.docm ransomware, how to decrypt the files ? [MOVED] [Solved][Closed]

  • 13 July 2019
  • 1 reply

Hi everyone:
After donwloading a link from "weetransfer" website and open it, my PC got .DOCM virus.
All files on desktop and in the folder i opened it in became .DOCM files.
i give the PC to a professional company in our country, they remove the virus but could not decrypt the files.
i contact the criminal as per the note left on my desktop and he decrypt on file for me.
How to decrypt these files?
I will upload an encrypted file and the same file after the criminal decrypt it.

Moderator: Moved to the correct forum.

Best answer by Caos 15 July 2019, 07:42

View original

This topic has been closed for comments

1 reply

Userlevel 7
Badge +11

In terms of recovering/decrypting the files, this type of virus usually encrypts the files with very high bit keys, and in very rare cases a decryptor can be created, usually due to failure or careless programming of the malware.
But in the vast majority it is not possible, at least at the moment.

You can check if the ransomware that attacked you currently has the possibility to be decrypted here: https://id-ransomware.malwarehunterteam.com/index.php?lang=en

You can find information that can help you here: https://www.nomoreransom.org/en/index.html

Also try the utilities offered by Kaspersky: http://support.kaspersky.com/viruses/utility

If you are a Kaspersky user with a valid license, open a support ticket in my Kaspersky account, send them a sample of an encrypted file, and if you have the same file unencrypted.