I wasn't able to locate anything via Google, and so was unable to "decrypt" the files (password-protected RARs).
The customer ended up paying these scum.

http://www.bleepingcomputer.com/virus-removal/remove-decrypt-accdfisa-protection-program
Has anyone seen this variant before (and know the password by chance)?
Update - e-mail address listed on the infection is down and customer unable to access via phone. We're proceeding with infection removal, but are nowhere with the password to return the customer files to their original state.


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Back to top








