Any files that are encrypted with GandCrab V5.0.4/5.0.5 will have a
random 5-10 character extension (i.e. .XMMFA, .LUKIZQW, .TKKLKM, .PFBRBHHEVM) appended to the end of the encrypted data filename and leave files (ransom notes) named [random uppercased extension]-DECRYPT.txt (i.e. LUKIZQW-DECRYPT.txt, TKKLKM-DECRYPT.txt).
Files encrypted by GandCrab V5.0.4/5.0.5 are not decryptable at this time without paying the ransom since these versions have been reported to
break the BitDefender decryption tool so it will not work.
Bitdefender confirmed it's not decryptable and the company has posted the following
note at the top of the decryption tool
download page.
QUOTE
"READ THIS BEFORE DOWNLOADING: this tool does not work for users infected with GandCrab version 5.0.4 and newer. GandCrab version 5.0.4 is currently undecryptable and running this tool on a computer infected by this version will result in Initialization Error."
There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.
.
When or if a decryption solution is found, that information will be provided in that support topic and victims will receive notification if subscribed to it.