I can find almost NO info on this infection which encrypts & renames files with an ".ihelperpc" extension.
It provides a large key and asks you to mail a picture or small file to them.
The instructions / ransom banner file : https://www.sendspace.com/file/t5hqvm
A sample encrypted file: https://www.sendspace.com/file/t0ez2e
The jist of the ransom note:
☠ FILE RECOVERY INSTRUCTIONS! ☠All your files have received a secret permission.
To remove this permission and restore all data you need:
Send 1 image or text file (less than 10mb) to mail firstname.lastname@example.org.In the response message we will send the recovered file and further instructions for recovery.
In the message include your personal ID (look at the beginning of this document).
Alternative communication channel - telegram, https://desktop.telegram.org/, our contact: @decryptionfiles
- If you have not received a response to your message more than 12 hours, write to an alternate email address email@example.com or use telegram
- Attempts to run the anti-virus tools will result in the loss of your data
- Attempts to self-decrypting files will result in the loss of your data
- Decoders other users are not compatible with your data, because each user has a unique key
Any help would be greatly appreciated. Thank you.