[SOLVED] How do I fix OMFL Ransomware?

Ranime

Prominent
Nov 16, 2019
39
0
530
Hi,
Today while I was on my Laptop, a CMD Window opened up. A lot of commands started running (it was fast so it was unreadable) I closed it ASAP. I opened up Task Manager to see what program did that or what else was running. There were some suspicious programs were running. I closed them & I switched to the "Start-Up" tab on Task Manager & Disabled all the suspicious programs. Three Programs were running atm "Haleng" "Kamnira" & "Mohszhvl". I right-clicked on them to see their file location there were all in different Directories so I deleted them also, an IPGrabber link but I quickly closed (I still doubt they got my IP). Although, It was too late. After 10-15 mins, Everything was converted to .omfl file format (Literally Everything except .dll files). It's some kind of Ransomware because it placed a .txt file in every directory. I really have no idea where it came from? The Laptop was idle when this happened. I downloaded nothing suspicious but I doubt I had an E-mail tab open in Chrome.


Code:
ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
[url=https://we.tl/t-egvXx8HqOt]https://we.tl/t-egvXx8HqOt[/url]
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.


To get this software you need write on our e-mail:
helpmanager@mail.ch

Reserve e-mail address to contact us:
restoremanager@airmail.cc

Your personal ID:
0272omflAsdhkioO7OVYUyivYvPEI6nuQIcKXNx74ml0mkowpmDzt1

I don't know how to get rid of this. Most of the applications are not working. I tried Emisoft's DJVU Decrypt tool as some online articles suggested it didn't work. Is there a way to recover the files?

Any help will greatly be appreciated

Regards,
Ranime
 
Solution
I guess I'll have to do it 🙁 I still wanna know the origin where does it come from?

You.
You went somewhere, downloaded something, opened something.
You are ultimately the origin.
Hopefully you will now make a backup and avoid the behaviors that led to this.

We got hit at work twice. Our former IT manager learned the hard way that we did not have a proper (if any) backup.

I wish you luck but as said already, clean Windows install is in your future.
I guess I'll have to do it 🙁 I still wanna know the origin where does it come from?

You.
You went somewhere, downloaded something, opened something.
You are ultimately the origin.
Hopefully you will now make a backup and avoid the behaviors that led to this.

We got hit at work twice. Our former IT manager learned the hard way that we did not have a proper (if any) backup.

I wish you luck but as said already, clean Windows install is in your future.
 
  • Like
Reactions: Ranime
Solution