Jump to content

a ransomware named .CEZOR [MOVED] [Solved][Closed]


Go to solution Solved by Guest #37,

Recommended Posts

this message shown in every folder and every file extension changed into .CEZOR help me out to decrypt my files please any one help.......... ATTENTION! Don't worry, you can return all your files! All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key. The only method of recovering files is to purchase decrypt tool and unique key for you. This software will decrypt all your encrypted files. What guarantees you have? You can send one of your encrypted file from your PC and we decrypt it for free. But we can decrypt only 1 file for free. File must not contain valuable information. You can get and look video overview decrypt tool: https://we.tl/t-WbgTMF1Jmw Price of private key and decrypt software is $980. Discount 50% available if you contact us first 72 hours, that's price for you is $490. Please note that you'll never restore your data without payment. Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours. To get this software you need write on our e-mail: gorentos@bitmessage.ch Reserve e-mail address to contact us: varasto@firemail.cc Our Telegram account: @datarestore Mark Data Restore Your personal ID: 111Asd3i74yih3gkdMRrOmiaGsrOBV5WeKx9PFMAoug3J1vvarRjmmut1 Moderator: Moved to the correct forum.
Link to comment
Share on other sites

  • Solution
Hi, In terms of recovering/decrypting the files, this type of virus usually encrypts the files with very high bit keys, and in very rare cases a decryptor can be created, usually due to failure or careless programming of the malware. But in the vast majority it is not possible, at least at the moment. You can check if the ransomware that attacked you currently has the possibility to be decrypted here: https://id-ransomware.malwarehunterteam.com/index.php?lang=en You can find information that can help you here: https://www.nomoreransom.org/en/index.html Also try the utilities offered by Kaspersky: http://support.kaspersky.com/viruses/utility If you are a Kaspersky user with a valid license, open a support ticket in my Kaspersky account, send them a sample of an encrypted file, and if you have the same file unencrypted. Try with STOPDecrypter v2.1.0.15 Regards
Link to comment
Share on other sites

Hi, In terms of recovering/decrypting the files, this type of virus usually encrypts the files with very high bit keys, and in very rare cases a decryptor can be created, usually due to failure or careless programming of the malware. But in the vast majority it is not possible, at least at the moment. You can check if the ransomware that attacked you currently has the possibility to be decrypted here: https://id-ransomware.malwarehunterteam.com/index.php?lang=en
Link to comment
Share on other sites

Hello Prashant sharma, Do you have a valid Kaspersky license? If "yes", open a support ticket via your MyKaspersky account, https://my.kaspersky.com/ If "no", did you follow all the information advised by Caos? Please let us know and please include: Operating system, version, build? Kaspersky software name? version? patch(x)? x = letter Actions/steps taken to recover? Thanks.
Link to comment
Share on other sites

Yes I have followed caos but nothing happens. I'm using win 7 x64 and yet not installed kaspersky
Did you submit to:
  1. https://www.nomoreransom.org/crypto-sheriff.php?lang=en ?
&
  1. https://id-ransomware.malwarehunterteam.com/index.php?lang=en ?
---------- Please read & follow every step very carefully: https://www.pcrisk.com/removal-guides/15383-cezor-ransomware Thanks.
Link to comment
Share on other sites

https://www.pcrisk.com/removal-guides/15383-cezor-ransomware 2 days back I have visited this link but The decryptor named STOPDecryptor was of old version and when today I visited this link I found a new one Its been great I have recovered 1tb of my data.... I'm speach less bro...
Link to comment
Share on other sites

  • 2 months later...
Hello dear FLOOD, My laptop infected with a ransomware virus named .nesa this message shown in every folder and every file extension changed into .nesa help me out to decrypt my files please any one help.......... ATTENTION! Don't worry, you can return all your files! All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key. The only method of recovering files is to purchase decrypt tool and unique key for you. This software will decrypt all your encrypted files. What guarantees you have? You can send one of your encrypted file from your PC and we decrypt it for free. But we can decrypt only 1 file for free. File must not contain valuable information. You can get and look video overview decrypt tool: https://we.tl/t-UV4s8jgncB Price of private key and decrypt software is $980. Discount 50% available if you contact us first 72 hours, that's price for you is $490. Please note that you'll never restore your data without payment. Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours. To get this software you need write on our e-mail: gorentos@bitmessage.ch Reserve e-mail address to contact us: gerentoshelp@firemail.cc Your personal ID: 0166hTlGeRsMTHVpwDk4Ylm4RWx1yyNzcacA5hSp3l60BnYwdny
Link to comment
Share on other sites

I really I followed most of these steps but to no avail, I did scan with avast antivirus and I did reset to my PC but nothing happened
Hello Abdulla Algibaly, Welcome!
  1. When the infection happened was Kaspersky software installed and active?
  2. Do you have a valid Kaspersky license?
  3. If "yes", open a support ticket via your MyKaspersky account, https://my.kaspersky.com/
  4. If "no", did you follow all the information advised by Caos ?
Thank you.
Link to comment
Share on other sites

I really I followed most of these steps but to no avail, I did scan with avast antivirus and I did reset to my PC but nothing happened
Hello Abdulla Algibaly, Welcome!
  1. When the infection happened was Kaspersky software installed and active?
  2. Do you have a valid Kaspersky license?
  3. If "yes", open a support ticket via your MyKaspersky account, https://my.kaspersky.com/
  4. If "no", did you follow all the information advised by Caos ?
Thank you.
Yes I have followed caos but nothing happens I'm using win 10 x64 and yet not installed kaspersky I did a scan with Avast antivirus but it didn't find anything And I did check on this site: https://id-ransomware.malwarehunterteam.com/index.php?lang=en to determine the type of virus and I found that my caught by a ransomware named .nesa and the name of virus is STOP (Djvu) according to that site
Link to comment
Share on other sites

Yes I have followed caos but nothing happens I'm using win 10 x64 and yet not installed kaspersky I did a scan with Avast antivirus but it didn't find anything And I did check on this site: https://id-ransomware.malwarehunterteam.com/index.php?lang=ento determine the type of virus and I found that my caught by a ransomware named .nesa and the name of virus is STOP (Djvu) according to that site
Hello Abdulla Algibaly, Thank you for posting back. Ok, so ID Ransomware, confirmed .nesa from STOP/DJVU family
  1. What happened when you used CRYPTO SHERIFF?
  2. Do you have backups?
  3. In another post Caos advises, "if decryption is not possible at this present time, save the files (which you deem convenient) in case they can be decrypted later."
  1. If you follow this advice. make sure to save the files to a drive that is used exclusively for the contaminated files, make sure the drive can be locked and labelled so no further disaster can occur.
Best regards
Link to comment
Share on other sites

1- this message is shown to me :

BAD NEWS

Sorry! We don’t yet have a solution to help you but we are actively looking for it. Please make sure you are uploading a ransom note and encrypted sample file from the same infection. It is recommended to back-up your encrypted files, and hope for a solution in the future. 2- I don't have any backups at this moment 3- I will But really I need a solution for this, how long time should it takes to fix it Thanks
Link to comment
Share on other sites

1- this message is shown to me : BAD NEWS Sorry! We don’t yet have a solution to help you but we are actively looking for it. Please make sure you are uploading a ransom note and encrypted sample file from the same infection. It is recommended to back-up your encrypted files, and hope for a solution in the future. 2- I don't have any backups at this moment 3- I will But really I need a solution for this, how long time should it takes to fix it Thanks
Hello Abdulla Algibaly, There is no time frame. However, the sites we've provided advise: "At the moment, not every type of ransomware has a solution. Keep checking the website as new keys and applications are added when available". If you see prashant sharma's post, originally he tried the solutions, with no success, however, after trying again, eventually success came. The Experts advise "never pay the criminals, there is no guarantee a solution will be provided". Thank you and best wishes. SAFETY 101 Tips and tools to fight viruses and vulnerabilities
Link to comment
Share on other sites

You said : Keep checking the website as new keys and applications are added when available".What page or website exactly should I keep checking? Do you have any account that I can send you a shots screen for some of the procedures Thanks
Hello Abdulla Algibaly, What I actually said was/is "However, the sites we've provided advise: "At the moment, not every type of ransomware has a solution. Keep checking the website as new keys and applications are added when available". ID Ransomware and Crypto Sheriff are the sites from above. Regarding screenshots, If you wish to share them (via pm) that's fine, but, I cannot do anything with them. We understand your predicament, if there was a solution we would share it with you. Thank you.
Link to comment
Share on other sites

You said : Keep checking the website as new keys and applications are added when available".What page or website exactly should I keep checking? Do you have any account that I can send you a shots screen for some of the procedures Thanks
Hello Abdulla Algibaly, What I actually said was/is "However, the sites we've provided advise: "At the moment, not every type of ransomware has a solution. Keep checking the website as new keys and applications are added when available". ID Ransomware and Crypto Sheriff are the sites from above. Regarding screenshots, If you wish to share them (via pm) that's fine, but, I cannot do anything with them. We understand your predicament, if there was a solution we would share it with you. Thank you.
Thank you so much
Link to comment
Share on other sites

  • 2 weeks later...
  • 1 month later...
hellohelp me pleasemy brother taked my ex hard and use it he return my hard infected by virus renamed all files by extintion .smok after nameand in every folder text tell : ATTENTION!

Don't worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-7cpJN3gq4f
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail:
restoredatahelp@firemail.cc

Reserve e-mail address to contact us:
gorentos@bitmessage.ch

Your personal ID:
0180jYgs9f6s91lvzNm5ZxY3CSkJzx9phvPQIKzKZBgnn1RK2xD7   help please
Link to comment
Share on other sites

Hello  @theone_2005,

Welcome!

  1. When the infection happened was Kaspersky software installed and active?
  2. Do you have a valid Kaspersky license?
  3. If "yes", open a support ticket via your MyKaspersky account, https://my.kaspersky.com/
  4. If "no", did you follow all the information advised, in this topic, by @Caos 11th July 2019?

Thank you.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.


×
×
  • Create New...