Jump to content

Recommended Posts

hello sir, 

few days ago my pc gets infected with some ransomware virus with .enfp extension. i don't know from where it came from there is some ''autolt v3 script'' was also running after every few seconds but i deleted it successfully named ''autolt.exe''. but files are still encrypted i've tried everything but nothing works it has online id please give some solution.

19939Vintage-Brass-Temple-Bell-SBG-43-(1).jpg.enfp

Link to post
Share on other sites

This is a newer variant of STOP/Djvu. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Link to post
Share on other sites
8 hours ago, GT500 said:

This is a newer variant of STOP/Djvu. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Hello, I also got infected a few days ago and my files are encrypted with .esfp. I saw in ‘_readme.txt’ file 

Your personal ID:   0288Widasdgy4HLd4Nu8hMhno9C8AEpO10FUGAYGVNmXbgsUt1
and in the file

C: \ SystemID \ PersonalID.txt - I see this: gy4HLd4Nu8hMhno9C8AEpO10FUGAYGVNmXbgsU. 

Please tell me which descriptor should I use?

Link to post
Share on other sites
On 4/2/2021 at 9:50 AM, Valentina Hlebarova said:

Your personal ID:   0288Widasdgy4HLd4Nu8hMhno9C8AEpO10FUGAYGVNmXbgsUt1
and in the file

C: \ SystemID \ PersonalID.txt - I see this: gy4HLd4Nu8hMhno9C8AEpO10FUGAYGVNmXbgsU. 

This is a newer variant of STOP/Djvu. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Since you have two ID's, you probably have some files with an online ID and some files with an offline ID. Our decrypter will tell you which ID each encrypted file has and whether they are online or offline ID's.

Link to post
Share on other sites
On 4/3/2021 at 7:12 PM, cybermetric said:

I don't think that the poster has 2 ID's. it looks like he truncated the ID from the PersonalID. txt file.

You're right, the end of the ID from PersonalID.txt must have been cut off when he copied it. The rest of the ID appears to be identical.

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...