Hi all.
Just to share, we received the reply from the attacker as shown below.
Waiting for my brother to check and decrypt. I don't know if this works or not.
---------- Forwarded message ----------
From: Jack Williams <
[email protected]>
Date: 2015-11-07 18:12 GMT+03:00
Subject: Re: Fwd: Email
To:
Hello!
Do you have process in the memory called lsassw86s.exe ? If yes , kill process lsassw86s.exe first.
Also delete c:\windows\system32\lsassw86s.exe file.
Now you can run decrypt tool.
1st Decrypt password: 145C7C3F238B235F36C19125854FC9A77A6K7)CIAu4wCUBc407T2(E3B43vEQ4q8R9I1g5b7kB*9fDzE3EwEa1+8i5N4F8)Dt4v712QB=5d0q8i0k
2st Decrypt password: 21063857F60263D5921FFD2CB9B24E569(C54l6sDI9u1v4d7C2p7dA(BDCICSCv9FCl98744MEy8&BO7p7VASEo2@EXCODQCf619-DU6gCa4q9E0u
3st Decrypt password: quu*A**$$quu*V$uLFquu*V$uLF
Decryption tool (password for the archive: 123 ):
https://www.sendspace.com/file/ex2rs1Download it and unpack to any folder. Also program require administrative rules (use administrator account).
Run decrypt.exe .
Copy paste 1st Decrypt password, 2st Decrypt password and 3st Decrypt passwords in decrypt tool 3 fields.
If you have not stop our software - use decryption tool, because the tool will stop our software before decrypting the files.
This is very important to stop our software service (and dont delete any files in ProgramData folder before stop) because your decrypted
files may will be encrypted again.
p.s. when you will start decrypt tool it would seem as if the program hanging, but everything is fine, just wait for the message about
successful completion of decrypting and dont touch decrypt window with your mouse.
If you have any questions or troubles in decrypting feel free to contact me .
Thank You!