ABN 3 Posted January 25, 2020 Report Share Posted January 25, 2020 (edited) Bom dia, boa tarde ou boa noite amigos, Agradecia que ajudou os meus ficheiros foram encriptados com o "ransomware" em 19 deste mês, já passei o kit do emsisoft no PC. acontece que os arquivos (imagem, vídeo e texto) continuam encriptados com a extensão "KODC e" NOSU A chave que foi adicionada pelos usuários por esta informação é: 0197nTsddWz89FpQxEfauas77thXAVHplctS6hWM5M3QvtYdI Exigem o pagamento de US $ 499, que já passou por US $ 980! Obrigado. Fixlog.txt FRST.txt Addition.txt Edited January 25, 2020 by ABN erro na escrita 1 Quote Link to post Share on other sites
MrSalazar 2 Posted January 25, 2020 Report Share Posted January 25, 2020 Pelo que sei sua chave é Online. Portanto é muito mais difícil de resolver o problema, porque essa chave de criptografia fica guardada em um servidor, então o acesso à ele deve ser restrito, impossibilitando assim o Decrypter de calcular o seu tipo de criptografia; mas quando a chave termina com t1 , quer dizer que é Offline, portanto está armazenada em seu computador, possibilitando o programa achar e desemcriptar seus dados com base nela. OBS: Traduz seu post para o Inglês, para facilitar o trabalho deles e te ajudar. 1 Quote Link to post Share on other sites
ABN 3 Posted January 26, 2020 Author Report Share Posted January 26, 2020 Good morning, good afternoon or good night friends, I would appreciate help: my files have been encrypted with "ransomware" since the 19th of this month, I already passed the emsisoft kit on the PC. it happens that the files (image, video and text) are still encrypted with the extension "KODC and" NOSU The key that was added by the viruses is: 0197nTsddWz89FpQxEfauas77thXAVHplctS6hWM5M3QvtYdI They require a payment of $ 499, which has already gone through $ 980! I already passed the "Emsisoft" kit, the viruses were eliminated, but the files are still encrypted! Attach the 3 files generated by "FRST" Thanks for listening. Addition.txt Fixlog.txt FRST.txt 1 Quote Link to post Share on other sites
GT500 883 Posted January 28, 2020 Report Share Posted January 28, 2020 On 1/26/2020 at 12:12 PM, ABN said: The key that was added by the viruses is: 0197nTsddWz89FpQxEfauas77thXAVHplctS6hWM5M3QvtYdI This is a newer variant of STOP/Djvu, and your ID is an online ID, so there is currently no way to decrypt your files. There is more information at the following link:https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/ On 1/26/2020 at 12:12 PM, ABN said: Attach the 3 files generated by "FRST" Please download the following fixlist.txt file and save it to the Desktop: https://www.gt500.org/emsisoft/fixlist/2020-01January-28/ABN/fixlist.txt NOTE: It's important that both files, the FRST download from earlier and the fixlist file, are in the same location or the fix will not work. If you need to, please copy the files from your Downloads folder to your desktop. Run the FRST download from earlier, and press the Fix button just once and wait. If for some reason the tool needs to restart your computer, please make sure you let the computer restart normally. After that let the tool complete anything it still needs to do. When finished FRST will generate a log on the Desktop (Fixlog). Please attach it to a reply. Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.