Share via

Adobe reader destroyed all of my files in computer and NAS

Anonymous
2020-12-11T13:37:12+00:00

Greetings,

Today when i was reading a document in adobe reader it changed the file extension to .adobe of all files on my NAS and PC and now my files are unable to open and Changing the file extension doesn`t do anything how to fix this? or should i contact adobe customer support

Thanks in advance.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. quietman7 MVP Alumni 19,740 Reputation points Volunteer Moderator
    2020-12-14T02:31:08+00:00

    Are there any obvious file extensions appended to your encrypted data files? If so, what is the extension? Is there an .[email], an ID number with random characters (.id-A04EBFC2, .id[4D21EF37-2214]) or an ID number with an email address (.id-BCBEF350.[<email>], .id[7A9B748C-1104].[<email>], _ID_<id***>_<email>) preceding the extension?

    The .adobe extension has been used by both Dharma (CrySiS) Ransomware and STOP (Djvu) Ransomware. The Dharma (CrySiS) variant will have an <id>-<id*** (8 random hex char)>.[<email>] followed by the .adobe extension. ID Ransomware accurately detects by filemarkers. The extension with two e's at the end (.adobee is only related to STOP (Djvu) Ransomware and leaves ransom notes named _openme.txt as explained here.

    • .id-EE6A4622.[******@foxmail.com].adobe = Dharma (CrySiS)
    • <filename>.<extension>.adobe = STOP (Djvu)
    • <filename>.<extension>.adobee = STOP (Djvu)

    Did you find any ransom notes? If so, what is the actual name of the ransom note?

    Can you provide (copy & paste) the ransom note contents in your next reply?

    .

    You can submit (upload) samples of encrypted files, ransom notes and any contact email addresses provided by the malware developer to ID Ransomware (IDR) for assistance with identification and confirmation of the infection. Please provide a link to the ID Ransomware results.

    .

    When dealing with ransomware, recovering one, two encrypted or even a few files by renaming them or removing (deleting) the extension is sometimes possible especially with very large files where the ransomware only performs partial encryption (as explained here and here) or if the malware encryption process went went awry or was interrupted but in most cases doing so does not always work. In fact, it often can result in additional problems with file corruption and complicate possible decryption should a future free solution ever becomes available. Most crypto malware experts recommend that you do not tamper with the encrypted files.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. JuliaMarvin 20,070 Reputation points Volunteer Moderator
    2020-12-11T16:25:51+00:00

    Please read:

    Try to identify with what kind of ransomware you are dealing.

    Upload a ransom note and/or sample encrypted file to identify the ransomware that has encrypted your data. > ID Ransomware 

    Might be Dharma ransomware...

    If so, this is the support thread: Dharma ransomware (filename.[<email>].wallet/.cesar/.arena) Support Topic

    Also see:

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. David-M 115.5K Reputation points Independent Advisor
    2020-12-11T14:07:20+00:00

    Hi, I'm David, an Independent Advisor, here to help you.

    Sorry, but I believe you may have been a victim of ransomware that encrypts all files and leaves them with the .adobe extension.

    I suggest you post your case on the link below. If there is a way to decrypt the files affected by this ransomware, this is the best place to get help.

    https://www.bleepingcomputer.com/forums/f/239/r...

    ATTENTION: Decryptors are provided for free, do not be fooled by sites that sell decryptors promising to bring your files back to normal. They don't work.

    ________________________________________________________

    Standard Disclaimer: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    ________________________________________________________

    Refer to the following articles so that you can protect yourself against Ransomware in the future.

    https://support.microsoft.com/en-us/windows/pro...

    https://docs.microsoft.com/en-us/windows/securi...

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments