NemucodAES; Fabian Wosar of her Emsisoft just released a decryptor for NemucodAES Ransomware. The malicious file that comes with spam emails, contains a JS file that will download a PHP script, which is the actual ransomware.
Once the PHP script is up and running it will scan the drives for targeted archives and after detecting them it will start with their encryption.
Unlike other ransomware, NemucodAES does not add any new ones extension and does not rename files that are encrypted, but will encrypt all files that have the following extensions:
How to Decrypt NemucodAES Ransomware
To decrypt files that are encrypted by NemucodAES ransomware, you must first download NemucоdAES Decryptor.
https://decrypter.emsisoft.com/download/
Once you've downloaded it, just double-click the executable to start the decrypt. You will be prompted by a UAC question. Click Yes to proceed.
The decryptor will try to retrieve your files and this may take a few hours.