Jump to content

QDLA virus


Recommended Posts

My files are encrypted by QDLA virus and all the files in all the drive are affected and got the extension .QDLA. 

 

Using quick heal removed the trojeon but files are not able to be decrypted using stop djvu.

 

Please help.

Edited by Prakashhsm
Wrongly mentioned the file name
  • Like 1
Link to comment
Share on other sites

20 minutes ago, Prakashhsm said:

My files are encrypted by QLDA virus and all the files in all the drive are affected and got the extension .qlda. 

 

Using quick heal removed the trojeon but files are not able to be decrypted using stop djvu.

 

Please help.

Are you sure the extension is .qlda? There is a new STOP variant the extension .qdla  (V0347)

Link to comment
Share on other sites

  • Prakashhsm changed the title to QDLA virus

While using EMSISOFT decryptor for STOPDjvu version 1.0.0.5 i am getting the below error. 

File: C:\Users\91989\OneDrive\Desktop\Ayyappa song 2021\video\videoplayback.mp3.qdla
Error: No key for New Variant online ID: ZdHmIPQIgTMsxebFURhd8MwlzKBVf7n6tL7l0kJn
Notice: this ID appears to be an online ID, decryption is impossible
 

Kindly suggest

Link to comment
Share on other sites

all the folder has the txt file. details as below.

TTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-W7mpKFSSv2
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail:
[email protected]

Reserve e-mail address to contact us:
[email protected]

Your personal ID:
0347gSd743dZdHmIPQIgTMsxebFURhd8MwlzKBVf7n6tL7l0kJn

Link to comment
Share on other sites

15 hours ago, Prakashhsm said:

Error: No key for New Variant online ID: ZdHmIPQIgTMsxebFURhd8MwlzKBVf7n6tL7l0kJn

This is not a bug in the program. Thus, the decryptor informs that it does not have a key and that decryption is impossible because the encryption key was generated on the ransomware server and transmitted to the computer to encrypt the files. It cannot be hacked by enumerating all the combinations, for the entire period of human life.

Quote

Notice: this ID appears to be an online ID, decryption is impossible

Yes, probably true. Emsisoft Decryptor accurately identifies decryption capabilities.
Next, I'll tell you what you should do as soon as possible and how else you can try to get some files back.

Link to comment
Share on other sites

What to do? Everything is lost?
If there is currently no way to decrypt files, but in the future, in theory, extortionists can publish keys to all of their victims. This does not happen often, but this year we have seen such cases several times.

Why did this happen?

This 'STOP Ransomware' enters the PC due to the fact that computer is poorly protected. People often use free antivirus programs with the 'Free' label in the name. None of these programs will protect PC from programs similar to 'STOP Ransomware', because basic protection is not capable of this feat.
If users used comprehensive protection of the 'Internet Security' class, then it would help protect PC from ransomware attacks.

There is no 100% protection against malware, but what the 'Free' antivirus gives is 1-2 percent protection. 

After this attack, PCs could have stayed other malware elements. This maybe is an info-stealer and something else. Therefore, it is urgent to conduct a full check and destroy malware.

Use an comprehensive anti-virus software such as Emsisoft Anti-Malware to effectively remove the malware. 
You can get a free trial 30-days version of Emsisoft Anti-Malware here: https://www.emsisoft.com/en/home/antimalware/

It will help you clean your PC from other malware for free.

!!! You need to neutralize all malicious files in the system. This should be done as quickly as possible. 

Link to comment
Share on other sites

Only after neutralizing all malicious files ...

This is not the decryption, it is the recovery of certain types of files using the features of these files.

1) If you have encrypted ZIP/RAR archives, you can partially recover them. Only 1-2 files are damaged there. Remove the extension that the ransomware added to the archives, and extract the files in the usual way. Everything except 1-2 files will be fixed. If there is only 1 file in the archive, then it will most likely be unrecoverable.

2) There is an alternative (additional) way to recover some media files:
WAV, MP3, MP4, M4V, MOV, 3GP.

https://www.disktuna.com/media_repair-file-repair-for-stop-djvu-mp3-mp4-3gp

But before trying the alternative variant with media files, it is recommended that you make a copy of the encrypted files. Something will be restored better, something will be restored worse. 

Some types of files can be opened (restored) using the application in which they were created. To do this, you must first remove the extension added by the ransomware. Then can try to open the file from the program in which it was created. If you open audio and video files in the editor, it will restore the structure, and upon closing it will offer to save the changes in the file.

3) If you have PDFs or files of other e-books, then they may suffer in part if they were not protected from manual modification. Therefore, after removing the added extension, they can be partially read (~ 80%).

Unfortunately, it is not yet possible to recover files created in MS Office applications due to their sensitivity to any damage. They can be easily damaged without encryption. It is easier to recover and read text written on paper or on the stone than one created in MS Office.

An alternative method for other files has not yet been found. I understand that this will not be enough, but recovering some of the files is better than to lose everything...

Link to comment
Share on other sites

https://www.disktuna.com/media_repair-file-repair-for-stop-djvu-mp3-mp4-3gp

It is recovering only the Mp3 files rest all files like mp4 files are not getting recovered. Kindly help me to recover the photos files as the photos are very important and all photos files are very valuable and memorable as i had a backup of photos for last 15years.

Please help to decrypt the photos 

 

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...