We have learned that the infection only encrypts the first 0x25800 bytes of the file so the rest of the file is decrypted and recoverable.
Another update from Demonslay335 (aka Michael Gillespie)
QUOTE
"Currently, if your ransom note has the "personal ID" ending with 6se9RaIxXF9m70zWmx7nL3bVRp691w4SNY8UCir0, we will be able to help soon. This ID is also present at the end of the encrypted files (open with a hex editor or notepad, it's the last 40 characters of the file before the "{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}").
If your personal ID is different than the above, then we will not be able to help you currently. In that case, it is best to archive your encrypted files, and take note of the MAC address of the infected machine. You may send this info to kNN or myself for archiving should a solution arise in the future.
I have updated ID Ransomware to identify if you have a decryptable ID when an encrypted file is uploaded, and it will tell you explicitly if so. So if you are unsure about checking the personal ID, you can just upload an encrypted file to the site and it will be able to tell."