This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

How do I decrypt .RUMBA files infected by DJVU Virus?

3 min read

This thread's last reply is from January 28, 2019, 6:14 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Greetings,

Due to some DJVU virus and ransomware my files are encrypted with .RUMBA and when I remove this extension the files become corrupted.
Please help me to solve this issue and recover my original files.

I think virus came from unofficial software downloads and I have scanned my PC with AVAST, Malwarebytes, Windows Defender, etc to delete the virus, the only thing needs to be done is to decrypt the .Rumba files

I have attached the FRST.txt and Additional.txt files.

Please help me to restore my files.
Your best chance of recovering your files lies with another forum .... https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-tro-djvu-rumba-openmetxt-support-topic/#entry4449966 .... Bleeping Computer are the experts with your Ransomware and have a number of decryption specialists who may be able to help you. So I advise you to post to the topic there that I've linked you to.

However, if you've already removed the infection, it may now be impossible to decrypt the files, since one or more of the infection files you've removed will have contained the decryption key needed to decrypt your files, and there may not be another way to get that key.

The experts at BC will be able to tell you if that is the case or not, so I advise you to let them know what you have done.

I include below a copy of the relevant section on Rumba from the article I linked you to (the actual one has live links, this copy does not).

Update 01/21/19:
STOPDecrypter v2.0.1.0.has been updated to include support for the .rumba variant and the new encrypted file format if you were hit by the OFFLINE KEY as explained in Post #451. As of now there is a new OFFLINE KEY embedded in the decrypter tool along with the previous key.

--Note: The decrypter will be able to decrypt files if your personal ID is D02NfEP94dKUO3faH1jwqqo5f9uqRw2Etn2lP3VB. If the decrypter skips your files and your personal ID is different than the one above, then we will not be able to help you at this time.

If STOPDecrypter indicates "No keys were found for the ID" you entered or "Unidentified ID", archive (save) the ID and MAC addresses in case of future decryption.


Victims of the .rumba variant who have NOT already posted their info in this support topic, contact Demonslay335 via PM with your personal ID from the ransom note and MAC address(es). Preferably, he wants victims to grab the information STOPDecrypter gives them and copy/paste it in the PM as explained in Post #467. We also do not need encrypted & original file pairs for this variant at the current time. If we find a way to use them, we will ask for them on an individual basis.
Thanks Gary,

I have already tried their methods but did not work for me.
Please help me find some other source of help.

Thank you so much.
The experts at BC are the best I know of, if they can't help you, then I'm afraid you're probably going to have to come to terms with the fact that your files are probably not going to get recovered.

Did you contact Demonslay335 because he really is the authority on this infection.
As you have posted for help on this matter at a number of forums, which is against MR policy ... https://www.malwareremoval.com/forum/vi ... 96#p491396 ... and as you are already receiving help at Bleeping Computer ....

This topic is now closed