Jump to content

.Mmpa file virus ransomware

I downloaded an application then suddenly when i install it i turns out a virus then my pc got infected all of my files cannot be opened. The file is .mmpa I dont know anything how to fix this i hope someone can help me here. I don't know if i should just reset my pc or maybe there is a way to fix it without reseting or reformating it

446FDE2C-8B7B-4578-B80D-4A2A32C48F82.jpeg

F5CD7824-9866-4441-9F54-B3807BAE9CE0.jpeg

958704E0-39F7-4740-9032-A07C38BEA2BC.jpeg

Link to comment
Share on other sites

Link to post
Share on other sites

It depends. If you got infected with the newer version, there's probably nothing you can do to get your files back. It is ransomware that uses strong encryption (AES-256 CFB [source]), so there's virtually zero chance of breaking it without getting access to the encryption key. The old version stored the key offline, which is how the security researchers were able to rescue your files. But without access to the key, there's essentially no way to decrypt them.

 

See: https://www.pcrisk.com/removal-guides/19143-mmpa-ransomware

Quote

 

There are currently two versions of Djvu ransomware infections: old and new. The old versions were designed to encrypt data by using a hard-coded "offline key" whenever the infected machine had no internet connection or the server was timing out/not responding. Therefore, some victims were able to decrypt data using a tool developed by cyber security researcher, Michael Gillespie, however, since the encryption mechanism has been slightly changed (hence the new version, released in August, 2019), the decrypter no longer works and it is not supported anymore. If your data has been encrypted by an older version, you might be able to restore it with the another tool developed by Emsisoft and Michael Gillespie.

 

 

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Eigenvektor said:

It depends. If you got infected with the newer version, there's probably nothing you can do to get your files back. It is ransomware that uses strong encryption (AES-256 CFB [source]), so there's virtually zero chance of breaking it without getting access to the encryption key. The old version stored the key offline, which is how the security researchers were able to rescue your files. But without access to the key, there's essentially no way to decrypt them.

 

See: https://www.pcrisk.com/removal-guides/19143-mmpa-ransomware

 

THanks for the info! If i reset my pc will it be back to normal? Sorry i'm noob when it comes to this things

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, charliellantino said:

THanks for the info! If i reset my pc will it be back to normal? Sorry i'm noob when it comes to this things

If by "reset" you mean wipe the disk and reinstall Windows, then yes, that should fix it.

 

Obviously you are going to lose all your files you haven't backed up somewhere. You should avoid backing up already infected files, because chances are you'll carry over the infection to the new installation.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Eigenvektor said:

If by "reset" you mean wipe the disk and reinstall Windows, then yes, that should fix it.

 

Obviously you are going to lose all your files you haven't backed up somewhere. You should avoid backing up already infected files, because chances are you'll carry over the infection to the new installation.

Okay thank you again! I appreciate it

Link to comment
Share on other sites

Link to post
Share on other sites

Maybe dumb question but how does this 'ransomware' not get detected by windows defender? Which OP has apparently been using (I assume) 

 

 

 

 

The direction tells you... the direction

-Scott Manley, 2021

 

Softwares used:

Corsair Link (Anime Edition) 

MSI Afterburner 

OpenRGB

Lively Wallpaper 

OBS Studio

Shutter Encoder

Avidemux

FSResizer

Audacity 

VLC

WMP

GIMP

HWiNFO64

Paint

3D Paint

GitHub Desktop 

Superposition 

Prime95

Aida64

GPUZ

CPUZ

Generic Logviewer

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×