Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ACCDFISA v2.0 Ransomware Support Topic - filename(!! to get password email id *id* to *email* !!).exe/.rar


  • Please log in to reply
296 replies to this topic

#286 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 17 February 2018 - 08:05 AM

third step uninstall antivirus.

restart the server.



BC AdBot (Login to Remove)

 


m

#287 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 17 February 2018 - 08:09 AM

I recommend to all the virus in the host file should not be in use otherwise after 60 days the keys change and are no longer recoverable

1: clean up with https://it.malwarebytes.com/mwb-download/
2 desistall anti virus
3. change dns to the network card: Dns: 8.26.56.26 - 8.20.247.20
4 generate the third key with: accdfisa2_2ndkeygen program
5 do not touch anything on the programmed date.
6 contact me when all this been done.



#288 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 17 February 2018 - 08:10 AM

I recommend to all the virus in the host file should not be in use otherwise after 60 days the keys change and are no longer recoverable

1: clean up with https://it.malwarebytes.com/mwb-download/
2 desistall anti virus
3. change dns to the network card: Dns: 8.26.56.26 - 8.20.247.20
4 generate the third key with: accdfisa2_2ndkeygen program
5 do not touch anything on the programmed date.
6 contact me when all this been done.
7 lock the VSSADMIN file



#289 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 17 February 2018 - 08:18 AM

at this point download this tools from this dedicated link
to you: https://1drv.ms/u/s!AsveL_I7orZEgZFezkx71Ax15c3MxA

2 save it on the desktop and straere with winrar

3 follow the numbered folders com 1 2 3


greetings are always here to help.

ale


#290 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 17 February 2018 - 08:24 AM

https://1drv.ms/i/s!AsveL_I7orZEgZFfTdlXCk4b8xtv9w



#291 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 17 February 2018 - 08:30 AM

demo:

 

https://www.facebook.com/photo.php?fbid=10204250813587928&set=a.1248782717105.28672.1755598314&type=3



#292 Emmanuel_ADC-Soft

Emmanuel_ADC-Soft

  • Members
  • 137 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Paris
  • Local time:07:08 PM

Posted 18 February 2018 - 05:49 AM

Hello Romero,

This url is not working. Regards,

Emmanuel



#293 SVQ

SVQ

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:08 PM

Posted 21 February 2018 - 01:24 PM

Hi Romeroalexis,

 

My system was encrypted un July 2016.

 

The mail is auinfo16@gmail.com

 

I´m waiting for a solution since this time.

 

There is the 2nd key generator from karwos, but I don´t know how get the fist and the 3rd key.

 

Doyou know any solution?

 

Thanks in advance.



#294 papasb

papasb

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 21 February 2018 - 01:32 PM

Hi. It would be really handy if everyone could post the exact random email they have, the month they were infected, the country they are in and the year they were infected...

#295 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 21 February 2018 - 02:00 PM

 
hi SVQ
I need ID and TXT file ransom

 

I server a file infected

 

Send everything to alexis.serf85@gmail.com
In WinRAR


#296 romeroalexis

romeroalexis

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 21 February 2018 - 02:04 PM

every email and every id to its variant.
after 60 days change key 1 and 2
key 3 never changes.

 

 

I remind everyone to stop the malware immediately, with malwarebyte.
and do not touch the windows registry and the program data and windows so64 folder

greetings alex



#297 sergiovalverdec

sergiovalverdec

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 21 February 2018 - 04:29 PM

Romeroalexis  I sent you an email with the information you requested, I ask you please can you help me, as it is very critical






4 user(s) are reading this topic

0 members, 4 guests, 0 anonymous users