software usually has more to do with the fact they they inject code into all running processes on the system to open hooks to read their memory and monitor their behavior. You'd have the same performance issues with or without local behavioral monitoring, because you're talking about an operation that only takes a few milliseconds and which is only triggered when a process is unknown.
  14. For now keep the notification that's causing the crash disabled, and our developers will see what they can do about the crash report you submitted. Crash reports are only accessible to developers, and possibly QA. They don't tell me when they receive them, and the only way to verify if they received yours would be to check by e-mail. If you entered the same e-mail address in the submission dialog that you used on the forums, then I can ask them if you would like. Reinstalling EAM most likely won't help. Of course you can try it if you like, and you should download via MyEmsisoft if you have an account (click on Personal Licenses in the upper-left, and then click the Install protection button on the right). If you don't, then download either the "Web installer" or the "64 bit MSI installer".
  15. Thanks. I've forwarded those to QA as well. I recommend deleting all debug logs now. We won't be needing the old logs anymore, so there's no reason to keep them.
  16. If the seat on your license key has not been used, then you can use it on any Windows computer you want, as long as it has Windows 7 Service Pack 1 or newer installed on it (with the latest Windows Updates installed). Just keep in mind that a single license seat can only be used on one computer at a time. This is a newer variant of STOP/Djvu. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link: He can't actually know that, since you haven't posted your ID here and also haven't posted the output from our STOP/Djvu decrypter.
  17. Please note that we prefer only authorized helpers to make recommendations.
  18. For a lot of us we just hate to see the bad guys win and we want not only to try to thwart their efforts as much as possible, but also to try to help those who have lost important files to these criminals. Granted this does cost us money, however the efforts do pay for themselves as more people hear about us and our fight against ransomware, and many of those people see our Anti-Virus software as a result and decide to try it out.
  19. They often release private keys publicly, and they also work with security companies who are making decrypters to supply private keys when they can.
  20. No key for New Variant online ID: 1CoHryxZeK8s4RJ1QhBXkC9I8KxujFFaRX6aslQ1 Notice: this ID appears to be an online ID, decryption is impossible please help me, I get virus .nlah
  21. How you know that? where is info on that??? I managed to install it by pressing F8 and select an option about sign drivers, don't remember the whole thing... now is scanning the drive!
  22. seriously just why? all this support for free, you guys are the nicest people . we don't deserve your support!, hats off to everyone at EMSISOFT and BleepingComputer .
  23. Are there any obvious file extensions appended to your encrypted data files? If so, what is the extension and is it the same for each encrypted file or is it different? Is there an ID number with random hexadecimal characters (.id-A04EBFC2, .id[4D21EF37-2214]) or an ID number with an email address (.id-BCBEF350.[<email>], .id[7A9B748C-1104].[<email>]) preceding the extension? Did you find any ransom notes? If so, what is the actual name of the ransom note? Can you provide (copy & paste) the ransom note contents in your next reply? You can also submit (upload) samples of encrypted files, ransom notes and any contact email addresses or hyperlinks provided by the malware developer to ID Ransomware (IDR) for assistance with identification and confirmation of the infection.
  24. Meet Stop Ransomware: The Most Active Ransomware Nobody Talks About Ransomware statistics for 2019: Q2 to Q3 report: Most commonly reported ransomware strains
  26. ok ok , so login in safe mode , and delete all the viruses.(it will work for sure) , once you do that , create a backup of all your encrypted software and store it safely, because you are infected by an online key , and the decryptor of online key is not possible until and unless the police or the FBI does not find the hackers and release their database of private keys!
