kunal kanojiya

my all files have been encrypted by .nlah please help me they are important ones

Recommended Posts

Attach a ransom note _readme.txt to your message. 

Do not edit anything.

Share this post


Link to post
Share on other sites

This is a newer variant of STOP/Djvu. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

 

Share this post


Link to post
Share on other sites
17 hours ago, kunal kanojiya said:

i have attached the note.... please help 

The ID in the ransom note is an online ID.

Share this post


Link to post
Share on other sites

hi, any hope with .nlah ''2020  version''?

ATTENTION!

Don't worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-BtumiluQaI
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail:
[email protected]

Reserve e-mail address to contact us:
[email protected]

Your personal ID:
0229yiuduy6S5dYNU1A2FW3Y29wfbulMnxYPV7Sh1ff107Sh9rOVyG

Share this post


Link to post
Share on other sites

Hi, 
I also need help .nlah decrypt. 
I recently got infected. It is new and online key. 
I tried "pair fail" submission form, but no help.
Maybe i can send some encrypted and original files to someone? 

 

Share this post


Link to post
Share on other sites
Quote

.nlah

This is new variant of STOP Ransomware  (known since June 1)

Only some decryption keys are currently added to Emsisoft Decryptor. There is no key for this variant yet.

Share this post


Link to post
Share on other sites
12 hours ago, Amigo-A said:

This is new variant of STOP Ransomware  (known since June 1)

Only some decryption keys are currently added to Emsisoft Decryptor. There is no key for this variant yet.

:(
Please, I really need my files back. 
How can I help develop .nlah decrypting? 
I added money claim text. 
I can send smaller encrypted and original files. .jpg .mp3 .mp4 .docx .exe and so on. 
I have some backups, but didn't had back up for most important files :(

 

_readme.txt

Share this post


Link to post
Share on other sites
On 6/6/2020 at 8:37 AM, kunal kanojiya said:

yes I know that with the help of link you have given... plz help me out in any way.....

The only help I can give you is to say "it's impossible to decrypt your files."

Share this post


Link to post
Share on other sites
On 6/7/2020 at 8:06 AM, wolfentine said:

Your personal ID:
0229yiuduy6S5dYNU1A2FW3Y29wfbulMnxYPV7Sh1ff107Sh9rOVyG

This is a newer variant of STOP/Djvu, and your ID is an online ID, so there is currently no way to decrypt your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Share this post


Link to post
Share on other sites
On 6/7/2020 at 11:56 AM, Maxx said:

I also need help .nlah decrypt. 
I recently got infected. It is new and online key. 
I tried "pair fail" submission form, but no help.
Maybe i can send some encrypted and original files to someone? 

This is a newer variant of STOP/Djvu, and it's not susceptible to that type of attack. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Share this post


Link to post
Share on other sites
5 hours ago, AngelYag said:

I got infected with this virus and I can't get my files back.

This is a newer variant of STOP/Djvu, and your ID is an online ID, so there is currently no way to decrypt your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Share this post


Link to post
Share on other sites
8 hours ago, Maxx said:

I added money claim text. 

I didn't see you had attached your ransom note before posting my previous reply.

Your ID is an online ID, so decryption of your files is not possible at this time.

Share this post


Link to post
Share on other sites
6 hours ago, AngelYag said:

If it's an offline ID, does it work?

Not for .nlah as we don't have the private key for its offline ID.

That being said, your ID was an online ID.

Share this post


Link to post
Share on other sites
On 6/9/2020 at 12:03 PM, GT500 said:

The only help I can give you is to say "it's impossible to decrypt your files."

any future hope for getting a decryptor tool and I can restore my files???🙏

 

Share this post


Link to post
Share on other sites
19 hours ago, kunal kanojiya said:

any future hope for getting a decryptor tool and I can restore my files???🙏

If law enforcement is able to catch the criminals or otherwise gain access to their servers and release their private keys for use in decrypters, then we can add them to our database so that everyone can get their files back.

Our recommendation is to save a backup of your encrypted files and keep it in a safe place in case decryption is possible at some point in the future.

We also recommend keeping an eye on BleepingComputer's newsfeed, as they will usually report on new developments with ransomware decrypters:
https://www.bleepingcomputer.com/

If you have an RSS feed reader, then they also have an RSS feed so that you don't have to manually check for news:
https://www.bleepingcomputer.com/feed/

Share this post


Link to post
Share on other sites
8 hours ago, Thomas95 said:

Is anyone trying to pay and got the files back? i'm wondering are they keep their word and send decrypton software?

As far as I am aware the criminals who make the STOP/Djvu ransomware do usually send a working decrypter.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    No registered users viewing this page.