SpyHunter Download and Install Instructions - How to, Technology and PC Security Forum | SensorsTechForum.com

SpyHunter Download and Install Instructions





If your SpyHunter download/install did not start automatically,

Start Your Download

SpyHunter 5

Step 1
Click the green download button above. After downloading the file click on it to open the installer
Run Spyhunter installer
Step 2
Click YES to approve SpyHunter installation
Install Spyhunter
Step 3
Wait for the scanner to finish and remove all detected threats
Scan your computer with spyhunter

Malware Detection & Removal

Detect and remove spyware, rootkits, ransomware, viruses, browser hijackers, adware, keyloggers, trojans, worms and other types of malware

Detection & Removal of Potentially Unwanted Programs & Privacy Issues

Detect and remove grayware, potentially unwanted programs, certain tracking cookies, and other nuisances. Users have the option to individually exclude these programs, if they wish

Advanced Removal Capabilities

SpyHunter’s advanced removal mechanism utilizes a customized low-level OS that operates beneath Windows to effectively remove rootkits and other stubborn malware infections

Regular Malware Definition Updates

SpyHunter regularly updates its malware definition database to detect and remove current malware threats

24/7 Customer Support

SpyHunter includes the Spyware Helpdesk, an interactive one-on-one customer support solution designed to handle any issues that SpyHunter is not able to automatically resolve

Custom Malware Fixes

Through SpyHunter’s Spyware HelpDesk, our support team can create and deliver custom malware fixes specific to the user’s unique malware problems. The Spyware HelpDesk can create a diagnostic report to be analyzed by our technicians, who can then create and deliver a custom fix that can be executed by SpyHunter


164 Comments

  1. AvatarDeepak Thagunna

    Please help me my all file are encrypt in D drive all are important for my office…… so what should i do i formatted C dive.. and install new window

    Reply
    1. Avatarawais

      my all files are encrypted by cyber Rain Somware plzz help me.

      Reply
    2. Avatararshag

      hi dear
      my pc get infected with candcrab v 5.0.4 after a wile i found that something wrong in my pc .. i watch up the netstat traffic and find 3 abnormal traffics i found them delete them and be sure that its deleted from reg msconfig startup etc .. then install a fresh version of windows and think i am safe now .. but the problem is how to decrypt my many encrypted files .. the files extension is .kuwnc ..any help ?

      Reply
    3. Avatarmarcos

      ola meu nome narcos
      meus arquivo tem Peet

      Reply
  2. AvatarVencislav Krustev

    Hello, Deepak

    We at sensorstechforum.com will try to help you but I need more information:

    What is the file extension after the encrypted files. (Examples may be .vvv, .ccc, av666@weekendwarrior55(.)com and others)

    Can you upload and send us 5 or 6 encrypted files to this email address:

    idunn0@abv.bg

    Best Regards,
    Vencislav

    Reply
    1. Avatarwilsonbataoil

      we facing problem same with mr. deepak..our admin office encrypt the virus called ransomware the they replace the exntension to .cerber. how can we fix it

      Reply
    2. AvatarJulius Hardean

      Hi, Vencislav

      please help me….
      i have problems..
      all my files encrypted be : .osk

      Reply
  3. AvatarMathieu

    Hi,

    Same problem as Deepack !! This is my computer for my work!! It is so bad !! I can’t lose all my files !
    The file extension is .vvv.
    Could you help me ?
    Thanks

    Reply
    1. AvatarMilena Dimitrova

      Hi Mathieu,

      You have been infected with TeslaCrypt. Have a look at these articles:

      http://sensorstechforum.com/remove-teslacrypt-and-restore-vvv-encrypted-files/

      http://sensorstechforum.com/remove-cryptesla-2-2-0-and-restore-vvv-encrypted-files/

      There are several decryptors aimed at encryption by TeslaCrypt. More information is available in our forum. You are welcome to join it and follow the topic about TeslaCrypt: http://sensorstechforum.com/forums/malware-removal-questions-and-guides/restore-vvv-files-encrypted-by-teslacrypt-ransomware/

      Reply
  4. AvatarMathieu

    Bonsoir Milena,

    Merci pour votre réponse, je vais essayer dès mon retour au bureau lundi…en espérant que cela fonctionne!!
    Je vous tiens informer.

    Bonne soirée

    Reply
    1. AvatarMilena Dimitrova

      Bonjour Matheu,

      Let us know if we can be of any help!

      Reply
  5. AvatarFarid Mohamed

    bjr milena ma machine du bureau vient d’être infecter par teslacrypte
    et tout mes fichiers convertis en extension(.vvv)comment récupere mes fichiers.

    Reply
  6. Avatararezki

    Bonjour Milena;
    Mon PC vient d’être infecté par Cryptowall 4.0 et mes fichiers sont désormais inaccessibles (cryptées). Y-a-t-il une possibilité de nettoyer la machine et restaurer les données.
    Merci pour votre aide

    Reply
    1. Avatarnora benseghir

      méme cas pour moi!! svp aidez moi!!

      Reply
  7. AvatarJaime

    Buenas Tardes ,por favor ayudenme,ha entrado un virus ransomware y me ha encriptado todos los archivos ,son fotos y algunos pdf ,la extension es “MICRO(micro)”asi como esta escrito ,muchas gracias .por favor ayudenme.

    Reply
  8. AvatarJose

    Muchas gracias por el foro.
    Por favor, necesito ayuda, un virus me ha encriptado los ficheros doc, pdf y xls y los ha sustituido por la extensión .ttt
    ¿ Podría ayudarme ? Mando alguno de los archivos
    Muchas gracias por su ayuda.

    Reply
    1. AvatarMilena Dimitrova

      Hello Jose,

      You can follow this topic in our forums: http://sensorstechforum.com/forums/malware-removal-questions-and-guides/restore-files-encrypted-with-xxx-ttt-and-micro-file-extensions/. You can also send us encrypted files to idunn0@abv.bg. We will see what can be done and if there’s a solution to the .ttt extension.

      Reply
      1. AvatarAlejandro Beltre

        te he escrito varias veces por mis archivos con malware .gif sin respuesta tuya. saludos

        Reply
        1. AvatarMilena Dimitrova

          Hi Alejandro,

          A decrypter is available for the older versions of Globeimposter ransomware – https://decrypter.emsisoft.com/globeimposter. You can try it but since the ransomware’s authors kept on updating their code, it is likely the decrypter won’t work. Another option for you is to try to restore your files via data recovery software as explained in step 2 in the instructions below this article: https://sensorstechforum.com/gif-file-virus-globeimposter-remove-restore/

          Good luck!

          Reply
          1. AvatarBurhan Ud Din

            Hi Milena
            I got the ransomcrab virus and all the extensions of my documents changed to .vkjsvmdpup I can’t run any of my files now. And the data is very Important to me.
            How can I get it back ?

      2. AvatarBurhan Ud Din

        Hacked by Gandcrab 5.0.4 and now all my files are encrypted and have the extension .vkjsvmdpup and I can’t open them and no one else can either I tried emailing them to a friend to run them on his computer but didn’t work. This data is very important to me, how can I get it back ?

        Reply
      3. AvatarMauricio Portocarrero

        Necesito desencriptar los archivos infectados por el Ransomware .promorad, alguien tiene alguna herramienta?

        Reply
    2. AvatarJose

      He enviado otros archivos , a ver si hay más suerte y pueden conseguirlo.
      Muchas gracias por intentarlo.

      Reply
  9. AvatarAnnika

    Tengo tantas dudas siempre de como saber si una web es buena o mala con la informacion que me da.. tengo que descargar segun vosotros el spyhunter-… como puedo asegurarme que por ejemplo esta web es real y nos ayudais en todo lo que podeis… soy muy incredula y seguro que me engañan … algun tip para discernir entre buena recomendacion y maliciosa? Mil gracias

    Reply
  10. AvatarTibone

    Hello, all my files have .micro extensions and its impossible to open open them, I heard that is TeslaScrypt 3.0 a new version, what can I do? I scanned all my pc with MalwareBytes and it seems to be clean now, but my files extension remains the same, what can I do to decrypt them? I have important files.
    Thank U

    Reply
  11. Avatarferoza

    What happened to your files?
    All of your files were protected by a strong encryption with RSA
    More information about the encryption RSA can be found here: https://en.wikipedia.org/wiki/RSA_(cryptosystem)

    What does this mean?
    This means that the structure and data within your files have been irrevocably changed, you will not be able work with them, read them or see them, it is the same thing as losing them forever, but with our help, you can restore them.

    How did this happen?
    Especially for you, on our SERVER was generated the secret keypair RSA – public and private.
    All your files were encrypted with the public key, which has been transferred to your computer via the Internet.
    Decrypting of YOUR FILES is only possible with the help of the private key and decrypt program which is on our Secret Server!!!

    What do I do?
    Alas, if you do not take the necessary measures for the specified time then the conditions for obtaining the private key will be changed
    If you really need your data, then we suggest you do not waste valuable time searching for other solutions becausen they do not exist.

    Reply
  12. Avatarferoza

    This is the above message I received with all my files encrypted. Its been hijacked and ransom is being asked with instructions.

    Reply
  13. AvatarMikeP

    Hi my customer has the Locky Encryption on all his PCs. I need help to restore his files.
    NO BACKUPS..

