Ever Been Hit With Ransomware?

Thank you so much for the help I really appreciate it.

I got it from bleepingcomputer and this thread http://www.bleepingcomputer.com/forums/t/608045/crypted-ransomware-nemucod-decrypttxt-support-and-help-topic/page-6

I think I already have the decrpter software downloaded if its a application called Decrypt_nemucod then yes I have that already I just have no idea how to use it.

YES EMSISOFT developed the decryptor.
okay what is the issue you are facing while trying to use it.
 
well I get an error message whenever I try and use it. " The decrypter could not determine a valid key for your system. Please drag and drop both an encrypted file as well as its unencrypted counterpart on to the decrypter to determine a correct key. Files need to be at least 510 bytes long."

There are hundreds of .crypted files do I have to decrypt every single one individually??
 
I know this dose not work for everone, but make sure your opening emails away from the device that hold important documents, you can even encrypt your hard drives as well.
 
well I get an error message whenever I try and use it. " The decrypter could not determine a valid key for your system. Please drag and drop both an encrypted file as well as its unencrypted counterpart on to the decrypter to determine a correct key. Files need to be at least 510 bytes long."

1. Make a decrypt folder
2. Put the downloaded app in the folder
3. Add the encrypted file and unencrypted version of the same file in that folder MAKE SURE THE SIZE IS MORE THAN HALF MB.
4. SELECT encrypted file and unencrypted version of the same file and DRAG onto the decrypt_nemucod.exe icon(the icon for decryting app) at the same time

THIS will LEAD TO A UAC PROMPT
click yes

IT WILL TRY TO GENERATE KEY.
 
Last edited:
There are hundreds of .crypted files do I have to decrypt every single one individually??

No you wont have to, once you get the key.

THE SOFTWARE WILL GIVE YOU THE STEPS.

IMPORTANT : do you have a good antivirus.
 
1. Make a decrypt folder
2. Put the downloaded app in the folder
3. Add the encrypted file and unencrypted version of the same file in that folder MAKE SURE THE SIZE IS MORE THAN HALF MB.
4. SELECT encrypted file and unencrypted version of the same file and DRAG onto the decrypt_nemucod.exe icon(the icon for decryting app) at the same time

THIS will LEAD TO A UAC PROMPT
click yes

IT WILL TRY TO GENERATE KEY.

I have followed your instructions exactly how you said to.

The only files that are over 500kb are the sample pictures. I do not have a unencrypted file so I tried downloading the exact file online. Its the same kb as the .crypted one.

So I added the Chrysanthemum.jpg 859kb
and I added the Chrysanthemum.jpg.crypted 859kb

put both of these files in the same folder along with the decrypt_nemucod.exe

I dragged both files at the same time into the decrypt_nemucod.exe and I still get the same exact error message. Am I doing something wrong here? Again thank you for your patience and generosity with your help you have no idea how much I actually appreciate it!
 
I have followed your instructions exactly how you said to.

The only files that are over 500kb are the sample pictures. I do not have a unencrypted file so I tried downloading the exact file online. Its the same kb as the .crypted one.

So I added the Chrysanthemum.jpg 859kb
and I added the Chrysanthemum.jpg.crypted 859kb

put both of these files in the same folder along with the decrypt_nemucod.exe

I dragged both files at the same time into the decrypt_nemucod.exe and I still get the same exact error message. Am I doing something wrong here? Again thank you for your patience and generosity with your help you have no idea how much I actually appreciate it!

Don't worry about it man we all need help sometime.

No you are doing everything right.

I wish i could take your computer's remote but can't take the risk.

Give me sometime to figure out the issue.

Just tell me this do you have any other files in that size range
Are you getting the UAC prompt when you drag the files.

IT seems you are infected by a new variant.
the solution is still in development.
 
Last edited:
Don't worry about it man we all need help sometime.

No you are doing everything right.

I wish i could take your computer's remote but can't take the risk.

Give me sometime to figure out the issue.

Just tell me this do you have any other files in that size range
Are you getting the UAC prompt when you drag the files.

Yeah its way too risky I wouldn't want you to get infected either.

Sure man no problem let me know if you need anything. I will leave this thread open and check it every 10 min or so.

I did a search for all the .crypted files on my C drive and all of the other files that are over 500kb are weird files that I have never even heard of. I tried searching for a few of them and I have no idea what they are.

Examples of these files are
Notes_LOOP_BG_PAL.wmv.crypted
title_trans_notes.wmv.crypted
YoutubeTutorials_4.jpg.crypted


Yes It does get a UAC prompt and then I press Run and it gives me that error message.
 
Im wondering if there is anyway I can just not deal with all of this and just wipe my hard drive clean? Is that even a possibility?
 
LETS START FROM SCRATCH

IF it is not working out with the decrypter

There may be two reasons for that

1. New variant
2. Layered encryption

upload an infected file on this link https://id-ransomware.malwarehunterteam.com/index.php
and tell the results
 
here is a screenshot for you bro.

screenshot.jpg
 
Im wondering if there is anyway I can just not deal with all of this and just wipe my hard drive clean? Is that even a possibility?

