mahmo

infected by Ransomware called (.guvara)

Recommended Posts

i need a help please
some one help me 

my all files infected with (.guvara)
.
The ransom note is ...

The

ATTENTION!

Don't worry my friend, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-xuSAEnnA8P
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail:
[email protected]

Reserve e-mail address to contact us:
[email protected]

Your personal ID:
065btydsljfhsFf81PxYfUZxMhnQiibgFdsZ1rQ5zmaZdp0I9Ufbm9w

 

 

Share this post


Link to post
Share on other sites

This is a new version of STOP-Djvu Ransomware

You need to leave the application to the developer STOPDecryptor at the link on the forum BleepingComputer
Only there are collected all the requests and cases where the decrypting failed. 
You need to carefully read the first post of the topic to find out what you need to provide. 

If you do not want to read there, provide the following information:

1) the extension on your encrypted files;
2) MAC (physical) address of the network card that was used to access the Internet at the time of the attack (others are not needed!!!);
3) personal ID from a ransom note or attach a this text file to your message;
4)  ID, which unsupported from the STOPDecrypter, only if you have already tried to decrypt and your extension is supported by STOPDecrypter.

But at the moment STOPDecrypter your extension does not support. 

Therefore, your message should be left there as soon as possible.

Share this post


Link to post
Share on other sites

If you do not know how to find the MAC (physical) address, then look at the screenshot there. Write only the address of the network card you used to access the Internet at the time you received the infection (wired or wireless (W-Fi)). 

Do not write both addresses! Determine exactly. This is not difficult.
It is necessary for you more, than for the developer of STOPDecrypter.
Such common errors lead to the fact that files cannot be decrypted.

Share this post


Link to post
Share on other sites
On 4/14/2019 at 2:11 PM, Amigo-A said:

If you do not know how to find the MAC (physical) address, then look at the screenshot there. Write only the address of the network card you used to access the Internet at the time you received the infection (wired or wireless (W-Fi)). 

STOPDecrypter will show them their MAC in its output, along with their ID. All they need to do is run STOPDecrypter, and then when it can't decrypt their files they can copy and paste the message at the bottom of the window into a forum post.

Share this post


Link to post
Share on other sites
котировка

STOPDecrypter покажет им их MAC в своем выводе вместе с их идентификатором.

 

Да, но только если ЭТОТ компьютер использовался во время атаки и заражения, а ЭТО сетевое устройство (встроенная сетевая карта, вторая сетевая карта, USB-LAN-устройство, Wi-Fi, USB flash-модем, и т.д.) в этот момент был использован. Каждое сетевое устройство имеет свой собственный MAC-адрес, и если вы отправите другой, который программа покажет на другом сетевом устройстве или другом ПК, расшифровка не будет выполнена правильно.

Demonslay335 пишет

котировка

Пожалуйста, следуйте инструкциям и укажите MAC-адрес зараженной машины, чтобы я мог заархивировать ваше дело ...

from FAQ

Quote

Q7: Here's my MAC address... of a different computer I am looking at the files from.
A: This is useless to me. I need to catalog the MAC address of the infected PC.

 

Share this post


Link to post
Share on other sites
11 hours ago, Amigo-A said:

Да, но только если ЭТОТ компьютер использовался во время атаки и заражения, а ЭТО сетевое устройство (встроенная сетевая карта, вторая сетевая карта, USB-LAN-устройство, Wi-Fi, USB flash-модем, и т.д.) в этот момент был использован. Каждое сетевое устройство имеет свой собственный MAC-адрес, и если вы отправите другой, который программа покажет на другом сетевом устройстве или другом ПК, расшифровка не будет выполнена правильно.

STOPDecrypter lists the MAC of every network adapter. Since the average user doesn't know how to find the MAC address of their network adapters, let alone what a MAC address even is, it's best for them to run STOPDecrypter.

As for the possibility of running it on the wrong computer, I have added a couple of lines to the instructions I wrote covering that and pointing to the FAQ.

 

Перевод предоставлен Google.
STOPDecrypter перечисляет MAC-адрес каждого сетевого адаптера. Поскольку рядовой пользователь не знает, как найти MAC-адрес своих сетевых адаптеров, не говоря уже о том, что такое MAC-адрес, для них лучше всего запустить STOPDecrypter.

Что касается возможности запуска его на неправильном компьютере, я добавил пару строк в написанные мной инструкции, охватывающие это и указывающие на FAQ.

  • Upvote 1

Share this post


Link to post
Share on other sites

OK. You have done a great and useful work.
Now, users should not be mistaken in this matter.

---

Google translator used several wrong phrases, but in general, the meaning should be clear.

Улыбнуло: "рядовой пользователь".  😃 

Share this post


Link to post
Share on other sites
10 hours ago, Amigo-A said:

Google translator used several wrong phrases, but in general, the meaning should be clear.

Yeah, that sounds about par for the course (assuming that means the same in Russian that it would in English). ;)

Share this post


Link to post
Share on other sites

Yes. Therefore, I trust to Google the auto-translation of the text at my sites into English, because he knows more words and rules in English than I do. But I know more words, phrases, lexical rules, dialects and I have more vocabulary in Russian. 

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.