    Reply
    1. AvatarRaj

      Hi Mike,

      It is same problem with me if you got any suggestion please reply me.

      Reply
      1. AvatarMilena Dimitrova

        Hi Raj and Mike,

        Unfortunately, there is still no decryption method available. Follow our forum topic about Locky for updates: http://sensorstechforum.com/forums/malware-removal-questions-and-guides/remove-locky-ransomware-and-restore-the-encrypted-files/. There you can find alternative methods to try to restore affected data.

        Reply
  14. Avatarxochilt

    hola tengo un virus que esta invadiendo y ya probe con Spyhunter4 y nada no lo reconoce pero mis imagenes y casi todos mis archivos aparecen o en formato de audio.mp3 o con archivos de txt y explorer con este mensahe “Recovery+wlsbk”

    en verdad necesito ayuda

    Reply
  15. Avatarkc

    help~~

    I have the same problem>>RSA4096 change all my files and photos in to .mp3

    1 how to remove it
    2 how to fix the file and photo

    Best regards
    kc
    hong kong

    Reply
  16. AvatarViktor

    Здравейте, и моя лаптоп е налазен от RSA-4096 всички файлове са преименувани на mp3 и jpg.
    Има как да я разкарам тази напаст и да си върна информацията или да преинсталирам?
    Поздрави! Виктор

    Reply
    1. AvatarMilena Dimitrova

      Здравей, Виктор,

      Искаш да кажеш, че някои от файловете ти се преименувани с extension .jpg? Можеш ли да ни пратиш рансъм бележката на support@sensorstechforum.com?

      Reply
      1. AvatarViktor

        само mp3, моя е грешката…

        Reply
  17. AvatarMd. Anisur Rahman

    Hello Friend, I am facing .locky extension problem. my all files are encrypted by .locky extension. following details.

    Please help me how to recover my all documents to previous format.

    Reply
  18. AvatarOscar Lagos

    estimados mi archivo fue infectado por un virus que dice ser rsa-4096. les solicito si me pueden ayudar con algun programa para poder desencriptar los archivos ya que tengo toda mi informacion de trabajo y personal.

    Desde ya muchas gracias

    Reply
  19. AvatarCesar

    Hola a mi me convirtio todos los archivos a .MP3 pueden ayudarme? Gracias

    Reply
  20. AvatarAj

    My all file extensions are chang..like my video mp4 file has .mp4.mp3 my .doc file has .mp4..etc like this and my every drive folder contain some html and some png file name “_RECOVER.pnhvv”..pls tell me solution

    Reply
  21. Avatarsolana

    hola me pueden ayudar urgentemente? porfavor
    mis archivos estan inscriptados. las extenciones son jpg ayudaa

    Reply
  22. AvatarShahnawaz

    Hi Support Team,

    I have download spyhunter but it failed to installed with this error. “Setup script function call error”

    Could you please help me out as all file affected with .CERBER extension.

    Reply
    1. AvatarMilena Dimitrova

      Hello Shahnawaz,

      The ransomware may be preventing you from installing the anti-malware program. We would advise you to contact the developer of SpyHunter as soon as possible.

      Reply
      1. Avatarvirender kumar

        dear mam, my data is lost file name change .locky

        could you conform about same.

        regards
        Virender

        Reply
  23. AvatarCarles Gili

    Acabo de descargar SpyHunter. Deseo que me solucione de una vez por todas el problema de SPAM con Skype. Saludos.

    Reply
  24. Avataralseraj

    Hi dear
    My filr all.cant be open it was incrypted by thWhat happened to your files?
    All of your files were protected by a strong encryption with RSA
    More information about the encryption RSA can be foun to.the ebd of this messange
    And he ask.me to pay money to help.me
    What should i do know
    Plz.help all.my file are excel
    Xlsx

    Reply
  25. Avatarshan

    im having issues with .cerber file i dont know how to remove this my fd (flashdrive) had been infected and also my C: driver, i have lots of files including my school activities. please help and i dont want to pay 500$ and got trick.

    Reply
  26. AvatarNana

    SVP, est ce que je peux réparer les menaces détectés par SPYHUNTER sans faire un achat et merci

    Reply
  27. AvatarNancy

    Hola mi computadora tiene el RSA4096 y le agrego a todos los archivos .scrip. Es decir que los archivos quedaron jpg.script. Estoy desesperada como puedo recuperar especialmente las fotos? Gracias

    Reply
  28. AvatarAyan Baral

    I am affected by Cerber Ransomware 4.0.3. It has encrypted files on my system and the extension is .9b83. Please help me to decrypt the files.

    Reply
    1. SensorsTechForumSensorsTechForum

      Hi Ayan,

      Can you provide more information about your infection case?

      Reply
      1. AvatarAyan Baral

        There is a file called README.hta on my system. I think this file has encrypted all the files on my system to format like yudhkr23rf.9b83. So basically all my filenames have been changed and the extension has been changed to .9b83

        Reply
        1. SensorsTechForumSensorsTechForum

          Unfortunately, there is no decrypter available for this ransomware. You can still find more information about the README.hta ransomware here: http://sensorstechforum.com/new-cerber-ransomware-remove-restore-encrypted-files/

          Reply
  29. AvatarHaris

    i am affected by Cerber Ransomware , all the files are encrypted extension is .a840. The folder contains Readme.hta files.

    Reply
    1. AvatarZakaria Bq

      hello,
      i have the same probleme and i see u r the only one who has a similar extension (mine a687).
      so i was wondering if you found a solution for the probleme please???

      Reply
  30. AvatarBrothercasters

    I am affected by the red Cerber Ransomware, my files are encrypted with extension .9e96 please help

    Reply
    1. AvatarVencislav Krustev

      Hello Brothercasters,
      At this point, there have not been any flaws discovered in the encryption by this virus, meaning that researchers will not be able to create a decryptor. IF the situation changes, we will post an update on our blog and link on the article page. So you can check that page regularly, we are constantly monitoring researchers and we are checking up on the virus ourselves too. Since this Cerber ransomware variant uses a combination that not only locks your files but also locks the unlock key, things are not as simple as they appear to be.

      You can, however try to use some of the alternative data recovery methods, like

      Data Recovery software.
      Using Shadow Explorer.
      Using a network sniffer to capture traffic communication
      Using other decryptors(risky for the files).

      You can also save the encrypted files on another drive and wait. We are really sorry to hear that your files are done for, but do not give up on them and DO NOT delete them. Check this article regularly for any updates on the matter:

      http://sensorstechforum.com/remove-red-cerber-ransomwares-2017-update/

      If there is a decryptor, we will post a download link on top of it.

      Reply
  31. AvatarVictor Wachanga

    There is no doubt that guys from SpyHunter created PlusNetwork hijacker

    Reply
  32. AvatarFaheem Ahmed

    please help in Remove Plus Network Browser Hijacker from chrome Computer

    Reply
  33. AvatarJesus David Guerra

    My PC was infected with lnk.[info@kraken.cc].wallet. Will I can recover my files?

    Reply
    1. AvatarBeaver Architect

      use “Shortcut”

      Reply
  34. AvatarCosta

    Hello, Ransomware attack my computer files.

    What program I need to use to back my files, all files are with extension .WALLET.
    I don’t have backup activated on computer, didn’t notice that was off.

    pleae advice. is there decryption program ?
    Should I move all files to external drive and format / reinstall my computer ?

    Reply
    1. AvatarCosta

      I was attacked by batman_good@aol.com

      Reply
    2. AvatarHesham Zeatar

      use hern cd
      and chose open mini windoes then you can controle your pc back and delete the virous manulay

      Reply
  35. AvatarViNod KuMar

    My System & External Hard Drive has affected by the Ransomware, my files are encrypted with extension .sage , SO any possible way to recover all my data, please help.

    Reply
  36. AvatarAneta Gw

    What about google drive? All my files there were attacked by flotera@protonmail.ch, AES-256 algorithm, changing all extensions to .aes. Is there any point in contacting google. How can I recover data ??? Please help.

    Reply
  37. AvatarAbdelkader Nemra

    my files extension is .sage? how can I recover my files?

    Reply
  38. AvatarShreeji Dwarka

    do you have any solution for *.wallet extension ?

    Reply
    1. SensorsTechForumSensorsTechForum

      Hello, Shreeji,

      Unfortunately, there is no decrypter for the .wallet ransomware.

      Reply
  39. AvatarRajesh Ghimire

    how to solve mole virus all file
    !!! IMPORTANT INFORMATION !!!!

    All of your files are encrypted with RSA-1048 and AES-128 ciphers.

    More information about the RSA and AES can be found here:

    https://en.wikipedia.org/wiki/RSA_(cryptosystem)

    https://en.wikipedia.org/wiki/Advanced_Encryption_Standard

    Decrypting of your files is only possible with the private key and decrypt program, which is on our secret server.

    Follow these steps:

    1. Download and install Tor Browser

    2. After a successful installation, run the browser and wait for initialization.

    3. Type in the address bar:
    4. Follow the instructions on the site.

    !!! Your DECRYPT-ID:

    Reply
  40. AvatarTerry Licia

    OK … sounds great but after I download it and install, and actually use it … am I going to learn that it cost $39.99 to get rid of what is found? Happens too dang often, so if so … I am yanking all endorsements/shared articles From SensorsTechForum. I hate being scammed. Time wasting, no damages but TIME wasting is costly. Hope this doesn’t happen …

    Reply
  41. Avatarchristian Radlmeier

    viel besser wie avast oder avira habe über 150 bedrohungen auf meinem pc gefunden die avast nicht gefunden hatte

    Reply
  42. AvatarMoggan

    Hi can i recover using partition guru software….

