Fabian Wosar

Emsisoft Employee
  • Content Count

    4403
  • Joined

  • Days Won

    1

Everything posted by Fabian Wosar

  1. Wurde entfernt. Ist im Grunde ueberfluessig, da es einfach nur ein RSS Import des Change Blogs war. Fuer die meisten User sind die umfangreicheren Announcements der Erneuerungen interessanter, die jetzt unter Emsisoft News importiert werden.
  2. Can you please upload the ransom note and one encrypted file to https://id-ransomware.malwarehunterteam.com and post the result link here? Thanks.
  3. There is, unfortunately, no known way to decrypt files encrypted by GlobeImposter2 that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups.
  4. Can you please upload the ransom note and one encrypted file to https://id-ransomware.malwarehunterteam.com and post the result link here? Thanks.
  5. Your files seem to be encrypted by GlobeImposter2. There is, unfortunately, no known way to decrypt files encrypted by GlobeImposter2 that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups.
  6. Please try the latest version of the decrypter.
  7. Can you please upload the ransom note and one encrypted file to https://id-ransomware.malwarehunterteam.com and post the result link here? Thanks.
  8. There is, unfortunately, no known way to decrypt files encrypted by GlobeImposter2 that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups.
  9. In general, try to pick a file to attack that is as high up in the list as possible. Every five items further down the list will double the decryption time.
  10. Guess your only options at this point are to recover from your latest backups, accept the data loss and try to move on or to pay.
  11. Can you please submit the ransom note and one encrypted file to ID Ransomware and post the result link here? Thanks.
  12. That looks like Cryakl. There is, unfortunately, no known way to decrypt files encrypted by Cryakl that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups.
  13. This appears to be a variation of Cry36. There is, unfortunately, no public fix for it at the moment. Kaspersky was successful in some limited number of cases, so you may want to try and contact them.
  14. Well, except for him being a criminal I guess. There was a new minor variant of Amnesia2 which is now also supported by our decrypter.
  15. There is unfortunately no known way to decrypt files encrypted by GlobeImposter 2 that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups.
  16. There is unfortunately no known way to decrypt files encrypted by GlobeImposter 2 that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups.
  17. As mentioned before in various places: We classified Cry36 as not feasible to decrypt using the restrictions we try to operate within. Kaspersky was able to "liberate" some of the private keys, so you can try to contact them. But it is highly unlikely that there will be a new decrypter for Cry36 from us.
  18. We suggest never to pay for it. Those are criminals after all. You shouldn't trust them.
  19. Due to a problem with a forum software upgrade, we had to rollback to an earlier backup of the forum software and database. Due to this rollback, all posts made after 04:00 AM CET on July 26th, 2017 are lost. We apologise for the inconvenience and are currently looking together with the forum software vendor into the reasons why the upgrade failed in hope to avoid similar issues in the future.
  20. Andere Philosophie. Andere Produkte packen in Quarantaene und fragen im Nachhinein ob das okay war. Wir fragen halt bevor wir irgendwas machen. Wenn Du lieber nicht gefragt werden moechtest, kannst Du jederzeit den Standard im Behaviour Blocker aendern um dichter an der Verhaltensweise anderer Produkte zu sein.
  21. Can you get me an unencrypted file (can be empty) of the same format or can you tell me which application created it so I can look up format specifications to see if I can teach the decrypter to recognise said format?