Yes a complete format and windows reinstall is a solution

you will loose all the files if you dont have a backup.

So its upto you

Or

there are manual ways to find all the registry modifications done by the ransomware and deleting them
then running an updated antivirus to remove the infected files

but you will loose the encrypted file

this method is risky as traces are left you will face the problem again.
 
Well it happened to me last night. I was a little drunk and not really thinking. I got an email that said I needed to appear in court. It seemed somewhat legit and it was not in my spam folder. It had an attatched file on it that seemed legit as well.

Long story short I have ransomware that has a note that says.

- If you do not pay in 3 days YOU LOOSE ALL YOUR FILES.
- Nobody can help you except us.
- It`s useless to reinstall Windows, update antivirus software, etc.
- Your files can be decrypted only after you make payment.
- You can find this manual on your desktop

I thought it was a joke until I actually did some reading up on it and it seems as if its a very serious problem right now. Some of my files have already been crypted. Does anybody have any experience in this stuff? I have been trying malware forums and stuff like that but those forums take FOREVER to answer me back. I can't lose all my files and I am freaking out :(

I beat these morons and their ransomware dozens of times on multiple computers. It's just malware. Frankly a Kaspersky Rescue Disk WILL get rid of it, but it will take a day, and you will need a lot of tools. Some of which include:

Rkill
ComboFix(if the device is below windows 8)
MalwareBytes
TDSSKiller

It's a scary world when the FBI can't solve a simple basic problem. I would create a service for this, but since the operations do need to be performed within 3 days ... failure to have the device physically present makes it impossible to correct. So I can't do it as a service because it would be cost prohibitive for people to overnight their devices for recovery.

This is NOT an easy recovery process. That said ... it's not particularly difficult either if you know what you are doing. It should be said that I've been doing this type of crap for over 20 years, so I'm quite familiar with zero-day exploits, malware, and viruses in general. I often recognize behavioral characteristics and can quickly identify the best tools for the job in most circumstances, but having the device present is critical.

People attempting to recover a device like this with less experience may easily screw up their operating systems, so it's not something I'd recommend for casual computer enthusiasts, but don't believe the hype ...


Plenty of us can wreck that ransomware when the device is directly in-front of us. Send me a PM OP, and I'll connect with you on Skype. I'm in no way afraid of doing a remote process with you whereby I can help teach you how to recover this device. I hope you have up to 1 day available to work on this, because it's likely to take that long.

As far as I'm concerned the more of us in the world who can defeat these morons - the better off the world will be.
 
Last edited:
Well it happened to me last night. I was a little drunk and not really thinking. I got an email that said I needed to appear in court. It seemed somewhat legit and it was not in my spam folder. It had an attatched file on it that seemed legit as well.

Long story short I have ransomware that has a note that says.

- If you do not pay in 3 days YOU LOOSE ALL YOUR FILES.
- Nobody can help you except us.
- It`s useless to reinstall Windows, update antivirus software, etc.
- Your files can be decrypted only after you make payment.
- You can find this manual on your desktop

I thought it was a joke until I actually did some reading up on it and it seems as if its a very serious problem right now. Some of my files have already been crypted. Does anybody have any experience in this stuff? I have been trying malware forums and stuff like that but those forums take FOREVER to answer me back. I can't lose all my files and I am freaking out :(

Court will never send you an email to appear.
 
jigsaw - all the steps are exactly the same and its not looking good.

I'm honestly at the point of just saying screw it. I put all my super important files on a 8gb usb stick and I am just thinking about wiping my hard drive and reinstalling windows again. Sadly I got my version of windows from thepiratebay so I will have to go through that nightmare again.

The only problem I see is the ransom note says its useless to reinstall windows... what if my hard drive is basically reset to factory settings? Will I still have this problem?

I don't know much about hardware but is my motherboard infected as well or is it just my hard drive?
 
The only problem I see is the ransom note says its useless to reinstall windows... what if my hard drive is basically reset to factory settings? Will I still have this problem?

A format is a format. Not even a virus can survive that. You'll just lose whatever files they encrypted, if you didn't back them up before you got infected.
 
Thats fine I didnt really see any files that I cared about that got encrypted. I am just afraid of losing everything so I put it on a usb stick. Can somebody explain exactly how to properly format a hard drive?
 
jigsaw - all the steps are exactly the same and its not looking good.

I'm honestly at the point of just saying screw it. I put all my super important files on a 8gb usb stick and I am just thinking about wiping my hard drive and reinstalling windows again. Sadly I got my version of windows from thepiratebay so I will have to go through that nightmare again.

The only problem I see is the ransom note says its useless to reinstall windows... what if my hard drive is basically reset to factory settings? Will I still have this problem?

Wait for a day

will come soon.jpg

the decrypter will be updated soon.
Thats the guy who made the first one.

dont give up hope man
DID YOU BACK UP AFTER GETTING INFECTED?

that part in the note most probably is a scare thats all.

EDIT: i will give you a windows 8 key if need be.
if you want a windows 7 too

SO cheer up.
 
Last edited:
Back
Top