    Reply
  43. AvatarMoggan

    when i run decrytion tool it tells some kind of database is missing in %TEMP% folder

    Reply
  44. Avatarchafik

    Please how can i remove virus ransomware extention . sage
    Please heplp me .

    Reply
  45. AvatarFayyaz

    please help me out my personal images and videos are infected with (.losers) extension

    Reply
    1. AvatarMilena Dimitrova

      Hi Fayyaz,

      Your initial comment was edited to remove the personally identifiable information in it.
      Please refer to this article for more information on the ransomware: https://sensorstechforum.com/remove-losers-ransomware-restore-losers-files/
      You can try Emsisoft’s CryptON Decrypter.

      Reply
  46. Avatarsathish

    Hello

    My Computer also Attached , but file Extension is .rapid

    please help me to recovery it.

    Reply
    1. Avatarrafiq

      use recovery software

      Reply
  47. AvatarRui

    id-4867BEC6.[GuardBTC@cock.li] ramsomware
    Does anyone knows how to decrypt?

    Reply
  48. AvatarROMULO SOUSA

    Olá, bom dia.
    Alguém com solução para a extensão id-98D424C1.[black.mirror@qq.com].java?

    Reply
  49. AvatarChristian Mahler

    Hello,

    id-C81F1544.[lion@discoverydayz.com].arrow

    Does anyone knows how to decrypt?

    Reply
  50. AvatarMiguel

    the extension is .arrow

    do you have solution?

    Reply
  51. AvatarAlejandro Bell

    Help!!!! a ransomwere took my computer and ask me money to give my files back. It added .gif extension to all files. I have been unable to find a solution. Ransomwere is globeimpostor 2.0 can you help me? thanks

    hola, a todos mis archivos le agregaron .gif a todos!!!!!! no soy un empresario. ellos se equivocaron. estoy desempleado. y trabajo con mi viejo PC. ayuda!!!!!!!

    Reply
  52. AvatarZahur

    Hi,
    You can use the shadow copy of your windows to recover the previous version before the attack. This is the best safest way. You can have other tool like ShadowExplorer-0.9-portable that will help to recover your previous good version.

    Regards
    Zahur

    Reply
  53. AvatarLynda Farabee

    Is there a malware version for iPhone?

    Reply
    1. AvatarMilena Dimitrova

      Hi there,

      Do you mean a version of the software for iPhone? Unfortunately there isn’t.

      Reply
  54. Avataramna bin ali

    hi my all files are encrypted and my files extension is .nm4
    can anyone here to help me for recover my files.

    Reply
  55. AvatarMohan

    Hi My PC affected by below virus and placed the text files every where.(.CRAB is added as extension to all files). Please help me if solution available.

    —= GANDCRAB V2.0 =—

    Attention!

    All your files documents, photos, databases and other important files are encrypted and have the extension: .CRAB

    The only method of recovering files is to purchase a private key. It is on our server and only we can recover your files.

    […]

    Reply
  56. AvatarSatish Aggarwal

    All my files have been added with a .crab suffix. Can u please help

    Reply
  57. AvatarADODO HENRY SHOLLY

    my all files are encrypted and leaving .CRAB extension. plzz help me.

    Reply
  58. AvatarAlex Pendres

    My comnputer got infected with the NMCRYPT ransomware. Are there any decryption tools for this type?
    Also which program is the best to be protected against the new ransomwares.

    Reply
  59. AvatarAli

    My PC has some ransomware the files are encrypted with extension as “id-56B1FDFB.[1februar@tuta.io].java”. How to decrypt successfully without losing data.

    Reply
  60. Avatarhamoudi

    hi milena aider moi s v p gandcrab v3 crepty

    Reply
  61. AvatarDave Meade

    My computer was infected and the files were renamed with a GrAnoSinSa extension. How can these be recovered

    Reply
  62. AvatarSaeed

    My computer also was affected by GandCrab V3, what should I do?!

    Reply
  63. Avatarperumal

    539788850ransomewarwd@india
    how to emove sir

    Reply
  64. AvatarJulius Hardean

    all my files encrypted by .osk….
    please help me…
    how can i fix it?

    Reply
  65. AvatarJohn Harve

    Hello, my name is Harvey and our office computer was infected and our files now have .CRAB in it’s extension. System restore was not any help. Tried reinstalling windows before I saw this but now windows won’t load. Help!

    Reply
  66. Avatarivan morales

    por favor podrían ayudarme tengo el ransware con la extensión *.*.aurora

    Reply
  67. AvatarJeffrey

    Hello please help

    My files have been encrypted with an extension .KRAD
    PLEASE help me now

    Reply
  68. Avatarola dule

    Hello, please help. my files have been encrypted with .KRAB

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello. That is GandCrab V4. There is a decryption tool released that you can try: https://sensorstechforum.com/decrypt-gandcrab-ransomware-files/

      Reply
  69. AvatarDigitrons

    please help. my files have been encrypted

    Reply
  70. AvatarLeon

    Hallo, ich habe auf dem PC den Trojan.Multi.autogenrunReg.A
    irgendwie eingefangen und suche nach einer funktion wie ich den ohne ein Programm mit Lizenz runterzuschmeißen kann. Ich verzweifel… bitte helfen sie mir BITTTEE!

    Reply
    1. AvatarMilena Dimitrova

      Hello Leon,

      Are you looking for a way to remove the Trojan for free?

      Reply
  71. AvatarDinesh

    I’m not able to download both the anti-spyware programs above..whenever I open in chrome, the browser is closing by itself. My system care has detected bitcoin.exe

    Reply
    1. AvatarMilena Dimitrova

      Hi Dinesh,

      By the looks of it, you have a miner installed on your PC which is crashing your browser. What system care are you talking about? Have you tried using alternative browsers?

      Reply
  72. AvatarDavid

    My server’s files have been encrypted with an extension .KRAB. Please let me know the successful rate to recover the files if I follow the procedures as suggested above. thank you

    Reply
    1. AvatarMilena Dimitrova

      Hi David,

      Please keep in mind that there is no official decrypter to decrypt .KRAB files. This makes any other method an alternative option which may or may not be effective. Gandcrab (.krab) is a very complex ransomware so we cannot guarantee anything. There is no assurance that data recovery software works for any ransomware. However, users who have relied on data recovery software have had partial success in recovering their data.

      Reply
  73. AvatarArnim

    Hallo ich habe einen KRAB Virus auf dem PC der alle Dateien verschlüsselt hat.

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hallo, Arnim.

      You have GandCrab Ransomware variant V4. Try out this decryptor to see if you can’t decode your files:

      https://sensorstechforum.com/decrypt-gandcrab-ransomware-files/

      Reply
  74. AvatarBruce

    I am trying to install the SpyHunter program and get a “Setup configuration scripting error”. What do I do?

    Reply
    1. AvatarMilena Dimitrova

      Hi Bruce,

      You should contact the software vendor: https://www.enigmasoftware.com/support/.

      Reply
  75. AvatarSumit

    Hi
    From last few days 3-4 pc in my office creating problem. On regular interval they are showing blue screen. firstly i think might be it happend just because of ram problem. So i changed the same but prb still persist then i changed the HDD but no gud luck. Then i think to order for new pcs for my office. but one of my client also facing the same problem in my office network. then it clicked in my mind that might be its bcz of virus.

    So plsss help

    Reply
    1. AvatarMilena Dimitrova

      Hi Sumit,

      Can you tell us what’s written in the Blue Screen note? It might be anything, and the text in the Blue screen will tell us a lot. Also, can you give us more details about the performance of the PC?

      Regards,
      Milena

      Reply
  76. AvatarJonathan

    Hallo,
    gibt es eine Lösung für einen Virus mit der Dateiendung .no_more_ransom?
    Unsere Firma ist betroffen und alle Daten wurden verschlüsselt.

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hallo,
      Das ist Rapid V1 Virus. Keine Lösung ist für Rapid V1.

      Reply
  77. AvatarFeverDoctor

    Hello.. My company pc server have been infected with combo file extension. All the files and document have been enrypted like SQLServer2012SP3-KB3072779-x64-ENU.exe.id-2A1D302C.[kingdata@cock.li].combo

    How can i remove this threat and recover the files again? Any suggestion or solution? Thank You.

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello FeverDoctor.
      Currently there is no way to decrypt your files, encrypted by this ransomware. You can try a data recovery program, to try and restore some files if the originals were deleted after encryption.

      You can try out the tool on this page for the removal of the virus.

      Reply
  78. AvatarRicardo

    Estimados mis archivos fueron infectado por un virus que dice ser GANDCRAB V5.0.2, con la extensión .LCMFOKH
    Les solicito si me pueden ayudar con algún programa para poder desencriptar los archivos ya que tengo toda mi información de trabajo y personal.

    Desde ya muchas gracias y abajo detallo la descripción que tengo ahora en mis carpetas, los archivos están pero no los puedo abrir.

    — = GANDCRAB V5.0.2 = —

    ¡Atención!

