You are welcome to discuss various security topics with our professional team and other users like you!
Read our Registration Agreement and create your FREE account here!

*

Tangoloo2

  • *
  • 3
  • +0/-0
      • View Profile
Problem with ransomware .docm
« on: May 25, 2019, 05:07:53 pm »
I haven't seen anybody with this ransomware problem. They demand to download something like ''Tor'' browser for some link to open and install. The extension of my files is .docm
There's a full text they send me:

''All your files are Encrypted!
For data recovery needs decryptor.
How to buy decryptor:

----------------------------------------------------------------------------------------

| 1. Download Tor browser - https://www.torproject.org/ and install it.

| 2. Open link in TOR browser - http://decrmbgpvh6kvmti.onion/
               
| 3. Follow the instructions on this page

----------------------------------------------------------------------------------------

Note! This link is available via "Tor Browser" only.

------------------------------------------------------------
Free decryption as guarantee.
Before paying you can send us 1 file for free decryption.
------------------------------------------------------------

alternate address - http://helpinfh6vj47ift.onion/


DO NOT CHANGE DATA BELOW
###s1drtwhvwghhr###75 02 7E 0C 78 50 C3 C6 A9 D2 07 13 B9 DF F4 0A
91 87 45 4E 35 1D 6C 82 69 50 61 F8 EF C7 52 DE
05 33 32 5C 5F F7 B2 53 59 B4 C2 CC E9 31 B1 24
35 AE 5E C5 02 DE 94 78 21 9A 64 8C 6F A6 C2 A5
D5 07 8C CD DD 0B F6 BF A1 89 5C 3A 27 D5 D2 24
BA 23 73 EE 02 EC 4F 73 CB 78 51 2F 73 3D 8D 0E
EC FD F7 97 70 CF 09 ED 39 F2 23 76 48 DB FB 82
46 A2 34 36 46 AA 15 D1 C7 BC 37 2D B2 4A BB 03
7A C1 86 E9 02 D6 9B 19 E6 F2 9C 46 C3 44 71 0B
A7 14 81 3C DF 97 AC FB 9C 21 53 5D A5 15 38 79
8E 54 9F D5 D7 1D E6 6F D0 38 94 EA 0D C6 74 54
52 49 3A 70 75 92 7F 6D 64 2D C2 AE 32 34 B2 57
C5 C1 6D 8E F7 F2 00 A5 69 AC 5F EB B3 29 D5 C8
3A 14 FB 32 48 86 1A A0 35 01 A4 66 0D FD D0 35
5F FA AE F6 C8 6E 6F 1E D8 19 B2 3E C8 B3 2F B8
9B A7 D6 60 58 E9 84 90 02 4F 4E 69 5D AD AC 20
###
Is there any cure for my files?
« Last Edit: May 26, 2019, 02:15:17 pm by Tangoloo2 »

*

Execute

  • *****
  • 384
  • +55/-0
  • Your friendly neighbourhood IT guy
      • View Profile
Re: Problem with ransomware .docm
« Reply #1 on: May 27, 2019, 10:56:48 am »
I 've cought a ransomware with .docm extension but haven't found anyone with this problem. Is there any cure for my files?

There is a GlobeImposter variant of this virus:
https://sensorstechforum.com/docm-ransomware-remove/

There is no remedy for restoring your files at this time, but you can remove the virus with an anti-malware tool and try to recover some files with a data recovery program.

*

Tangoloo2

  • *
  • 3
  • +0/-0
      • View Profile
Re: Problem with ransomware .docm
« Reply #2 on: May 27, 2019, 06:29:11 pm »
Thank you, I will try.