Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

STOP Ransomware (.STOP .Djvu, .Puma, .Promo) Support Topic


  • Please log in to reply
12103 replies to this topic

#451 Demonslay335

Demonslay335

    Ransomware Hunter


  •  Avatar image
  • Security Colleague
  • 4,770 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:14 PM

Posted 21 January 2019 - 02:00 PM

@all

 

They've made some changes to the malware starting with the .rumba extension. I have updated the decrypter to support this new encrypted file format if you were hit by the offline key.

 

There is a new offline key embedded in the decrypter (v2.0.1.0) for ID D02NfEP94dKUO3faH1jwqqo5f9uqRw2Etn2lP3VB. If you have this ID, the decrypter will now be able to decrypt your files.

 

2019-01-21_1258.png

 

2019-01-21_1300.png

 

https://download.bleepingcomputer.com/demonslay335/STOPDecrypter.zip


logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic]

ransomnotecleaner-25.png RansomNoteCleaner - Remove Ransom Notes Left Behind [Support Topic]

cryptosearch-25.pngCryptoSearch - Find Files Encrypted by Ransomware [Support Topic]

If I have helped you and you wish to support my ransomware fighting, you may support me here.


BC AdBot (Login to Remove)

 


#452 Cokgolok

Cokgolok

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  

Posted 21 January 2019 - 02:58 PM

 

 

 



 
I'am from indonesia, please help to @kNN @Demonslay335 .. Laptop infected with .pdff 
 
 
 
trying with STOP! decryptor from @Demonslay335 nothing help because its different Personal ID.
 
 
 
this is the log from decryptor
http://prntscr.com/m9xh0v
 
 
[!] No keys were found for the following IDs:
[*] ID: mXqz4Z3FFZYcYsu6hPRQbYwAOfSPEgW1dnAhmDX2
Please archive these IDs and the following MAC addresses in case of future decryption:
[*] MAC: EC:0E:C4:3E:C9:8F
[*] MAC: 00:00:00:00:00:00:00:E0
This info has also been logged to STOPDecrypter-log.txt
 
this is sample https://drive.google.com/open?id=1AhflsyzOQGx5mASgv7Ea8Ztvdxgxad6G
 
Any help very appreciate, Thanks in advance
 

belum semua bisa pake itu gan baru beberapa ID aja yang bisa
 
Ane kena awal pas ni virus baru release kena pdff ane, ente daerah mna gan

 

halo gan, ane juga kena semalem. mohon bantu pencerahannya gan



#453 patvaros87

patvaros87

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:14 PM

Posted 21 January 2019 - 03:13 PM

@all

 

They've made some changes to the malware starting with the .rumba extension. I have updated the decrypter to support this new encrypted file format if you were hit by the offline key.

 

There is a new offline key embedded in the decrypter (v2.0.1.0) for ID D02NfEP94dKUO3faH1jwqqo5f9uqRw2Etn2lP3VB. If you have this ID, the decrypter will now be able to decrypt your files.

 

2019-01-21_1258.png

 

2019-01-21_1300.png

 

https://download.bleepingcomputer.com/demonslay335/STOPDecrypter.zip

 

1000x Thanks, you are the best.  Thank you for your support!! I' am very happy, again I can use my files. You are the GOD !!!! :step1:



#454 Cokgolok

Cokgolok

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  

Posted 21 January 2019 - 03:14 PM

Hi, I'm from indonesia, need your help @kNN @Demonslay335
 

MAC address : 50:5B:C2:B8:1C:ED

Personal ID : 027sng9SwkMQ3C3zP6yNcemHZZ52xPO1IJ9lRaafN6u

 

infected with .rumba


encrypted and decrypted file : https://ufile.io/ttvec


Best regards, Thank you


Edited by Cokgolok, 21 January 2019 - 03:16 PM.


#455 khan114

khan114

  •  Avatar image
  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:14 AM

Posted 21 January 2019 - 03:53 PM

Hi,

My friends laptop data has been encrypted with ransomware having extension .tfude. I download STOPDecrypter v2.0.1.0 but after running to infected file it decrypt the files but they are unable to open.

 

I tried to share snap of files but its not pasted here. i can share files if you wanted for further analysis.

 

Note from Ransomware is below:

 

---------------------------------------------- ALL YOUR FILES ARE ENCRYPTED ----------------------------------------------- 
 
Don't worry, you can return all your files!
All your files documents, photos, databases and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees do we give to you?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can download video overview decrypt tool:
Don't try to use third-party decrypt tools because it will destroy your files.
Discount 50% available if you contact us first 72 hours.
 
