WARNING:
- in order to work correctly, those tools requires to be run directly on the infected machine (not on any other machine where the encrypted files were moved).

----------------
This package contains 2 commandline tools:
1) VindowsKeygen.exe
2) VindowsDecryptor.exe

For your convenience, there are also optional run files, that you can edit supplying your parameters to above tools:
1) run_keygen.bat
2) run_decryptor.bat

Folder 'headers' contains a set of headers for supported formats - their role will be explained further.
----------------
Use VindowsKeygen first, in order to find your key.
You need to prepare 1 encrypted file along with it's decrypted copy. Supply them to the keygen via command line:

VindowsKeygen.exe <encrypted file> <valid file>

Example:

VindowsKeygen.exe square1.png.vindows square1.png
---
If you do not have a valid copy of any of your files, 
instead of the valid file you can use one of the pre-prepared headers, that you will find in this package.
Choose a header from 'headers' directory, that has an extension corresponding to your encrypted file, i.e.:

VindowsKeygen.exe square1.png.vindows 16.png

Wait for your key to be generated. It may take from few seconds up to few minutes.
The key will be dumped to the file: vindows_key.txt
----------------
When you have your key generated, copy it from the file vindows_key.txt and use VindowsDecryptor to recover the rest of your files.
Example:
VindowsDecryptor.exe csVHRwL40U6Q2guvG&V!XR=jIx59BT1a

Wait for your files to be decrypted.
In case of any problems, please don't hesitate to contact: hasherezade@gmail.com

