Hi quietman7,
I attach a photo for my files infected at my pc at my work , this photo is veryc small sample for my encrypted data
Kindly acknowledge......!
Hope to get tools for decryption very soon .
Thanks quietman7
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Yesterday I was using my computer normally then suddenly a popup showed telling me that there was updates installing and I knew that it's not from Microsoft as when I opened the source from task manger I found that it's not related to Microsoft updates so I click on end task then I tried to open Windows defender but it showed this message " page not available Your IT administrator as limited access to some areas of this app, and the item you tried to access is not available. Contact IT helpdesk for more information. Then I found that a program called windows powershell is installed by itself .. Then the screen blacked out showing only this message when I tried to open Task manger " Task manger has been disabled by your administrator"
SO I tried to restart the my computer but couldn't open start...after managing to restart by pressing the power button for awhile to restore windows from a restore points , there was three but all failed and also repair failed so click on reset my computer but keep my files ..when it finished I found all my files "pictures , programs , pdfs, doxc, " all of it ended with this extension
.udjvu
like in the picture attached
So How can I get my files back and open them?
"when I tried to use snap tool I didn't find it"
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Cuando o si se encuentra una solución de descifrado, esa información se proporcionará en este tema de soporte y las víctimas recibirán una notificación si se suscriben a ella.
.
Además, lo más probable es que un artículo de noticias se publique en el Bleeping Computer front page.
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
Tengo el mismo problema.
Como me puedo enterar de la solución CUANDO ESTA LLEGUE?
How I know the solution. When it began. Sorry my wrong english.
From another post:
Mi ingles es malo.
Me sumo a este tema por si aparece una solución.
Google translation:
My English is bad.
I join this issue in case a solution appears.
Any files that are encrypted with GandCrab V5.0.4/5.0.5 will have a random 5-10 character extension (i.e. .XMMFA, .LUKIZQW, .TKKLKM, .PFBRBHHEVM) appended to the end of the encrypted data filename and leave files (ransom notes) named [random uppercased extension]-DECRYPT.txt (i.e. LUKIZQW-DECRYPT.txt, TKKLKM-DECRYPT.txt).
Files encrypted by GandCrab V5.0.4/5.0.5 are not decryptable at this time without paying the ransom since these versions have been reported to break the BitDefender decryption tool so it will not work. Bitdefender confirmed it's not decryptable and the company has posted the following note at the top of the decryption tool download page.
QUOTE
"READ THIS BEFORE DOWNLOADING: this tool does not work for users infected with GandCrab version 5.0.4 and newer. GandCrab version 5.0.4 is currently undecryptable and running this tool on a computer infected by this version will result in Initialization Error."
There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.
.
When or if a decryption solution is found, that information will be provided in that support topic and victims will receive notification if subscribed to it.