    Todos sus archivos, documentos, fotos, bases de datos y otros archivos importantes están cifrados y tienen la extensión: .LCMFOKH

    El único método para recuperar archivos es comprar una clave privada única. Solo nosotros podemos darle esta clave y solo nosotros podemos recuperar sus archivos.

    El servidor con su clave está en una red cerrada TOR. Puedes llegar de las siguientes maneras:

    ————————————————– ————————————–

    | 0. Descargar el navegador Tor – https://www.torproject.org/

    | 1. Instalar el navegador Tor
    | 2. Abra el navegador Tor
    | 3. Abra el enlace en el navegador TOR: http://gandcrabmfe6mnef.onion/cf3bf5a6b818852b
    | 4. Siga las instrucciones de esta página.

    ————————————————– ————————————–  

    En nuestra página verá instrucciones sobre el pago y tendrá la oportunidad de descifrar 1 archivo de forma gratuita.

    ¡ATENCIÓN!

    PARA EVITAR DAÑOS DE DATOS:

    * NO MODIFICAR ARCHIVOS CIFRADOS
    * NO CAMBIE LOS DATOS A CONTINUACIÓN

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello Ricardo,
      this is indeed GANDCRAB V5.0.2 virus.

      A decryptor tool is released for this and previous versions of GandCrab. You can see instructions and how to download the decryptor from this article – https://sensorstechforum.com/decrypt-gandcrab-ransomware-files/

      Reply
  79. AvatarAli

    Hey guys

    i have a problem there is a solution please i need help

    —= GANDCRAB V5.0.4 =—

    ***********************UNDER NO CIRCUMSTANCES DO NOT DELETE THIS FILE, UNTIL ALL YOUR DATA IS RECOVERED***********************

    *****FAILING TO DO SO, WILL RESULT IN YOUR SYSTEM CORRUPTION, IF THERE ARE DECRYPTION ERRORS*****

    Attention!

    All your files, documents, photos, databases and other important files are encrypted and have the extension: .BEONRS

    The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.

    The server with your key is in a closed network TOR. You can get there by the following ways:

    —————————————————————————————-

    | 0. Download Tor browser – https://www.torproject.org/

    | 1. Install Tor browser
    | 2. Open Tor Browser
    | 3. Open link in TOR browser: http://gandcrabmfe6mnef.onion/3cd8f6c45444c164
    | 4. Follow the instructions on this page

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello, Ali.

      There is a decryptor for older variants of this virus. However, I doubt that it will work for v5.0.4. Wait around one month as researchers might be working on a newer version of the decryptor.

      Reply
  80. AvatarNikola

    Hello
    Please help me, my all file are encrypt in D drive.File extension is .gdcb

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello, Nikola.
      That should be the original GandCrab ransomware virus with the .gdcb extension. You can try out the decryptor of BitDefender made for most versions of GandCrab from the link: https://sensorstechforum.com/decrypt-gandcrab-ransomware-files/

      Reply
  81. AvatarChandra

    PLZ HELP:HOW TO REMOVE:EARFLRGR FILE FORMAT?

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello Chandra.
      If that is the extension added to files then you have a ransomware virus that has encrypted your files. If that extension is random (meaning that another computer with the same virus will get a different extension/file format) this may be GandCrab ransomware.

      Try this decryptor tool : https://sensorstechforum.com/decrypt-gandcrab-ransomware-files/

      But if it is version 5.0.4, then you cannot decrypt your files currently.

      Reply
  82. AvatarRanjith Kanjoor

    I have a problem and need help. My server’s files have been encrypted with an extension .adobe.
    Please help to decrypt the files. Also cannot install any software into the Server. We tried to install SpyHunter in the server but can’t install, Is the portable version of Spyhunter available?

    Reply
  83. Tsetso MihailovTsetso Mihailov

    Hello Ranjith,

    That is a variant of Dharma ransomware – https://sensorstechforum.com/adobe-files-virus-dharma-remove/

    The ransomware might be blocking the installation of software or certain security programs.

    SpyHunter does not have a portable version available.

    Reply
  84. Avatarrenee aluste

    Hi. so today i also got scammed. i think it was a file i got from piratebay. Battlefield 5 or overcooked 2

    i can send you some samples.
    —= GANDCRAB V5.0.4 =—

    ***********************UNDER NO CIRCUMSTANCES DO NOT DELETE THIS FILE, UNTIL ALL YOUR DATA IS RECOVERED***********************

    *****FAILING TO DO SO, WILL RESULT IN YOUR SYSTEM CORRUPTION, IF THERE ARE DECRYPTION ERRORS*****

    Attention!

    All your files, documents, photos, databases and other important files are encrypted and have the extension: .MGVXJVT

    The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.

    The server with your key is in a closed network TOR. You can get there by the following ways:

    —————————————————————————————-

    | 0. Download Tor browser – https://www.torproject.org/

    | 1. Install Tor browser
    | 2. Open Tor Browser
    | 3. Open link in TOR browser: http://gandcrabmfe6mnef.onion/276b254fa6968acd
    | 4. Follow the instructions on this page

    —————————————————————————————-

    On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.

    ATTENTION!

    IN ORDER TO PREVENT DATA DAMAGE:

    * DO NOT MODIFY ENCRYPTED FILES
    * DO NOT CHANGE DATA BELOW

    —BEGIN GANDCRAB KEY—
    lAQAAORAIzk3xnM/k7jLGjpmeiPp+vrbVhkhIDSdq1WImF9XV7IiQIxaonh0ULoXhYTMYxO51m60a6ViTnQVjdtpgL2QErJl7s279RDP+OtFvmPi5ayen+jQ4D8KICu+LNVBm6ic2We9RWElHZ6nuzt8IydRFX37mg43C9cgV64e2V0w8ik0HeschD1Cvp6FSgBfXR0JaO6wGG0gS0wLSUw1n4xWtyh2EkJYBWCyHPZWSfCcyQnV0pK1KW9TbXUlTINwKHlQiIQISerJUG2DkrXB/MVpJJ1cOER8VKG9COz1CBVEoo53Nk97j0fR73s5bc4yU2Ggko+up47o9aqZbkkWS5gRcanuTBtQRnAiZpY0GqBdUuPUZljrK5p91w0Zfv4xn2ZxqYbO2sqJmByDQ5e5qwZ/xQnTEPZWMidFKJ9qQKgbn8iM+WKzl0Ye8/hFTiqiWTAU6gr8SC+0Z0rkyrPsX/yNcG9Z51iOlNFr450ehq9ZQ1JIq2WaDA9Fj416jXyjs1E6YHCRByTzQNhJ8s5x/fl0KsLDsXUeL3atPTq3qc0efqOtUC5Hm/l381SjDI3oVYNA8F7m+XK5hVe7z+SdTODk8Ld+86bN9mHfVEZIoD3u+/aFoCPMbgcWikJY+0N6Xyyp72thNAvq1mq77cdCcf3d5IftMRzmkQvOhQjFbwebzNCjae0GukifB1H9FnHbUM0lJMOfwDcjgvW2HlUyy7DK+P/8Fk3Tp+W2K8/FK6Lx2MuyknBHpEd7A43ntPma2D4I/dNm5iZgXxL8w1bUooKIHIaLvt6o3hb+/F2VgYH0+r6TEeZC/vjeMg32lKGV6bG+Enq0w8IviTj2dsuNPstH35XjyNqaWfx/vGCI5L4RPdxsLBXrw2I0KwJKGHDteHxvw+UovTs7m9eEiqpiv5aaDmDzcGxpCXEyYkr9MbbzONVtPTLXwOxp+F4nnYPv0jSXBNCIod03x3MnuHJqbMNcNYWiMYH3oNCgZWC+Glr/eVx4SVUgWvLb57ZMj2nB5btQxxI+/0cNbolv7Pstxu7BQKRsvuQgSMuCalSU/rLQBOn9vfn0luDzCFwdQwkKjzi/rLitCGuFhxs0PEC/noPlKXwd0Cr+/napytzXDoV1cWGPbNElSnWiDV/iKFjT+CEkwEJemyH1VwcJ4DbCuMzdcaefUyPmiCawHQV7t5q6B/MoZ45/dFqBDpA6ZU2eE7R3JUcjmUU6L0TtCvAFN1POvDaT4baSaAfl+ktLaLJ8aR/iBGyK++sRDKN/3sv6PTPhjQRQwCijsBd9PoI4RFGxo7RCeNH2n5D8unfEPBiaFictn8UXwRvfQEOwTnrx3GtOWi93RnoAuDOJzBUM6LSRDcW1cynYufoR6g6Se4qy6IFNM29aWeN+3lMO38H0Us9YX2B9dVJNjjS7bMLjTefCBTBN6fTIVxpLluBZ2ZiUsgQFWsf1oNFPoQp8jyZ3jHckECNayNr+KsbRkAOSIRw1/E95nTOq5lPktJjOxwTq3ks0yPx8BCt8s8rbsxaelozJu1EXb0Pzo+ul9Kf2eaNNXICzEffpMj4lzoj5DjHsF9HMK77Ey+VT1pVDAU2JuKwAkSRlp5lMzLWusFGNmPDrIZq5uB0AIfofI4LBDcvVTYLztrD2HDau6clTrJLcyCsE8zhnS9QmXDqK+eagmnJsEC0LZJrIybFHiNqIq8eRpbG6+lLrjQeYnFFQa8uHdynt2mEAxWZZ4LKScKwzq12+fgQcy9yFIK7OorbFWVU3Asfq1FW/xUJkTkBjplJYGWOcA4NbupJ7XTl2T0ZCSeT/CB7K634PgEOUsVqO4ezCt/j5ArhgtZFAIVcLBUi/pTUJqXD3Lzq2y+w92F0b26e7K89jj78EJkUjaqIMev1lPTeGmJJ1RhxxUDcaD3nDG5gJaf+slKAiteXDriI0ReH8DUNvnRcaUDw9XAkSdS6tqjz46tSkL/Oe58lkNu7lXb7ccpQBp/XNCwA5g/aayNUJeMa+Gz//lFSVs7ei254I55zn1nrScVmFhMVuxij5rr6BYA/j9N5xJoNV+cc75mmShKEA0MHRFwMF2YsFYZngwyy+zvY7X3Lo1Luu2UboVY0DhtqBQ6+qGeetubRgzOvTmIlq+iUKh3PHnKkJ2BI4/axV6kDNtVcLkKIagmOsmt9WtUEagqFuz9SKUWl72rleFIJHnhcGkpoVOatjkxAtbjg/52QPKA729aBKoDQtK/Rou4Q=
    —END GANDCRAB KEY—

