Once it has started, PHP script will scan the drives for targeted files, and after detecting them will start by encrypting them.
Unlike other ransomware, NemucodAES does not add any new extension or rename the files that are encrypted, but will encrypt all files that have the following extensions:
File Extensions
.123, .602, .dif, .docb, .docm, .dotm, .dotx, .hwp, .mml, .odg, .odp, .ods, .otg, .otp, .ot, .ot, .pot , .potm, .potx, .ppx, .ppsm, .ppsx, .pptm, .sldm, .sldx, .slk, .stc, .std, .sti, .stw, .sxc, .sxd ,. Sxm, .sxw, .txt, .uop, .uot, .wb2, .wk1, .wks, .xlc, .xlm, .xlsb, .xlsm, .xlt, .xltm, .xltx, .xlw, .xml, .asp, .bat, .brd, .cd, .cmd, .dch, .dip, .jar, .js, .rb, .sch, .sh, .vbs, .3g2, .fla, .m4u, .swf .bmp, .cgm, .djv, .gif, .nef, .png, .db, .dbf, .frm, .ibd, .ldf, .myd, .myi, .onenotec2, .sqlite3, .sqlitedb ,. Paq, .tbk, .tgz, .xNUMXdm, .asc, .lay, .lay3, .ms6, .ms11, .crt, .csr, .key, .p11, .pem, .qcow12, .vmx, .aes, .zip, .rx, .rxNUMX, .r2, .r00, .r01, .zz, .tar, .gz, .gzip, .arc, .arj, .bz, .bz02, .bza, .bzip, .bzip03 , .xls, .xlsx, .doc, .docx, .pdf, .djvu, .fb2, .rtf, .ppt, .pptx, .pps, .sxi, .odm, .odt, .mpp ,. Ssh, .pub, .gpg, .pgp, .kdb, .kdbx, .als, .aup, .cpr, .npr, .cpp, .bas, .asm, .cs, .php, .pas, .class, .py, .pl, .h, .vb, .vcproj, .vbproj, .java, .bak, .backup, .mdb, .accdb, .mdf, .odb, .wdb, .csv, .tsv, .sql , .psd, .eps, .cdr, .cpt, .indd, .dwg, .ai, .svg, .max ,. Skp, .scad, .cad, .xNUMXds, .blend, .lwo, .lws, .mb, .slddrw, .sldasm, .sldprt, .u2d, .jpg, .jpeg, .tiff, .tif, .raw, .avi, .mpxNUMX, .mpeg, .mpe, .wmf, .wmv, .veg, .mov, .xNUMXgp, .flv, .mkv, .vob, .rm, .mp2, .wav, .asf, .wma , .mxNUMX, .midi, .ogg, .mid, .vdi, .vmdk, .vhd, .dsk, .img, .iso
To decrypt files that are encrypted by NemucodAES ransomware, you must first download NemucоdAES Decryptor.
After downloading it, simply double-click the executable to launch the decryptor. You will be prompted by UAC. Click on button Yes to move on.
The decryptor will try to retrieve your files and this may take a few hours.