Recommended Posts

my pc was infected by derp virus

the id on _readme.txt is 0176Asd374y5iuhldGIgYYpdpFOd8zWMHfi9ziGIE9Lh0LJttGTeACwqQ

and on personalid.txt is GIgYYpdpFOd8zWMHfi9ziGIE9Lh0LJttGTeACwqQ
KzZDbsL5uUAqMCZQH1bfMhtyqpeo4e4SiPderpt1

so is it offline or online or both ? and can i decrypt some files?

Share this post


Link to post
Share on other sites

Unless you happen to find ransom notes that have offline ID's in the, then your files more than likely all have online ID's. The easiest way to tell is just to run the decrypter and see if it can decrypt any of your files, although in the case of .derp we may not have the offline key for it yet, but at least the ID's will appear in the decrypter's output.

Share this post


Link to post
Share on other sites

The form of encryption used in newer variants isn't susceptible to the use of file pairs. Normally, with the type of encryption it uses, it's secure enough that there's no way to decrypt files without the private key. The only alternative is waiting tens of thousands of years for a supercomputer to brute force the key.

Share this post


Link to post
Share on other sites

my pc was infected by derp virus

the personalid on _readme.txt is   0176Asd374y5iuhldTH3qgRaDDLBvQeNNvDNd7xgtvrKTJPW4CP2Ny1Hj

virus wirte on this registery hash code is  KqLP7Cmpx34=

 

so is it offline or online or both ? and can i decrypt some files?

 

ransomware note is :

 

ATTENTION!

Don't worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-IbdGyCKhdr
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail:
[email protected]

Reserve e-mail address to contact us:
[email protected]

Your personal ID:
0176Asd374y5iuhldTH3qgRaDDLBvQeNNvDNd7xgtvrKTJPW4CP2Ny1Hj

Share this post


Link to post
Share on other sites
19 hours ago, saeidazizi said:

Your personal ID:
0176Asd374y5iuhldTH3qgRaDDLBvQeNNvDNd7xgtvrKTJPW4CP2Ny1Hj

This is a newer variant of STOP/Djvu, and your ID is an online ID, so there is currently no way to decrypt your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Share this post


Link to post
Share on other sites
On 12/1/2019 at 5:24 AM, saeidazizi said:

virus wirte on this registery hash code is :  KqLP7Cmpx34=

That's not a decryption key.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.