NemucodAES; Fabian Wosar of her Emsisoft just released a decryptor for NemucodAES Ransomware. The malicious file that comes with spam emails contains a JS file that will download a PHP script, which is the real ransomware.
Once it has started, PHP script will scan the drives for targeted files, and after detecting them will start by encrypting them.
Unlike other ransomware, NemucodAES does not add any new ones extension and does not rename files that are encrypted, but will encrypt all files that have the following extensions:
How to Decrypt NemucodAES Ransomware
To decrypt files that are encrypted by NemucodAES ransomware, you must first download NemucоdAES Decryptor.
https://decrypter.emsisoft.com/download/
After downloading it, simply double-click the executable to launch the decryptor. You will be prompted by UAC. Click on button Yes to move on.
The decryptor will try to retrieve your files and this may take a few hours.