.onion help required!

Discussion in 'Windows XP / Older OS' started by Kaerar, Jun 6, 2017.

  1. Kaerar

    Kaerar MDL Novice

    Joined:
    Nov 10, 2013
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    0
    Hi guys, just run into an issue with some nasty malware on a very old Dell Inspiron laptop.

    Seems like the guy already had an issue using ACDSee and it being a nasty bit of malware in the first place, but now everything important is a .onion file.

    Going through various references to this it seems to be related to the Dharma virus and in turn is quite painful to deal with. One of the stipulations is that the background got changed so the ransomer could be contacted. However blank background seems to have happened and no way to know or contact the ransomer.

    This is posing a bit of an issue, if anyone has any ideas on how to decrypt these files then I'm all ears, or eyes in the case of this forum :)
     
  2. MrMagic

    MrMagic MDL Guru

    Joined:
    Feb 13, 2012
    Messages:
    6,020
    Likes Received:
    4,147
    Trophy Points:
    210
    #2 MrMagic, Jun 6, 2017
    Last edited: Jun 6, 2017
    EDIT - Decrypter below
     
  3. Kaerar

    Kaerar MDL Novice

    Joined:
    Nov 10, 2013
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    0
    Wasn't sure if they were legit or more viruses to deal with :D
     
  4. MrMagic

    MrMagic MDL Guru

    Joined:
    Feb 13, 2012
    Messages:
    6,020
    Likes Received:
    4,147
    Trophy Points:
    210
  5. Kaerar

    Kaerar MDL Novice

    Joined:
    Nov 10, 2013
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    0
    Thanks will give that a go.
     
  6. Kaerar

    Kaerar MDL Novice

    Joined:
    Nov 10, 2013
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    0
    #6 Kaerar, Jun 14, 2017
    Last edited: Jun 14, 2017
    (OP)
    Unfortunately the Rakhni Decryptor from Kaspersky didn't work :(

    Ah but it's a variant of Rannoh. Problem is now it needs an original file to compare to an encrypted file, which is kinda hard to do...