We can decrypt any .DATAWAIT and .INFOWAIT variants even without the ransom note : we absolutly need a pair of crypted/original file bigger than 150 Ko to brute force the key.
For the other variants we have to check each request to confirm.
You can contact me directly at emte@adc-soft.com
Hi, thank you for your efforts.
I wanted to check, is decryption still not free for users who doesn't have Dr.Web licence during the ransomware accident ... as you said in the previous posts? (Especially .DATAWAIT)
Yes, Dr.Web decryptors are never free, except for computers with Dr.Web antivirus in use when the files have been encrypted. The charges are reasonable, 150 EUR.
If and when a free decryptor will be available, you will be informed immediatly by the Bleeping Computer Forum.
Kind regards,
Emmanuel - emte@adc-soft.com
--
Emmanuel Teillard d'Eyry – Support Service Manager
ADC-Soft | 18bis, rue de l'Est - 92100 Boulogne-Billancourt (France)
emte@adc-soft.com - Phone: +33 (0) 967 37 28 90
Partner of Dr.Web for ransomware decryption : https://partners.drweb.com/find_partner?mode=search&country=64&city=1161&searchByName=&lng=en