    —BEGIN PC DATA—
    wfKD6iudumBkmpL8IRr4U6qxGlaiOXLtnzw0OuL12FYqvNmWPB5KYaxd5ZYqToVRu3YR7n1WoLezTFGHwx5FBJjzntMK77r6TUHaDB7iIpJD8/bFAv/9mGGoBpAZLv6j1vxN2QfxHpKSioOhX0ScArEAnLYFOOOX+LnRbRYkenQ0bbeWp8CvYZdYTaTcxsIpGI5g2+eAd1LxZAtV4gP0uUXcPiJv2PCMd0PrMOAP2IpOLGGTBpxdmt4oT3Z/P+o/bvrK1slzgDbqjdhAB3hvl8BnB912CCQxeg7GDMUr8315SmnFVg/vke4tbdiyqdynn7r657Rip7F/kQDB5uKg/3A2U+t3GoVYL1rcBnrtwhGPEY0brCcQ4t64PaazY8lybIyn2S2ikJQdTWYqaFO3JNMJ8JE8wMQoXBOcnPs+B+4sALWf+2FPg8RrXQ2dxGFKwQ71ZinpDhFN3vXLMeav1wYZN3QRRleKYznQ1lHgdH8ImU7fnSz7QUhnnrIols+w63ISVfrpdjeCfG0cFMAWPwJN7X9XQ3HC36ZGEuDtJEipBY9MZJHzHoUOfb/LRdoPpYl7V6Tu4LPLzMT9JHZwh8QznewxRZVtK/+ublDWt+IYXpleMtQu9EBhPlLc2rpglWnYLVczhgsDfm/5H2FXiTkEy7IGT7XbFwF0Kd//yTN9dCw35m4IfamU4HJgLea8GR1LXfkDKNZ7jXPfkwqZwiMum8U8mM3gnIq2Oj5tSSskDm5IqxtIYAECsbxGZk8y58tHO5+lJ0+NrupOyo88Q+zDgO6m4+7l
    —END PC DATA—

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello Renee,

      there is a decryptor for older variants of this virus. However, I doubt that it will work for v5.0.4. You have to wait for a decryptor update if it ever gets released.

      Reply
  85. AvatarThythy

    Pessoal peguei o virus pdff alguém poderia me ajudar pelo amor de Deus???

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Hello Thythy,
      I don’t see what the problem is – there is a decryption program given in the article’s Update January 2019 section: https://sensorstechforum.com/pdff-ransomware-remove-virus-infections/

      Download and install it – it should work.

      Reply
  86. Avatarwibowo

    hello .. I found all my files changed to the extension .rumba file.
    What should I do? thanks.

    Reply
  87. AvatarMunawer

    My PC got effected with GANDCRAB V5.1. Anyone have a solution. My office files are there.

    Reply
  88. AvatarMauricio Jaramillo

    Hi Milena & Vencislav

    May i send to you some files of my case encription to idunn0@abv.bg ? my files encripted have extension .BIP.

    Hope you can help me. Regards.

    Reply
    1. AvatarMilena Dimitrova

      Hi Mauricio,

      Unfortunately there is no decryption tool for this version of the ransomware. Even if you send us files there is nothing we can do to help you.

      Reply
  89. AvatarChandra

    Hi,all my files got extension of EARFLRGR
    dose any1 know how to remove them.

    Please Help.

    Reply
    1. AvatarMilena Dimitrova

      Hi Chandra,
      Sounds like you have been infected by GandCrab ransomware, most likely the 5.1 version. Can you tell us more about your case?

      Reply
      1. Avataraseel

        i have attaced by GandCrab v5.1 plz help me .

        this is the extension : .PNWTI

        and the massage is :

        —= GANDCRAB V5.1 =—

        ***********************UNDER NO CIRCUMSTANCES DO NOT DELETE THIS FILE, UNTIL ALL YOUR DATA IS RECOVERED***********************

        *****FAILING TO DO SO, WILL RESULT IN YOUR SYSTEM CORRUPTION, IF THERE ARE DECRYPTION ERRORS*****

        Attention!

        All your files, documents, photos, databases and other important files are encrypted and have the extension: .PNWTI

        The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.

        The server with your key is in a closed network TOR. You can get there by the following ways:

        —————————————————————————————-

        | 0. Download Tor browser – https://www.torproject.org/

        | 1. Install Tor browser
        | 2. Open Tor Browser
        | 3. Open link in TOR browser: http://gandcrabmfe6mnef.onion/6f470055924c9939
        | 4. Follow the instructions on this page

        —————————————————————————————-

        On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.

        ATTENTION!

        IN ORDER TO PREVENT DATA DAMAGE:

        * DO NOT MODIFY ENCRYPTED FILES
        * DO NOT CHANGE DATA BELOW

        —BEGIN GANDCRAB KEY—
        lAQAAGtuYbBpIaCYO17CA49q6/LqvtpuPBrKGxHhamxKDfGSv4KM5CNHzp2wcYy+u1Chx48h1Vmxy2qcSwZvXVVrfAD16B9zQGG4VY7cUObXKiJQ5yUzNCRs5VWSGLSFclCc8gvYeBzvO0OLus6y0vW13vdHqqgy+oAPOJwB3GfPAHJk25t1X/4gdtRSkNwu3AKbELxQnfAQ/lPNfGTM840KAm2Cy/nL6mvg3sKyLnYd4OP1CHQKgtJ3O7QR8jKoVPWm8qDLtY8UsrrxgnGbD+2LghPvHvqj5zFdGqIAoWUQRVtuRv6BhmHbS068w1/C0pXvC77t/siAJBLUSvnp3rh3LoeK8vc6PeHROmOgK4Wq5x2nbhLG1lWzFo1AYAJGiw3FTibKV+Rpqt2j99bo4SSB8hiTBLCRxBh8ti7pmnbctW/DJ/MF//2mh5gpkhYrn4X3H+iN0/t7/6yeHeN8R8EcTo8iLL0UfNI9FK3MJeMA4vJtn1eR5D4/im7seLbPZni2CzL5HchAsBxWAFEqBbEL7HJisiQYBB5RMkhtivfosn3RTrwuGQEWRXcuVfdiR2gEd2CZkzQIqXGqNn0gBsTH8mxP78L1FkYDmNrhhA5kNns9e1Cjf6i1ZDm7YAsMCI2rbwINq6u3CVTCGx6spE2w18RoRpVL0rcA87fhODlCwOA8r+4nfRB2LzKDGBL7+lECeQ4IIwmlb9vPFDlpXIFAc+xf/VOpNC6DVhPYC0853Ho/T9NNJGjMPUcuw/UWoYGXr9X1g4bCVoOhi0qyrqIx+zgatVUefFv1yMQ57xWk4IQpTb82X/Lh9pf1r5TR9NPJY5SZm7cLt4rQHD7mMORp2Ly22aYHdWa/rkmjDsASISrciVNms8MFPb/3fFov087lTsHlcbb2IkjnZ8HVdl4IiAs2s1/aIpNK4seeBP8I0BlJGt6JO3v52Z2TwoFZMEzIvj0v9ozG0ExKu02HQgxkffd9TROc+HBK4LLASuTZ0Hl0LMAJQgbyAxZMyJggjgp6VH93H5sHwPWjNhm78zmMqwSg0MJEDJ+IN38uymi4nxEJtJoTaxr5SOr5qE58u/Pj3o+rSk57EBtpF5P00QWsfWMBpa7demo4LskXbzzSmOPOzwkBvufTbMQeK1XwFOKpxj0fmRVs37IuRuZs0XI35y18BHdkAcnu4xN3GvJOG25El9T12gEbkwDDQWednBOIoClufhhNvh3q42260Z8YcPXCKuBJH5OdSSANcsQVLkpOCDkForyTST+S46Zvbd7ewLlA+vKh6qdJmpLKU2l9P7VLBzlNr+/AGBYVL0EpgMwMepKlCf227Rv5sDTPrV9B6gO2AOnDKzkqrsvwiDdPUdRbk7TAznGy9H1CpJmNl3Jjyddmbh/BTBbG/fQiGFEXI/W/x1vgcbczgjmy0jVIk7S66owmQDBFujJygpmnzqMTQvjTjOh1AZyZ9jo5uxxoKq4V7Caz1c/o4ifh2MgU4kD9BjbqdM6TJGYcyXm7/EocKUS1XgzLEfZYvbmB7d81v9D+QSAE6vnQUO883+M92ycQn/M+/hR3cTGKtJlyFfuxIKs4NQcxh76wdomAfDAOcjInNiB0yKZEaSkcgDr/dPZIcTrfjJIXrWLw436fauuzp2UAMD8Ca3DM6QM2fS4+c3wDCvck3ydbKjzpTplwuwWv6gCGXFCpcrbXBKAlCCtfVelexpim+k65ligfZJ8MpqlnFE8EFzBy3Jz4XyPhe+hbodOI13bdOMhKaPAGEV+BGT+uGbA9RDx9TTH5iUwX21GL+mkl/T8U0T4/m8NS5w2tpLfQYQtZMwMzTaR4j5E7pwi7t7k4gpNNC6mr/cv7H9RR31PnTx3YPY5Hl8rDJ8WTbNpj8Qlmc92rRc2vWJMXkkcv7w+Bim8Ohbgh4s7CtAP/L6sSGpjxfi0VqOrLroJ/TpvzY3RcLfppbhFDbc1M5KVRog3qowPz9ouhFv51/IlHAJz5kX4e81449nyJho0kbFh7FOpYAQeuEDkq8SCuHZOa5gVyggQOUnvqHf2p8FJqmejvnH3YOxM9bkDROhZMghC6rod6diunLbIuq5ArZysqTt//b//Cx3UKbR6jzkALeycr7m1wamPZ+9vcbD3AFZp59XYt1Ui2M7NtnKLPSoBY74FuM0wqwXXitDWpTVCWh9Gr2H/zI/nFAdts8XSB+T5Gdau9eG1qxPpd9hVkXrXVvPd8TuVtKYLNU/P5u7qmWX0=
        —END GANDCRAB KEY—

