K
K
kamwork2015-11-10 17:32:59
Encryption
kamwork, 2015-11-10 17:32:59

How to cure all files from a virus that adds the .value extension?

Hello!
The secretary opened the letter, all her files were renamed, and some garbage was registered in them, when opening, even after we return the extension, there is still information that you need to send SMS and all that.
Who faced? Do you have detailed instructions on how to win? Or maybe someone in the teamviewer mode can help solve the problem?

Answer the question

In order to leave comments, you need to log in

11 answer(s)
E
Eugene, 2015-11-10
@yellowmew

As a rule, even anti-virus companies are no longer able to help, since ransomware makes it impossible to decrypt without a key that (maybe) is in the ransomware.
If shadow copies were not enabled, you can say goodbye to these files with 99.9% probability.

A
Alexander Taratin, 2015-11-10
@Taraflex

No way.
For the future habrahabr.ru/post/101971

R
Roman Mirilaczvili, 2015-11-10
@2ord

Don't mess with extortionists. Otherwise, you will finance their future activities.
Contact antivirus companies and maybe even the police.
Ransomware can also make mistakes in the code, due to which decryption by experts can be successful.

L
LESHIY_ODESSA, 2015-11-10
@LESHIY_ODESSA

Yesterday it was already:
vmartyanov.ru
antifraud.drweb.ua/encryption_trojs -> Free decryption of user data

V
Vladimir Martyanov, 2015-11-10
@vilgeforce

Do not listen to these "experts": they understand absolutely nothing in the subject area, especially since they have not even looked at your files. A link to the Dr.Web form is given, go there. And yes, are you sure it's value and not vault? For vault, yesterday we rolled out a decryption for almost all cases.

A
Artem @Jump, 2015-11-10
curated by the

The most reasonable thing is to restore data from a backup.
This data is encrypted, no one except those who encrypted it can decrypt it.
Contacting anti-virus companies and other places is a pointless undertaking.
In general, there are three options -
1) Restore from backup.
2) We pay the attackers and hope that they will help.
3) Forget about the data and do without them.

There are no other options.

F
FAN2 tom, 2015-11-10
@FAN2tom

How many similar questions can you ask? RESERVE your data correctly and sleep well.

K
kamwork, 2015-11-11
@kamwork

Vladimir Martyanov , let's solve the problem already. I will take it out separately, what would be in front of everyone, it will be useful not only to me.
I send you several files, you confirm receipt of the files here, then immediately say whether you can decrypt or not. If yes, I buy a license, you decrypt files on the whole computer accordingly.
I'm leaving a review. A lot of satisfied customers come to you.
I repeat, I can’t upload files through the Doctor Web form, due to the lack of a license

A
Alexander Chernykh, 2015-11-10
@sashkets

if there are no backups, then gaplyk
https://threatpost.ru/updated-cryptowall-encrypts-...

M
morgan, 2015-11-11
@morgane

In some cases, since there are lazy and narrow-minded entities among virus writers, recovering deleted files can help. Recuva or R studio can help in this case.

L
lnquisitor, 2015-12-10
@lnquisitor

kaspersky had a service, you need to send an example of an encrypted file there, and they will give you a medicine, you don’t need a license, I treated one client like this about six months ago, everything is ok

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question