===============================# aes-ni ransomware #===============================
█████╗ ███████╗███████╗ ███╗ ██╗██╗
██╔══██╗██╔════╝██╔════╝ ████╗ ██║██║
███████║█████╗ ███████╗█████╗██╔██╗ ██║██║
██╔══██║██╔══╝ ╚════██║╚════╝██║╚██╗██║██║
██║ ██║███████╗███████║ ██║ ╚████║██║
╚═╝ ╚═╝╚══════╝╚══════╝ ╚═╝ ╚═══╝╚═╝
SORRY! Your files are encrypted.
File contents are encrypted with random key (AES-256 bit; ECB mode).
Random key is encrypted with RSA public key (2048 bit).
We STRONGLY RECOMMEND you NOT to use any "decryption tools".
These tools can damage your data, making recover IMPOSSIBLE.
Also we recommend you not to contact data recovery companies.
They will just contact us, buy the key and sell it to you at a higher price.
If you want to decrypt your files, you have to get RSA private key.
In order to get private key, write here:
[email protected]
[email protected]
Also there is one fast way to contact us.
If you are familiar with Jabber, write us to JID: zooolo(at)darknet.nz (it is Jabber, not e-mail address!)
You can get Jabber account for example at
hxxps://www.xmpp.jp/signup
IMPORTANT: In some cases malware researchers can block our e-mails.
If you did not receive any answer on e-mail in 48 hours,
please do not panic and write to BitMsg (
hxxps://bitmsg.me) address:
BM-2cVgoJS8HPMkjzgDMVNAGg5TG3bb1TcfhN
or create topic on
hxxps://www.bleepingcomputer.com/ and we will find you there.
Also it will be better if you download Tor browser here:
hxxps://www.torproject.org/download/...d-easy.html.en
Download, install and run it; then visit our site (from Tor browser):
hxxp://kzg2xa3nsydva3p2.onion/index.php
Please do not visit this site from standard browser: it just will not open. You need Tor Browser to open .onion sites.
There is a form, you can write us there if all e-mails are blocked and we will contact you very fastly.
If someone else offers you files restoring, ask him for test decryption.
Only we can successfully decrypt your files; knowing this can protect you from fraud.
You will receive instructions of what to do next.
You MUST refer this ID in your message:
DC#519592DBDB2D83AE45395397BEDBA1B8
Also you MUST send all ".key.aes_ni" files from C:\ProgramData\ (in Windows Vista, 7, 8, 8.1, 10)
or in C:\Documents and Settings\All Users\Application Data\ (in Windows XP, 2003) if there are any.
===============================# aes-ni ransomware #===============================
Скрыть