        —BEGIN PC DATA—
        7ftDEgLb/ZS0lcmZbHM61KXJ6QO2D/gKvw6PbtYgV3YCWPMC6p+aYGVxBWDf9PHJGZCnAuCVoODTRWDIWHQoQwiarrPYzrMSaOhjauuXqqaJGKcpfEuRImaggcQxqjTspUgjXSBiCMFwiXb/mVL0WqdHBCPTMqf7pyZoO8A3r2a40K0RSPodErXB3tlQsteHOvUvIOp0UINbA040E67YDK9FziOIB8UmLrF7Z+nMNN28gAj2553+UxZ7kdxkWKcyoYW/5yRHEXKxMM2ByVDlemWo11rwnM+ZoF9dSRnO3jB2mOf74YDhGBIpUaitRXUVY/fI0xdSRSCatOeJEtBUBnBqo8Y4R7a3NbHLmdSRjEeFP9zy9fNnLLDjCqPrrwFWtuZ1T1bJh/bhL2J0tff8Sziz9aBToVvF253wPF+x5ChCudnoMFoD6iWVyempqBtvY7wGrsQypy8F1fylVzmR7qp4Aew7gTCwMkzab44fzNxaLR6j0bi6wCnihDOwKP6gho2bWK3+7AkRvCuiioFbEvlEsSMxAMXhxNQVIEf1WEGfye+MZp0A1gw/8OQUe20ExHTuCujrHdcxPCKVXMpcLsEb9AmZcCuV8rDCEcisErTUnIGaYUInb5c0+VHIc23S0aJeDE/FkoGtqF9w0EbXxJXG6XVYm+/KN/NnEpudV5j7zhFfA7oH7w42mF+IdGF8o5KsQFpjql1vytzw8lzJuuRBOA4tyUZuPcZyGAVsVOBpu3zqEaf+as1M7XVHDWIYTMSoLfTUyH8=
        —END PC DATA—

        Reply
  90. AvatarCristian

    Hola, que tal? todos mis archivos estan encriptados con Dharma ransomware y tienen extensión .frend

    hay un txt con nombre
    FILES ENCRYPTED
    que dice “all your data has been locked us
    You want to return?
    write email workresewalt1983@aol.com or FobosAmerika@protonmail.ch

    se pueden llegar a recuperar ?

    Reply
  91. AvatarCristian

    Hola, que tal? todos mis archivos estan encriptados con Dharma ransomware y tienen extensión .frend

    hay un txt con nombre
    FILES ENCRYPTED

    se pueden llegar a recuperar ?

    Reply
  92. Avataraseel

    my files got extension of .PNWTI
    dose any1 know how to remove them.

    Please Help.

    and the text is :

    —= GANDCRAB V5.1 =—

    ***********************UNDER NO CIRCUMSTANCES DO NOT DELETE THIS FILE, UNTIL ALL YOUR DATA IS RECOVERED***********************

    *****FAILING TO DO SO, WILL RESULT IN YOUR SYSTEM CORRUPTION, IF THERE ARE DECRYPTION ERRORS*****

    Attention!

    All your files, documents, photos, databases and other important files are encrypted and have the extension: .PNWTI

    The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.

    The server with your key is in a closed network TOR. You can get there by the following ways:

    —————————————————————————————-

    | 0. Download Tor browser – https://www.torproject.org/

    | 1. Install Tor browser
    | 2. Open Tor Browser
    | 3. Open link in TOR browser: http://gandcrabmfe6mnef.onion/6f470055924c9939
    | 4. Follow the instructions on this page

    —————————————————————————————-

    On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.

    ATTENTION!

    IN ORDER TO PREVENT DATA DAMAGE:

    * DO NOT MODIFY ENCRYPTED FILES
    * DO NOT CHANGE DATA BELOW

    —BEGIN GANDCRAB KEY—
    lAQAAGtuYbBpIaCYO17CA49q6/LqvtpuPBrKGxHhamxKDfGSv4KM5CNHzp2wcYy+u1Chx48h1Vmxy2qcSwZvXVVrfAD16B9zQGG4VY7cUObXKiJQ5yUzNCRs5VWSGLSFclCc8gvYeBzvO0OLus6y0vW13vdHqqgy+oAPOJwB3GfPAHJk25t1X/4gdtRSkNwu3AKbELxQnfAQ/lPNfGTM840KAm2Cy/nL6mvg3sKyLnYd4OP1CHQKgtJ3O7QR8jKoVPWm8qDLtY8UsrrxgnGbD+2LghPvHvqj5zFdGqIAoWUQRVtuRv6BhmHbS068w1/C0pXvC77t/siAJBLUSvnp3rh3LoeK8vc6PeHROmOgK4Wq5x2nbhLG1lWzFo1AYAJGiw3FTibKV+Rpqt2j99bo4SSB8hiTBLCRxBh8ti7pmnbctW/DJ/MF//2mh5gpkhYrn4X3H+iN0/t7/6yeHeN8R8EcTo8iLL0UfNI9FK3MJeMA4vJtn1eR5D4/im7seLbPZni2CzL5HchAsBxWAFEqBbEL7HJisiQYBB5RMkhtivfosn3RTrwuGQEWRXcuVfdiR2gEd2CZkzQIqXGqNn0gBsTH8mxP78L1FkYDmNrhhA5kNns9e1Cjf6i1ZDm7YAsMCI2rbwINq6u3CVTCGx6spE2w18RoRpVL0rcA87fhODlCwOA8r+4nfRB2LzKDGBL7+lECeQ4IIwmlb9vPFDlpXIFAc+xf/VOpNC6DVhPYC0853Ho/T9NNJGjMPUcuw/UWoYGXr9X1g4bCVoOhi0qyrqIx+zgatVUefFv1yMQ57xWk4IQpTb82X/Lh9pf1r5TR9NPJY5SZm7cLt4rQHD7mMORp2Ly22aYHdWa/rkmjDsASISrciVNms8MFPb/3fFov087lTsHlcbb2IkjnZ8HVdl4IiAs2s1/aIpNK4seeBP8I0BlJGt6JO3v52Z2TwoFZMEzIvj0v9ozG0ExKu02HQgxkffd9TROc+HBK4LLASuTZ0Hl0LMAJQgbyAxZMyJggjgp6VH93H5sHwPWjNhm78zmMqwSg0MJEDJ+IN38uymi4nxEJtJoTaxr5SOr5qE58u/Pj3o+rSk57EBtpF5P00QWsfWMBpa7demo4LskXbzzSmOPOzwkBvufTbMQeK1XwFOKpxj0fmRVs37IuRuZs0XI35y18BHdkAcnu4xN3GvJOG25El9T12gEbkwDDQWednBOIoClufhhNvh3q42260Z8YcPXCKuBJH5OdSSANcsQVLkpOCDkForyTST+S46Zvbd7ewLlA+vKh6qdJmpLKU2l9P7VLBzlNr+/AGBYVL0EpgMwMepKlCf227Rv5sDTPrV9B6gO2AOnDKzkqrsvwiDdPUdRbk7TAznGy9H1CpJmNl3Jjyddmbh/BTBbG/fQiGFEXI/W/x1vgcbczgjmy0jVIk7S66owmQDBFujJygpmnzqMTQvjTjOh1AZyZ9jo5uxxoKq4V7Caz1c/o4ifh2MgU4kD9BjbqdM6TJGYcyXm7/EocKUS1XgzLEfZYvbmB7d81v9D+QSAE6vnQUO883+M92ycQn/M+/hR3cTGKtJlyFfuxIKs4NQcxh76wdomAfDAOcjInNiB0yKZEaSkcgDr/dPZIcTrfjJIXrWLw436fauuzp2UAMD8Ca3DM6QM2fS4+c3wDCvck3ydbKjzpTplwuwWv6gCGXFCpcrbXBKAlCCtfVelexpim+k65ligfZJ8MpqlnFE8EFzBy3Jz4XyPhe+hbodOI13bdOMhKaPAGEV+BGT+uGbA9RDx9TTH5iUwX21GL+mkl/T8U0T4/m8NS5w2tpLfQYQtZMwMzTaR4j5E7pwi7t7k4gpNNC6mr/cv7H9RR31PnTx3YPY5Hl8rDJ8WTbNpj8Qlmc92rRc2vWJMXkkcv7w+Bim8Ohbgh4s7CtAP/L6sSGpjxfi0VqOrLroJ/TpvzY3RcLfppbhFDbc1M5KVRog3qowPz9ouhFv51/IlHAJz5kX4e81449nyJho0kbFh7FOpYAQeuEDkq8SCuHZOa5gVyggQOUnvqHf2p8FJqmejvnH3YOxM9bkDROhZMghC6rod6diunLbIuq5ArZysqTt//b//Cx3UKbR6jzkALeycr7m1wamPZ+9vcbD3AFZp59XYt1Ui2M7NtnKLPSoBY74FuM0wqwXXitDWpTVCWh9Gr2H/zI/nFAdts8XSB+T5Gdau9eG1qxPpd9hVkXrXVvPd8TuVtKYLNU/P5u7qmWX0=
    —END GANDCRAB KEY—

