I’m glad I found this forum. Maybe someone can help me.
My PC caught some ransomware (I suspect a dropbox invite, but realy can’t tell).
Files changed according to the following scheme:
Original file (for example): Flower.jpg
Now they look like this:
Additionally these text-files showed up: HOW TO RECOVER ENCRYPTED FILES.TXT
I uploaded both types of files to ID ransomware,
results were these:
- ransomnote_filename: HOW TO RECOVER ENCRYPTED FILES.TXT
- sample_extension: .badnews
• custom_rule: Encrypted size marker [0x00 - 0x08] 0x0400100000000000
I tried to use decrypt_globe3.exe by emnisoft. (I got some original files to compare.)
With the .badnews-files it didn’t work at all.
When I altered the name either to .globe3 or .amnesia it started decyphering, went to 100% but couldn‘ deliver a positive result.
Any hint on what I could try next?
Thank you a lot in advance!