Recommended Posts

Hello @dfarn26,

Thank you for contacting Emsisoft Support.

This is very likely DHARMA(CrySiS).  Unfortunately, there is no way to decrypt your files using third-party tools.

Share this post


Link to post
Share on other sites

  

On 1/30/2020 at 4:20 AM, Kevin Zoll said:

This is very likely DHARMA(CrySiS)

 

Hello @dfarn26

Now there are at least two more encryptors that add exactly the same extension to the files - .harma

To find out exactly which encryptor you are dealing with, you need to attach several encrypted files and a note from the extortionists to the message. 
If these are files with hta or html extensions, then they must be archived with a password of '123' so that forum protection does not change them contents.

Probably, the infection is still on your PC, you need to check Windows with antivirus tool and eliminate the threat.

Emsisoft Emergency Kit
https://www.emsisoft.com/en/home/emergencykit/ 

FRST (Farbar Recovery Scan Tool)
https://help.emsisoft.com/en/1738/how-do-i-run-a-scan-with-frst/ 

Attach the results of the scan to your new message. Support specialists will look at the logs and tell you what to do next.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.