Recommended Posts

the Ransomware need decryptor.... they removed shadow volume copy, so wont be able to restore and also encrypt the original file, so no point of using data recovery tool.

Please suggest

  • Like 1

Share this post


Link to post
Share on other sites

Hello @Deepak Jha

The format of the encrypted file indicates that it is Dharma Ransomware
You can verify this yourself through the ID Ransomware service.

I recommend that you attached the files of the ransom notes to your message. These may be files RETURN FILES.txt and Info.hta

Share this post


Link to post
Share on other sites
14 hours ago, Amigo-A said:

I recommend that you attached the files of the ransom notes to your message. These may be files RETURN FILES.txt and Info.hta

>>>

Share this post


Link to post
Share on other sites

@Shaaban Ahmed

extension .nacro - this is result of STOP Ransomware attack

extension .id[C67C79A7-2275].[[email protected]]  - this is result of Phobos Ransomware attack

The last one was Phobos, after it it is impossible to decrypt files without receiving a unique key for decryption.

 

 

Share this post


Link to post
Share on other sites

@Shaaban Ahmed

Now you need to think about the security of your PC. You have received two newest crypto-ransomware on your computer. This means that the next time your files will be encrypted again, if you do not take measures to protect.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.