Operating System
Windows 7
Infection date and initial symptoms
Encrypted every files.
Current issues and symptoms
Extensions on every encrypted file is: ungfwsa !
System logs
I did not upload the FRST.txt logs

Mahesh Sudula

Level 12
Verified
I Know its in appropriate to reply here, just to help out !
Hello, just download latest Gand crab Decryptor of Bit defender ( specific latest as of date)
Now, run the decryptor in the location where you want the decryption ..for ex: if desktop
then select path on decryptor as:c/Users/ Desktop like that !
Pls do not run the decryptor directly on whole system..it yields nothing !
 
Reactions: donzzi

donzzi

Level 1
I Know its in appropriate to reply here, just to help out !
Hello, just download latest Gand crab Decryptor of Bit defender ( specific latest as of date)
Now, run the decryptor in the location where you want the decryption ..for ex: if desktop
then select path on decryptor as:c/Users/ Desktop like that !
Pls do not run the decryptor directly on whole system..it yields nothing !
it does not work
Screenshot_6.png
 

bjm_

Level 5
Verified
READ THIS BEFORE DOWNLOADING: this tool does not work for users infected with GandCrab version 5.0.4 and newer. GandCrab version 5.0.4 is currently undecryptable and running this tool on a computer infected by this version will result in Initialziation Error.
In order for this recovery solution to work, you are required at least 1 available ransom-note on your PC. The ransom-note is required to recover the decryption key. Please make sure that you do not run a clean-up utility which detects and removes these ransom-notes prior to execution of this tool. The information inside the ransom-notes is essential in the decryption process as it allows us to compute the unique decryption key for your files.

GandCrab Ransomware decryption tool
4183.png
4187.png
4184.png
4188.png
IDK
I know its not appropriate for me to reply here.....just offering re "tool".
FWIW ~ YMMV
 
Last edited:

Bursec

New Member
I have a client with the same ransom... We had to wait to the decrypt, and i foud it on nomoreransom.org, but use it by your own risk.
 
Reactions: bjm_