Smok3d Posted June 3, 2017 Report Share Posted June 3, 2017 (edited) Hi, I am trying to figure out what encryption this ransomware is using...... ID Ransomware says it is a dharma variant I cannot get either decryter to work. Thought it may be an Amnesia variant but that does not work either. Has the 830s7 extension. Ransom note: See what you can find out about this virus ... * ALL YOUR WORK AND PERSONAL FILES HAVE BEEN ENCRYPTED * To decrypt your files you need to buy the special software – «Nemesis decryptor» You can find out the details / buy decryptor + key / ask questions by email: [email protected] Any help would be much appreciated. EDIT: I am told it is CryptON variant but the decrypter gives error with file pair. Cheers Edited June 4, 2017 by Smok3d update Link to comment Share on other sites More sharing options...
Cesar1986 Posted June 5, 2017 Report Share Posted June 5, 2017 hi I have the same problem. Any idea to decrypt this files Link to comment Share on other sites More sharing options...
Smok3d Posted June 5, 2017 Author Report Share Posted June 5, 2017 @Cesar1986 Not as of yet. I am told this is a variant of the Crypton ransomware, some are referring to it as cry36 for the 36 byte file size difference. Still awaiting news on decryption tool. Link to comment Share on other sites More sharing options...
Fabian Wosar Posted June 5, 2017 Report Share Posted June 5, 2017 Same as here: Closed to keep things in one place. Link to comment Share on other sites More sharing options...
Recommended Posts