CharlesTalk

Member
  • Content Count

    5
  • Joined

  • Last visited

Community Reputation

1 Neutral

About CharlesTalk

  • Rank
    New Member

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. https://www.sendspace.com/file/s5ndbp
  2. I am sending again with the email. What kind of ransomware is this? Is there a decryptor? .HelloAgain.README.TXT
  3. This ransomware created a task in windows to execute a powershell script. In freezing we were able to recover the files using a kaspersky decryptor Some machines only have the information file for recovery. It's the same as freezedbywizard. The email is the same. The difference is the name for HelloAgain Virus Total: https://www.virustotal.com/gui/file/46c0e2cb833a77695d9ed94c8c09b4be178bc80b2288c48b6d7649e4323e3e04/detection https://www.virustotal.com/gui/file/cfb6205c0165002f9b11bac6853de1793774b7c1315fc5fdef9989b83b7f60a0/detectionl UWT4 Home Page.URL.HelloAgain Read Me First.txt.HelloAgain
  4. Hello, The first time we were targeted by .Freezing, now for the second time we were targeted by .HelloAgain. There are no recovery notes on disk C