EiTsang 0 Posted March 19, 2020 Report Share Posted March 19, 2020 Computer files are encrypted .Devos Ransomware Is there a solution now? Quote Link to post Share on other sites
Amigo-A 136 Posted March 19, 2020 Report Share Posted March 19, 2020 Attach a ransom note and several encrypted files to message. If nothing has changed, then this is Phobos Ransomware. But we need to look at the files to confirm this. Quote Link to post Share on other sites
EiTsang 0 Posted March 20, 2020 Author Report Share Posted March 20, 2020 !!!All of your files are encrypted!!! IMPORTANT!!! WRITE TO US AT ONCE ON TWO SPECIFIED E-MAIL!!! TWO AT ONCE!!! [email protected], [email protected] ★Communication methods left by gangsters,Bitcoin transactions Quote Link to post Share on other sites
Amigo-A 136 Posted March 20, 2020 Report Share Posted March 20, 2020 Need a ransom note file and several encrypted files. They need to be attached to the message. Quoting is not necessary. Quote Link to post Share on other sites
GT500 854 Posted March 21, 2020 Report Share Posted March 21, 2020 You can attach a copy of the ransom note and an encrypted file to a reply, which will help us identify the ransomware for you. Either drag and drop them into the reply field, or use the "choose files" link next to the paperclip icon at the bottom of the reply field. Quote Link to post Share on other sites
EiTsang 0 Posted March 23, 2020 Author Report Share Posted March 23, 2020 新文字文件(2).reg.id [B89DA01C-2692]。[[email protected]]。德沃斯LOGO180x180.PNG.id [B89DA01C-2692]。[[email protected]]。德沃斯OPP計劃-B20181116.pdf.id [B89DA01C-2692]。[[email protected]]。德沃斯 20160318公交會性別平等.docx.id[B89DA01C-2692].[[email protected]].Devos Quote Link to post Share on other sites
EiTsang 0 Posted March 23, 2020 Author Report Share Posted March 23, 2020 德沃斯OPP 。新文字文件(2).reg.id [B89DA01C-2692]。[[email protected]]。德沃斯LOGO180x180.PNG.id [B89DA01C-2692]。[[email protected]]。德沃斯info.htaOPP計劃-B20181116.pdf.id [B89DA01C-2692]。[[email protected]]。德沃斯 info.txt Quote Link to post Share on other sites
GT500 854 Posted March 23, 2020 Report Share Posted March 23, 2020 The ransom notes were empty, however this appears to be Phobos:https://id-ransomware.malwarehunterteam.com/identify.php?case=284e2d553e29b00c7be452e1e459ebcffc0a3787 Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.