Jump to content

New Variant Offline id


Recommended Posts

Hi,

Infected by .cool , so after I remove the viruses I run the program and

I got this message in log section:

No key for New Variant offline ID:   vkkerIMedP7WK1ZhHOAlJV10Wxn9fHEbEQbgait1
Notice: this ID appears be an offline ID, decryption MAY be possible in the future.

It's quite clear what it is written, but

is there any hope? :) Should I wait for any upgrade?

Link to comment
Share on other sites

2 hours ago, Incognicat said:

No key for New Variant offline ID:   vkkerIMedP7WK1ZhHOAlJV10Wxn9fHEbEQbgait1
Notice: this ID appears be an offline ID, decryption MAY be possible in the future.

Yes. It is recommended to save the files in a safe place. This must be done before you try to do anything with the files.

Link to comment
Share on other sites

There is a detailed guide here, but if you don’t want to read a lot of text, then I will briefly summarize the essence.

There are 't1' characters at the end of the identifier, this usually means that the 'offline ID' is being used and the files can be decrypted in the future when the decryption key for this variant is loaded into the 'Emsisoft Decryptor'. This event depends on the voluntary transfer of the key by someone who bought the key from the extortionists. This may happen or may never happen. Then it will be added to the Decryptor and will allow anyone with the same variant to decrypt the files without paying the ransom.

The appearance of a new key is not reported anywhere. The work is done every day. It is recommended to save the encrypted files on an external drive, download the 'Emsisoft Decryptor' once a week and check the decryption capability.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...