Emsisoft Decrypter for NemucodAES 1.0.0.80
|
Author:
Emsisoft
Date: 08/22/2017 Size: 951 KB License: Freeware Requires: Win 10 / 8 / 7 / Vista / XP Downloads: 4902 times Restore Missing Windows Files |
Download@MajorGeeks Download@MajorGeeks
|
MajorGeeks: Setting the standard for editor-tested, trusted, and secure downloads since 2001. |
Get free antivirus with AI-powered online scam detection Download Free!
Emsisoft Decrypter for NemucodAES can decrypt the NemucodAES ransomware, a newer variant of the Nemucod ransomware family.
NemucodAES was written in a combination of JavaScript and PHP. It uses AES and RSA to encrypt your files. Encrypted files will keep their original file names and a ransom note called "DECRYPT.hta" can be found on your Desktop. The ransom note reads as follows:
ATTENTION!
All your documents, photos, databases and other important personal files were encrypted
using a combination of strong RSA-2048 and AES-128 algorithms.
The only way to restore your files is to buy decryptor. Please, follow these steps:
Create your Bitcoin wallet here:
https://blockchain.info/wallet/new
Buy 0.13066 bitcoins here:
https://localbitcoins.com/buy_bitcoins
Send 0.13066 bitcoins to this address:
1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
Open one of the following links in your browser:
http://luxe-limo.ru/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://musaler.ru/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://vinoteka28.ru/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://www.agrimixxshop.com/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://sharedocsrl.it/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
Download and run decryptor to restore your files.
If Emsisoft Decrypter for NemucodAES does not find Nemucod *.db in your temp folder, it will not run. If you cleaned your drive of temporary files before becoming infected, this might be the reason why.
NemucodAES was written in a combination of JavaScript and PHP. It uses AES and RSA to encrypt your files. Encrypted files will keep their original file names and a ransom note called "DECRYPT.hta" can be found on your Desktop. The ransom note reads as follows:
ATTENTION!
All your documents, photos, databases and other important personal files were encrypted
using a combination of strong RSA-2048 and AES-128 algorithms.
The only way to restore your files is to buy decryptor. Please, follow these steps:
Create your Bitcoin wallet here:
https://blockchain.info/wallet/new
Buy 0.13066 bitcoins here:
https://localbitcoins.com/buy_bitcoins
Send 0.13066 bitcoins to this address:
1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
Open one of the following links in your browser:
http://luxe-limo.ru/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://musaler.ru/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://vinoteka28.ru/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://www.agrimixxshop.com/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
http://sharedocsrl.it/counter/?1FeZr4bvMpCf1QTS49VjsdhtnP6zPvMjbP
Download and run decryptor to restore your files.
If Emsisoft Decrypter for NemucodAES does not find Nemucod *.db in your temp folder, it will not run. If you cleaned your drive of temporary files before becoming infected, this might be the reason why.
Screenshot for Emsisoft Decrypter for NemucodAES





Tactical Briefings