YTAnonymous 0 Posted April 6, 2020 Report Share Posted April 6, 2020 All of my files were encrypted by .mado extension and i see __readme.txt in my folder ATTENTION! Don't worry, you can return all your files! All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key. The only method of recovering files is to purchase decrypt tool and unique key for you. This software will decrypt all your encrypted files. What guarantees you have? You can send one of your encrypted file from your PC and we decrypt it for free. But we can decrypt only 1 file for free. File must not contain valuable information. You can get and look video overview decrypt tool: https://we.tl/t-PHJh5SU4jT Price of private key and decrypt software is $980. Discount 50% available if you contact us first 72 hours, that's price for you is $490. Please note that you'll never restore your data without payment. Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours. To get this software you need write on our e-mail: [email protected] Reserve e-mail address to contact us: [email protected] Your personal ID: 0217OIWojlj488TaHEsq5r7cNJKbYdWseLEB2pW1FuZKoKjKg5tt1 When i tried to Decrypt it with Emsisoft STOP i got this File: D:\22 Dec, 09.10.mp3.mado No key for New Variant offline ID: 8TaHEsq5r7cNJKbYdWseLEB2pW1FuZKoKjKg5tt1 Notice: this ID appears be an offline ID, decryption MAY be possible in the future Quote Link to post Share on other sites
airiel 0 Posted April 6, 2020 Report Share Posted April 6, 2020 facing a same problem Quote Link to post Share on other sites
GT500 854 Posted April 7, 2020 Report Share Posted April 7, 2020 On 4/5/2020 at 10:51 PM, YTAnonymous said: No key for New Variant offline ID: 8TaHEsq5r7cNJKbYdWseLEB2pW1FuZKoKjKg5tt1 Notice: this ID appears be an offline ID, decryption MAY be possible in the future This is a newer variant of STOP/Djvu. Fortunately your ID is an offline ID, however we don't yet have the private key for it. I recommend running the decrypter once every week or two so that you can see when we've been able to add the private key for your variant. There is more information at the following link:https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/ @airiel If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There's more information at the link above. Quote Link to post Share on other sites
YTAnonymous 0 Posted April 8, 2020 Author Report Share Posted April 8, 2020 23 hours ago, GT500 said: offline ID: 8TaHEsq5r7cNJKbYdWseLEB2pW1FuZKoKjKg5tt1 This's the offline id Quote Link to post Share on other sites
GT500 854 Posted April 8, 2020 Report Share Posted April 8, 2020 59 minutes ago, YTAnonymous said: This's the offline id Correct. Just keep in mind that the ID in the ransom notes has an extra 4-digit number on the begining. For .mado that number should be "0217". Quote Link to post Share on other sites
YTAnonymous 0 Posted April 8, 2020 Author Report Share Posted April 8, 2020 2 hours ago, GT500 said: Correct. Just keep in mind that the ID in the ransom notes has an extra 4-digit number on the begining. For .mado that number should be "0217". Yep, it is 0217, i'll waiting for the next update Emsisoft Decryptor, i know you guys working for this, and stay safe Quote Link to post Share on other sites
GT500 854 Posted April 9, 2020 Report Share Posted April 9, 2020 21 hours ago, YTAnonymous said: Yep, it is 0217, i'll waiting for the next update Emsisoft Decryptor, i know you guys working for this, and stay safe We don't actually have to update the decrypter. It gets the keys from an online database. Just run the decrypt once every week or two, and when the key has been added it should start decrypting files. Quote Link to post Share on other sites
YTAnonymous 0 Posted April 9, 2020 Author Report Share Posted April 9, 2020 5 hours ago, GT500 said: We don't actually have to update the decrypter. It gets the keys from an online database. Just run the decrypt once every week or two, and when the key has been added it should start decrypting files. Alright thanks for the information Quote Link to post Share on other sites
Gofra 0 Posted April 27, 2020 Report Share Posted April 27, 2020 On 4/9/2020 at 10:29 AM, GT500 said: We don't actually have to update the decrypter. It gets the keys from an online database. Just run the decrypt once every week or two, and when the key has been added it should start decrypting files. if my code starting "8TaH" i won't be able to recover my files? Quote Link to post Share on other sites
GT500 854 Posted April 28, 2020 Report Share Posted April 28, 2020 20 hours ago, Gofra said: if my code starting "8TaH" i won't be able to recover my files? It's more important what the ID ends with. Quote Link to post Share on other sites
Gofra 0 Posted April 28, 2020 Report Share Posted April 28, 2020 6 hours ago, GT500 said: It's more important what the ID ends with. tt1 Quote Link to post Share on other sites
GT500 854 Posted April 29, 2020 Report Share Posted April 29, 2020 16 hours ago, Gofra said: tt1 If the ID really ends in t1 then that should mean it's an offline ID, which means decryption should be possible once someone donates the private key for that ID. Quote Link to post Share on other sites
Gofra 0 Posted April 30, 2020 Report Share Posted April 30, 2020 On 4/29/2020 at 6:30 AM, GT500 said: If the ID really ends in t1 then that should mean it's an offline ID, which means decryption should be possible once someone donates the private key for that ID. How we can get the private key for that ID? Quote Link to post Share on other sites
GT500 854 Posted May 1, 2020 Report Share Posted May 1, 2020 On 4/30/2020 at 3:28 AM, Gofra said: How we can get the private key for that ID? Only the criminals have the private keys. A victim who has that offline ID and pays the ransom has to donate the decrypter the criminals sent them to us so that we can extract the private key from it. Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.