You are welcome to discuss various security topics with our professional team and other users like you!
Read our Registration Agreement and create your FREE account here!

*

molejas

  • *
  • 1
  • +0/-0
      • View Profile
Encrypted files
« on: June 18, 2019, 12:54:57 am »
Hello,

Our 2 servers, file and exchange 2016, were infected by a ransomware.
I want your help to tell exactly what kind of ransome is that and if I can revert the encryption of my files.
TEXT:
"All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail luciolussenhoff@aol.com
Write this ID in the title of your message 9EF7A78C-1023
In case of no answer in 24 hours write us to this e-mail:leeming.derick@aol.com
If there is no response from our mail, you can install the Jabber client and write to us in support of waitheisenberg@xmpp.jp
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files. "
How can I remove the ransomware and How cai I revert the files?

Urgent!!!



*

Execute

  • *****
  • 384
  • +55/-0
  • Your friendly neighbourhood IT guy
      • View Profile
Re: Encrypted files
« Reply #1 on: June 19, 2019, 10:33:27 am »
Hello,

Our 2 servers, file and exchange 2016, were infected by a ransomware.
I want your help to tell exactly what kind of ransome is that and if I can revert the encryption of my files.
TEXT:
"All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail luciolussenhoff@aol.com
Write this ID in the title of your message 9EF7A78C-1023
In case of no answer in 24 hours write us to this e-mail:leeming.derick@aol.com
If there is no response from our mail, you can install the Jabber client and write to us in support of waitheisenberg@xmpp.jp
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files. "
How can I remove the ransomware and How cai I revert the files?

Urgent!!!

This looks like the newest 2019 version of PHOBOS ransomware.
For information and removal instructions check the following article:

https://sensorstechforum.com/phobos-ransomware-remove-restore-phobos-files/

As to how you can revert the files, there is no decryption tool, but you can try a Data Recovery tool, although I have not seen it being effective against PHOBOS.

What you can do from now on is to backup your 2 servers on two separate locations, so at least one of the backups survive.

*

flashhmob

  • *
  • 2
  • +1/-0
      • View Profile
Re: Encrypted files
« Reply #2 on: July 08, 2019, 12:45:16 pm »
Does this work?

*

Execute

  • *****
  • 384
  • +55/-0
  • Your friendly neighbourhood IT guy
      • View Profile
Re: Encrypted files
« Reply #3 on: July 09, 2019, 03:51:57 pm »
Does this work?

What exactly are you referring to?