---------------------------------------------------------------------------------------------------------------------------
 
 
To get this software you need write on our e-mail:
pdfhelp@india.com
 
Reserve e-mail address to contact us:
pdfhelp@firemail.cc
 
Your personal ID:
024kSSCqHHUsJov1Xq56xQ0RmMP7V4Sz7KUZCwqkdkM
 
 
please help in this matter.


#456 kishox

kishox

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:09:14 PM

Posted 21 January 2019 - 03:58 PM

Hello, 
 
 
.rumba 
 
Key ID:   0275bOacFY0verQBAz9zXaT14Bx27I3dQRVEsR6VG42
 
MAC: 
  24-BE-05-09-C1-15
 
uploaded files:  https://ufile.io/zueak  
 
BR,


#457 TheComAdd

TheComAdd

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:14 PM

Posted 21 January 2019 - 04:12 PM

Hello, if possible, please help with .tfudet:

 

 
Physical Address: ‎34-F3-9A-CF-B3-2C
 
personal ID:
026N3TshhNYkbOVYeMpWLAa3v9Tdaoj2SXQVRjc87at


#458 simpar

simpar

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:11:14 PM

Posted 21 January 2019 - 04:21 PM

@all
 
They've made some changes to the malware starting with the .rumba extension. I have updated the decrypter to support this new encrypted file format if you were hit by the offline key.
 
There is a new offline key embedded in the decrypter (v2.0.1.0) for ID D02NfEP94dKUO3faH1jwqqo5f9uqRw2Etn2lP3VB. If you have this ID, the decrypter will now be able to decrypt your files.
 
2019-01-21_1258.png
 
2019-01-21_1300.png
 
https://download.bleepingcomputer.com/demonslay335/STOPDecrypter.zip


Hello sir.

I have seen your message in the topic and i've tried to decrypt rumba files but there's a problem with this. I have decrypt the files with that decrypter and i got the normal file but the file didn't act like the original file. For example a docx file is empty when i decrypted it.

Plus i have both .rumba extension and .ilrkdszxe extension in the same file. There is a sample of both files. When i decrypted the rumba file i got rid of rumba but ilrkdszxe still stays. Is there any solution for this? I got over 6 thousands pictures inflected by that bleep. I have no backup or something. I am desperate like hell :(

https://ufile.io/oaat7
https://ufile.io/9l7gt

#459 Aice400

Aice400

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  

Posted 21 January 2019 - 04:47 PM

Hello ,

Rumba







To get this software you need write on our e-mail:
pdfhelp@india.com

Reserve e-mail address to contact us:
pdfhelp@firemail.cc

Your personal ID:
027OvtLrLmeryfCqytqt1RBbEMCEF4rsN4yIfBU0K3Z

#460 quietman7

quietman7

    Bleepin' Gumshoe

  • Topic Starter

  •  Avatar image
  • Global Moderator
  • 61,914 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:03:14 PM

Posted 21 January 2019 - 04:53 PM


...Plus i have both .rumba extension and .ilrkdszxe extension in the same file. There is a sample of both files. When i decrypted the rumba file i got rid of rumba but ilrkdszxe still stays. Is there any solution for this? ...

Crypto malware can be responsible for dual (multiple) infections since it will encrypt any directory or file it can read/write to. Ransomware does not care about the contents of the data or whether your files or drives are already encrypted...it will just encrypt (re-encrypt) them again. Even the same ransomware can encrypt data multiple times with different strains. That means dealing with both ransomwares and both ransom demand payments in order to decrypt data.

 

Based on infection rates we see, you are most likely infected with a variant of GandCrab V5.

  • GandCrab V5 (V5.0.1) will have a random 5 character extension (i.e. .fbkdp .ibagx .qikka) appended to the end of the encrypted data filename and leave files (ransom notes) named [random extension]-DECRYPT.html (i.e. qikka-DECRYPT.html, eiuhtxjzs-DECRYPT.html).
  • GandCrab V5.0.2 and beyond will have a random 5-9 character extension (i.e. .fnxfavh, .eiuhtxjzs, .ilrkdszxe) appended to the end of the encrypted data filename and leave files (ransom notes) named [random extension]-DECRYPT.html (i.e. fnxfavh-DECRYPT.html, eiuhtxjzs-DECRYPT.html).
  • GandCrab V5.0.4+ will have a random 5-10 upper-case character extension (i.e. .XMMFA, .LUKIZQW, .TKKLKM, .PFBRBHHEVM) appended to the end of the encrypted data filename and leave files (ransom notes) named [random upper-cased extension]-DECRYPT.txt (i.e. LUKIZQW-DECRYPT.txt, TKKLKM-DECRYPT.txt).
  • GandCrab V5.1+, like its predecessors, will also have a random 5-10 upper-case character extension appended to the end of the encrypted data filename.

