karan11

FILES ARE ENCRYPTED BY .ADAME FILE VIRUS

Recommended Posts

MY FILES ARE RECENTLY ENCRYPTED BY .ADAME RANSOMWARE.THEY WANTED ME TO PAY MONEY AT [[email protected]].MY ALL FILES ARE ENCRYPTED BY THESE VIRUS SUCH AS AUDIOS VIDEOS DOCS ETC. I'M UPLOADING SOME OF THE FILES TO GIVE YOUS SOME IDEA. PLEASE HELP ME OUT GUYS........

AKS.Think-and-Grow-Rich-PDF.pdf.id[845807B0-2275].[[email protected]].Adame bpo q&a.txt.id[845807B0-2275].[[email protected]].Adame Napoleon Hill -Pathway to Personal Success.pdf.id[845807B0-2275].[[email protected]].Adame radhat-3.pdf.id[845807B0-2275].[[email protected]].Adame The Complete Guide To Genius.pdf.id[845807B0-2275].[[email protected]].Adame

Share this post


Link to post
Share on other sites
Quote

extension .id[845807B0-2275].[[email protected]].Adame

Hello @karan11

Looking at the format of the encrypted file, we can say that this is the result of the Phobos Ransomware attack.
But in order for our help to be more accurate and informative, ALWAYS need to attach to the message 2-3 different encrypted files and a ransom notes, that the extortionists left for you. 

This may be files info.txt, info.hta

I recommend to put them in the archive and attach to the message, in this way they will not be damaged.

  • Upvote 1

Share this post


Link to post
Share on other sites

Hi Anugio-A,

My computer is infected in the similar way to the OP's situation but maybe some variant from his/hers. Would appreciate your kindly help if you can look at it. B.T.W. I didn't find any infected txt or hta files but I assume ".ini" or ".html" files may be the easiest to decrypt if possible.

Thanks so much in advance for any help if you would like to offer!

 

desktop.ini.id[D2206A4C-2275].[[email protected]].Adame index.html.id[D2206A4C-2275].[[email protected]].Adame

  • Upvote 1

Share this post


Link to post
Share on other sites

Hello @ym888

This is also the result of the Phobos Ransomware attack.

You need to attach to the message still a ransom notes, that the extortionists left for you, so that I can catalog your case.

This may be files info.txt, info.hta

I recommend to put them in the archive and attach to the message, in this way they will not be damaged.

Share this post


Link to post
Share on other sites
19 hours ago, Amigo-A said:

Hello @karan11

Looking at the format of the encrypted file, we can say that this is the result of the Phobos Ransomware attack.
But in order for our help to be more accurate and informative, ALWAYS need to attach to the message 2-3 different encrypted files and a ransom notes, that the extortionists left for you. 

This may be files info.txt, info.hta

I recommend to put them in the archive and attach to the message, in this way they will not be damaged.

hello @Amigo-A 

Bro i tried to look for ransom note in the form of txt, hta but i'm unable to locate it. I used spyware 4 & avast software after i got attacked by ransomware,maybe during scanning it might have got deleted.To be certain i tried to locate ransom txt or message through recovery software still no luck. i would appreciate  if you forward this matter and find some solution for this problem . i'm uploading more files that are affected by ransomware.

IMG-20141231-WA0000.jpg.id[845807B0-2275].[[email protected]].Adame IMG-20160303-WA0001.jpg.id[845807B0-2275].[[email protected]].Adame IMG-20160925-WA0000.jpg.id[845807B0-2275].[[email protected]].Adame Screenshot_2016-09-20-14-19-39-992_net.wargaming.wot.blitz.png.id[845807B0-2275].[[email protected]].Adame Screenshot_2016-10-18-17-54-03-424_net.wargaming.wot.blitz.png.id[845807B0-2275].[[email protected]].Adame

Share this post


Link to post
Share on other sites

Hello Amigo-A,

my computer is infected too by this virus, my files are encrypted, but I din't find the info.txt or info.hla.

I erased my hdd and I did a backup of my encrypted files... I send you two examples...

Thanks a lot in advance for any kind of help you can offer. Can I do something?

kant.docx.id[2620CE0C-2275].[[email protected]].Adame Critica idealismo.docx.id[2620CE0C-2275].[[email protected]].Adame

Share this post


Link to post
Share on other sites

Sorry, I couldn’t answer earlier due to lack of time for answers.

Previously and at the moment there is no known way to decrypt files after an attack by Phobos Ransomware. This is checked regularly as the current version or a new version of the encryptor is released.

None of those involved in decrypting files after an attack by ransomware has not yet published a decryptor or method that allows you to decrypt files or otherwise return information from files after a Phobos attack.

If you will frantically search for new information on the Internet, then take into consideration the following info: many sites that Google gives in search results make public disinformation and offer to download fake decryption tools.

Sites that provide true information and free decryption tools:
https://www.bleepingcomputer.com/forums/f/239/ransomware-help-tech-support/
https://support.emsisoft.com/forum/83-help-my-files-are-encrypted/ 
if you want, add to them those that are in my signature. :)

These sites (forums) help victims for free. No fee is required if they can help. Experts from different countries and different nationalities gather here. If decryption becomes possible, then they and we will report on successful decryption methods in the news and on forum publications.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.