Recommended Posts

It may be Dharma. I recommend uploading a copy of the ransom note along with an encrypted file to ID Ransomware so that you can verify which ransomware you are dealing with:
https://id-ransomware.malwarehunterteam.com/

You can paste a link to the results into a reply if you would like for me to review them.

Share this post


Link to post
Share on other sites

Blue22

Before you decrypt the files, you need to make sure that there is neither this infection nor any other infection on the PC. We have seen cases when those who suffered from previous versions successfully decrypted files, but then they were attacked by the same encryptor, which encrypted files with a different extension, and used an encryption key that cannot be calculated. In punishment for haste and complacency, the user lost his files a second time and, possibly, forever.

As experience shows, very often after encryption on a PC, this or another infection remains, which you could get together with the encryptor.
Malicious programs often work in groups: trojans of a different type, password hijackers, backdoors, dormant malware, dangerous browser plugins.
Therefore, I advise you to check your PC for active and dormant malware. This can be done here in the forum in the next section.

You can also download the free tool Emsisoft Emergency Kit yourself and check the computer.

Share this post


Link to post
Share on other sites

You better need pay them and you get back all your files(I paying them 6000 USD and get key very quickly),If you try with another soft decrypted you most likely never get result.and after month or two if you ready to pay the kackers can ask price three times more expensive now :(

Share this post


Link to post
Share on other sites
12 hours ago, dovebird said:

You better need pay them and you get back all your files(I paying them 6000 USD and get key very quickly),If you try with another soft decrypted you most likely never get result.and after month or two if you ready to pay the kackers can ask price three times more expensive now :(

There is no free decrypter for this variant of Dharma. Anything claiming to decrypt files encrypted by Dharma for free is either intended for another variant, or is a fraud.

Also note that if you feel you absolutely have to pay the ransom, it's best not to contact the criminals yourself. Find someone experienced in negotiating with criminals like this to assist you (Coveware for instance).

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.