Bitdefender released a free decrypter for victims of GandCrab V1 with the .GDCB extension and a free decrypter for victims of GandCrab V4, early versions of V5 recognizable by their extensions...V4 .KRAB and V5, V5.0,1, V5.0.2, V5.0.3 random 5-9 character (i.e. .fbkdp .ibagx .qikka .eiuhtxjzs9) respectively. Files encrypted by GandCrab V5.0.4+ are not decryptable at this time without paying the ransom since these versions have been reported to break the BitDefender decryption tool so it will not work.


.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#461 sirheny

sirheny

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:14 PM

Posted 21 January 2019 - 05:03 PM

Hello,

 

here is Holger from Germany, i have the same problem like them most here i think 

STOPDecrypt says :

 

Unidentified ID: iW1iatU8mul2teup8JklhDNiHiGH5Lpaij4ITpVS

MAC: 00:1A:4D:5A:32:BD 

 

it will be very important to recover all my pictures and the bachup of it is infectet too...

 

i´m confused with sending an encrypted file and an original file, i have only encrypted files, i looking for something to decrypt back to original file ?!?!?

 

 

Thanks for your help 

 

 



#462 Anth12

Anth12

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:14 PM

Posted 21 January 2019 - 05:04 PM

Hi!

 

I have received all your messages, I have to check them.

Please, a lot of you have sent useless messages, please, follow the following steps to send me messages:

- Only one message and thread with all the needed information (encrypted and decrypted file, MAC address and personalID in the ransom note)

- Send personalID and mac address as text in the message (no photos, no files). It is easier to check.

- Send the infomation, do not send a message to just say your are infected, i am not going to reply to this messages. Just send the information.

- Send the files compressed as ZIP (no RAR or any other format)

- Upload your files to a service in which I do not need to register to download your files (for example: https://uploadfiles.io)

 

Send only what is neccesary and send it as soon as possible. A lot of you won't be able to decrypt your files because the time has passed and there is no way to recover the encryption key. Time is VERY important.

Hii i got infected by .djvut like a week ago 

-Your personal ID:

0226se9RaIxXF9m70zWmx7nL3bVRp691w4SNY8UCir0

-Mac address : 02-03-35-61-62-61

-Zip file : https://ufile.io/x8opd



#463 sirheny

sirheny

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:14 PM

Posted 21 January 2019 - 05:04 PM

Hello,

 

here is Holger from Germany, i have the same problem like them most here i think 

STOPDecrypt says :

 

Unidentified ID: iW1iatU8mul2teup8JklhDNiHiGH5Lpaij4ITpVS

MAC: 00:1A:4D:5A:32:BD 

 

it will be very important to recover all my pictures and the bachup of it is infectet too...

 

i´m confused with sending an encrypted file and an original file, i have only encrypted files, i looking for something to decrypt back to original file ?!?!?

 

 

Thanks for your help 

 

 



#464 SirCosick

SirCosick

  •  Avatar image
  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 21 January 2019 - 05:11 PM

Hello,

 

here is Holger from Germany, i have the same problem like them most here i think 

STOPDecrypt says :

 

Unidentified ID: iW1iatU8mul2teup8JklhDNiHiGH5Lpaij4ITpVS

MAC: 00:1A:4D:5A:32:BD 

 

it will be very important to recover all my pictures and the bachup of it is infectet too...

 

i´m confused with sending an encrypted file and an original file, i have only encrypted files, i looking for something to decrypt back to original file ?!?!?

 

 

Thanks for your help 

 

 

Hi, Holger.

What they mean by decrypted file is the original version of a now encrypted file, a version you can recover by downloading exactly the same file or recovering it from your inbox/sent tray in your mail. For example, I sent them a .pdf file that was encrypted and a normal version of the same file that i rescued from my mail because I had sent it months ago to someone else.

I don't know if I made myself clear.



#465 quietman7

quietman7

    Bleepin' Gumshoe

  • Topic Starter

  •  Avatar image
  • Global Moderator
  • 61,914 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:03:14 PM

Posted 21 January 2019 - 05:18 PM

...i´m confused with sending an encrypted file and an original file, i have only encrypted files, i looking for something to decrypt back to original file ?!?!?...

In the majority of these cases, victims who say decryption failed or they cannot find a file usually misunderstand where they can find them or what is needed. You only need a single file pair for the decrypter to work...an encrypted file and its exact unencrypted original.

Everyone can always find a clean unencrypted copy of an original file version that was encrypted in order to make a pair...files you downloaded from the Internet that were encrypted and you can download again to get the original; pictures that you shared with family and friends that they can just send back to you; default or sample wallpapers and pictures that were shipped with your Windows version which you can get from another system running the same Windows version.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users