I have already used ID Ransomware (but it didn't answer my question) : https://id-ransomware.malwarehunterteam.com/
I have scaned all files by Malwarebytes and as a result it have found:
- Cerber
- Cerber.NSIS
- Locky
But the behavior of ransomware that encrypted my files is not similar to Cerber and Locky so I still don't know what to use to decrypt my files.
So, can you help me to identify which ransomware encrypted my files?
Behavior that I have noticed:
- no file names, and extensions have been changed
- on each disk and on desktop i have found text files: Your "files are locked !.txt", "files are locked !!.txt", "files are locked !!!.txt", "files are locked !!!!.txt", "files are locked !!!!!.txt"
- content of "files are locked !.txt":
Support e-mail: suppcop@india.com suppcop@yandex.ru
Your personal files encryption produced on this computer: photos, videos, documents, etc.
Encryption was produced using a unique public key RSA-2048 generated for this computer.
To decrypt files you need to obtain the private key.
The single copy of the private key, which will allow to decrypt the files,
located on a secret server on the Internet; the server will destroy the key after 120 hours.
After that nobody and never will be able to restore files.
To obtain the private key for this computer, you need pay 0.2 Bitcoin (~145 USD)
I have no idea how should I identify what ransomware has encrypted my files, because this behaviour, as I read, is not common for Cerber and Locky.
Please help me