    —BEGIN PC DATA—
    7ftDEgLb/ZS0lcmZbHM61KXJ6QO2D/gKvw6PbtYgV3YCWPMC6p+aYGVxBWDf9PHJGZCnAuCVoODTRWDIWHQoQwiarrPYzrMSaOhjauuXqqaJGKcpfEuRImaggcQxqjTspUgjXSBiCMFwiXb/mVL0WqdHBCPTMqf7pyZoO8A3r2a40K0RSPodErXB3tlQsteHOvUvIOp0UINbA040E67YDK9FziOIB8UmLrF7Z+nMNN28gAj2553+UxZ7kdxkWKcyoYW/5yRHEXKxMM2ByVDlemWo11rwnM+ZoF9dSRnO3jB2mOf74YDhGBIpUaitRXUVY/fI0xdSRSCatOeJEtBUBnBqo8Y4R7a3NbHLmdSRjEeFP9zy9fNnLLDjCqPrrwFWtuZ1T1bJh/bhL2J0tff8Sziz9aBToVvF253wPF+x5ChCudnoMFoD6iWVyempqBtvY7wGrsQypy8F1fylVzmR7qp4Aew7gTCwMkzab44fzNxaLR6j0bi6wCnihDOwKP6gho2bWK3+7AkRvCuiioFbEvlEsSMxAMXhxNQVIEf1WEGfye+MZp0A1gw/8OQUe20ExHTuCujrHdcxPCKVXMpcLsEb9AmZcCuV8rDCEcisErTUnIGaYUInb5c0+VHIc23S0aJeDE/FkoGtqF9w0EbXxJXG6XVYm+/KN/NnEpudV5j7zhFfA7oH7w42mF+IdGF8o5KsQFpjql1vytzw8lzJuuRBOA4tyUZuPcZyGAVsVOBpu3zqEaf+as1M7XVHDWIYTMSoLfTUyH8=
    —END PC DATA—

    Reply
  93. Avatardjelmen

    Hello, please help. my files have been encrypted with udjvu haw to restore my files

    Reply
  94. AvatarFrancesco

    Buonasera,
    siamo stati infettati dal trojan GandCrab 5.1 lo scroso 28 gennaio 2019.
    Non sappiamo come, ma sul NAS dove erano contenuti tutti i backup, le cartelle sono scomparse!
    Abbiamo fatto analizzare il NAS da una società, la quale non è stata in grado di recuperare eventuali copie delle cartelle cancellate o sovrascritte.
    Abbiamo n. 2 server completamente infettati, con tutti i DB dei dati contabili.
    Abbiamo l’azienda in ginocchio, se avete delle soluzioni, contattateci per favore.

    Reply
  95. Avatarzolbo

    Hello My best files infection rumba Ransomware virus help me
    How to Restore Files Encrypted by this virus

    Reply
    1. AvatarMilena Dimitrova

      Hi there,

      Fortunately, there is a decryption available for all the files, encrypted by most of the STOP ransomware variants. If the .rumba variant is part of the STOP ransomware, we would strongly recommend that you see the decryption tool for STOP ransomware to try and restore your files. It is available in the last section of our article here: https://sensorstechforum.com/remove-rumba-files-virus/

      Reply
  96. AvatarMauriciaze

    Hello
    Hi, my computer has been infected by Gandcrab v5.1 . All my files got extension of PWHTV

    Does any one know how to remove them and restore the files

    Please Help.

    Reply
    1. AvatarMilena Dimitrova

      Hello,

      Sorry to hear about your infection. Unfortunately, there is no decryption tool for this version of the ransomware. You can remove the ransomware using an anti-malware program but there is no option to restore your files. More information about the ransomware: https://sensorstechforum.com/remove-gandcrab-5-1-ransomware/?%D0%B4%D0%BB%D0%BD

      Reply
    2. Tsetso MihailovTsetso Mihailov

      Mauriciaze and ALL GandCrab victims – a new GandCrab Decryption tool was released today by BitDefender which works with GandCrab 5.1 and other of the newer variants. Download it from here: https://labs.bitdefender.com/2019/02/new-gandcrab-v5-1-decryptor-available-now/

      Reply
  97. AvatarMartin

    En ce qui me concerne, tous mes fichiers sont aussi cryptés. Ils se terminent tous par:
    Ink.fil_recovery@mailchuck.com.gj3l

    Je suis vraiment découragé …

    Reply
    1. Tsetso MihailovTsetso Mihailov

      I do not recognize this ransomware – can you share more information? Do you see any text file as a ransom note?

      Reply
  98. Avatarnamalom

    my computer is encrypted some files are named name.qlbfg and some other are
    named name.hocid and at folders i can’t see any thing just this txt file belowe

    —= GANDCRAB V5.2 =—

    ***********************UNDER NO CIRCUMSTANCES DO NOT DELETE THIS FILE, UNTIL ALL YOUR DATA IS RECOVERED***********************

    *****FAILING TO DO SO, WILL RESULT IN YOUR SYSTEM CORRUPTION, IF THERE ARE DECRYPTION ERRORS*****

    Attention!

    All your files, documents, photos, databases and other important files are encrypted and have the extension: .QLBFG

    The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files.

    The server with your key is in a closed network TOR. You can get there by the following ways:

    —————————————————————————————-

    | 0. Download Tor browser – https://www.torproject.org/

    | 1. Install Tor browser
    | 2. Open Tor Browser
    | 3. Open link in TOR browser: http://gandcrabmfe6mnef.onion/a3d31fcf4a321236
    | 4. Follow the instructions on this page

    —————————————————————————————-

    On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.

    ATTENTION!

    IN ORDER TO PREVENT DATA DAMAGE:

    * DO NOT MODIFY ENCRYPTED FILES
    * DO NOT CHANGE DATA BELOW

    —BEGIN GANDCRAB KEY—
    lAQAAFawjiTukNEj+BF54wj5LUBlsLv2tEELZRbgvVkLLCZn2jtoM2CyY0B0ym5qoZKNd01LN51z65H6OVMGVV1n5ORbQXVum53jfswpKRH6U+9/K+nxihj2qvoqWZnw5boBpT7zH+ANRJR9w/Y5HK23qvEijLV6Z3uO2mWNEHHXGMZYJQkMXMwKpaTpfvi5UDBwrcvLptUDTuDDo5eAeeRdulrzgX4MhAIs+YQEElQcs8yngCuThVOCGbloaa+o8UCSfVu55NOs6CJxBdoDugkI+QQq9IiiZt0Db6sS7deozvpoShQmqQDzxKu0UUbN/BVwv+KeSFMQ7vm7IgNq8FvXt0qGpqN92kzB/3LcKgdQkFGMi3LRcZUjG4gdVkjATNNqEkWsTbPz4qOe8FnkFkNmML2X/sIkh0CvML9UOdFJSMPS9HIRlBbGlW2eCC7eP9af9QqW5inQ90zhE0wDSBgiB1nWW5uNkl9z9eKL3hSHBvXuhNCORacbWNzg8Ta4rXjJfUfz0y4DBod+z+AZJ21CDMTIQOgaLtR531moBLB87hdUqy290KxyAKQd4pRyJ3sW29SdfZu5EliiLm3TVNmFnx78MEoThEvF7I40t2pps5Gf06U1Moe1+zmKd+olNFs2um8k2t52gPDKIMg5GxVYyeHey6W2cTaYt09NLx7mrjzW0KdtaTKHVhSL9h7z2QgeWngfaaySLn3yc3MuVy7Ewp28gaPaBw3TNYHTD4yFFwuIQrVeE6OB/3vD1E+s4jsH33G3w/uJnzq6MvJsvFCVVZxCS8qKqUWfauNhjMuX2l489nF6CRiVqQk02SuvyldHaXi31p1ipiRnL2K2722FII9sRMmFzyzEN5WGC+SbwGIPSE9jA72kjqNs76ZYjlerVPoKci5WOXY9/CNv7Vsgzix7ZU8ASYyQNqvVR1LUaodRc4aJgd4FTtG6CyePBrWkV5NuhZs2vkpDYrFvmeZy4lYpCYC/Ep5Q546eSn0asr4jx+0+ufef+0TPeKMHiWynSOz/WjSFFxbSofrYD3M9lknCdE2xeCGPni20HhhO2w9+yxBR8zghF/ufLNdNyvlOnmRtq2BxPTzOslyRInwt7R3PH1+GnBNBouNzyEHevGnru4K2cnFiqPjSePbA3R1zU1tTsI5N4ZuP8Ok1q1NLUsj/gwK2GzBi3SfvqQXhJ5JGzkt8fGR9thBlO863foMFEhb7hzshJ5Vi2pH3aWlkWYN3YkcxSqimWek7aoDNayqoxlWxjmbEJff1ZWXmeM+/r0HCL97jwq7XYnT0iVunEiqtsJaTb+5TER1cnFC4PFv+LfiBVLsK9T+JGVMchJgjwKsigaVt3KBNqChf9Lu1t2nrZPdCIPsiXppyVbmrm9U6HuinxSBfLyj5DzLgNHVZGedwtEN1m4Knd0WKvMw3tpS0dcHSeLL6dhJVzmL5dFKD9rPyOykU7kg3kCQLAUoGDyw2uuR5tn0XFttno27IycZHQ/YI8da00nVbT2fNuLtRcPxbJiVumpjjKPzsBwrEXH/FM3mB89Y/2lfFCLUb5h3fF1igD06j1GYK5m9IcIV0Ix0pxnsUBISiO7ZDDaE+0eYln3vUqKkT0zYMM9/LfeSNVYJasx3/wvALRQxa+34mVZs33Qg8ttMV0utbSM4Hq38ZMO1+6TG21qp850HUfBCzy+Hf/7CaaxfWAxy2ABVk03TlHNJoucZ8yhXBK1I5/u8pizPVOr1ljVU2OGPI1TIvhunym5QmCb1/xQtfFKVRsRsJDYn1sX6gZnaIYx0bw8+w4OD3LsHN2D8ZeS+E3puUz6tp95ampygygXIvESRVYvw8hrfVPi2ntAa4b0dygTTauy/I7wAVTXNT1Ch7fDVtILWiSfBtWj+z7wSzysoSXgjQaq8EziFu00NSAUf/gCtHrh5Zl6bZcXs019nd6ta5wHDytvkOba0cy5yBNuj2awNNEBH2N3st8dY3O6FbFUOAppJjQuEPYm9CWWtpp+jE1v/gUmNgveyrAw87zdBcERSaGz5SQtbhUJZ+Hay6cVE1p0RNhtZQ9lWAmtU97kkVlQTdpL1EXuXLeKWOcrtFCs5h8igY/vfB1r+r+Pmb6uEzGumeXQ1IyBNWLgEfsuX/Gk+ju8oMxlwjH8ASbykKTM+yuRZ2ZpsylaoQLHqiBFWORUt1uw03esvuY/8vNamDe834ak206dmT//hrHzFZN9lST7SvwPnTMsFxmwrRHe6EZEI=
    —END GANDCRAB KEY—

    —BEGIN PC DATA—
    7ftDEgLb/ZS0lcmZbHM61K3J6QOtD7cKjA7absMgUXYxWLsC+5+UYF9xVmD69NnJL5DRAvCVquDQRQbISXRUQxyatrOgzrMSCeh2aqKXn6bkGOYpfkudIkyglsR+qgzsn0gBXVZiGMFtiWv/h1LjWtNHOyPlMqj77SZ5O803l2bp0KkRSPpXEt3B7NkEsoqHCvUxIKd0RYNBA3M0Ra6NDPBFwyPGB6omZbF1Z/DMBN2jgFT22p34Uwp7yNxcWLkyvIX753pHVnLiMKiBllCheiCo9VrynNKZ719BSQ/OpzB7mP37yoC+GAMpE6ikRSsVJ/ed019SRCCUtOSJPtBSBnlqwcZnR7S3PLGdmdeR2EeDP9jyqvM2LOLjXaOzrwtWt+Z9T0LJ3PazLyB04PfbS2azjqBZoTnF2J39PFixlig2ubfoNVoP6iWVy+mhqBlvZrwBrtMyoC8H1f6lQDmW7qx4B+w4gTiwNkzbb5sfsNxWLWCjtLinwFbihjOmKJSg8o3rWMv+7QkSvCmijYFbEvlEsCM9AN3hxtQXIEb1T0Gaye+MZp0I1g0/8OQQe24E3nSZCuTra9dUPDyVI8peLtcbngntcFuVlLDEEcqsErTanICaZUIjb5w071HLc2DS16JADErFkYGhqFlw3UbVxJXG7XVPm7DKY/N2EuSdXJiJzn5fKLo37yg2mF/QdDV8rpKlQFpjqV1xyp7wr1yPuq9BZw52yQduOcZ3GBpsVeB2uy/qR6e+apxMtHUZDWcYCcSgLfzUmX+LaPgeZd3LiBJ7Atr3fEU9tt2FxK1J+epVhax2TkkTzokkfsLqe6GYIz0GwIrWpTmYJPCnrOebK1PvwycDnIpSoEC2uJB2YUvNY9am
    —END PC DATA—

    Reply
    1. Tsetso MihailovTsetso Mihailov

      GANDCRAB V5.2 is the name of the ransomware, as also clearly stated in the ransom note. It is quite new and there is no solution for it for the time being.

      Reply
  99. AvatarTrusu Razvan

    I was infectet with gandcrab v5.2 . The extension of encypted file is .aduwulqg . My antivirus Bitdefender does not recognize this tipe of infection . The recovery and decryptor from them is not working , is not recognize the extension. Do you have any ideea of how can i restore the files ?

    Reply
    1. Tsetso MihailovTsetso Mihailov

      Unfortunately, this is one of the worst viruses your computer can get infected with. Newer versions come out daily. The v5.2 variant is still not decryptable. The BitDefender decryption tool works with all other variants – 5.1 and below, but not with 5.2.

      No solution for recovering the files at this time.

      Reply
  100. AvatarAndres Sierra

    hello, can you recommend some tool to decrypt files infected with the .ETH extension?

    Reply
    1. AvatarMilena Dimitrova

      Hi Andres,

      Unfortunately, no official decrypter for this ransomware is available at this point. You can read more information about it here: https://sensorstechforum.com/remove-eth-files-virus/

      Reply
  101. Avatarmicke

    I just got the gandcrab 5.2 on my server ! it is the worst shit i evver com a cross !! :/

    hope soon there will be a decrypt tool against this !

    Reply
  102. AvatarFreddy

    Muy buenas tardes podrian ayudarme los archivos de la unidad D : / de mi equipo se infecto con un virus y todos los documentos de word tiene una extension diferente a la que estaban grabados por favor especial me brindarian su ayuda gracias….a continuacion se los describo
    Archivo: PULSAR1(pulsar1) y son docuemntos de word pero no puedo abrir ninguno de mi carpeta les ruego ayudenme con eso…

    Reply
  103. Avatarjavier

    PROMORAD2 es la extensión del virus. Habrá solución para sacarlo? y asi recuperar mis archivos

    Reply
    1. AvatarMilena Dimitrova

      Hi Javier,

      Here’s more information about Promorad2 ransomware: https://sensorstechforum.com/remove-promorad2-virus-files/
      Unfortunately, there’s no decrypter for it so far.

      Reply
  104. Avataramrith

    hi there

    all of my files are ending with a .rectot file extension . i ahve so much old stuff i was holding onto like wedding pictures etc that i cannot access.please could you tell me how to recover them

    Reply
  105. AvatarMohsin Khan

    Hi Guys,

    Please help me getting all file infected with .horon file extension and it shows this message everywhere in read me file :

    ATTENTION!

    Don’t worry, you can return all your files!
    All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
    The only method of recovering files is to purchase decrypt tool and unique key for you.
    This software will decrypt all your encrypted files.
    What guarantees you have?
    You can send one of your encrypted file from your PC and we decrypt it for free.
    But we can decrypt only 1 file for free. File must not contain valuable information.
    You can get and look video overview decrypt tool:
    https://we.tl/t-8gklbDGTaZ
    Price of private key and decrypt software is $980.
    Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
    Please note that you’ll never restore your data without payment.
    Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.

    To get this software you need write on our e-mail:
    gorentos@bitmessage.ch

    Reserve e-mail address to contact us:
    ferast@firemail.cc

    Our Telegram account:
    @datarestore

    Your personal ID:
    103Asd437yHIUSdgfdg6FmtEnulvlo3t7GhuRXMbP3BCWI62uMZsak3cEI

    Please get me solution and post on : mohsin.khanstar@gmail.com

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...