See prices in :
See prices in :

Decrypting ransomware

How to decrypt your files infected by ransomware using AVAST.

Understanding ransomware

Ransomware Has it encrypted all your files and is demanding a ransom to decrypt them? Do not pay the ransom; instead, use one of our free decryption tools

Decrypting AES_NI:
This ransomware was first detected in December 2016. It uses AES-256 combined with RSA-2048 to encrypt files.
Changing file names: .aes_ni, .aes256, .aes_ni_0day
Ransom note: The message contains a file called «!!! READ THIS – IMPORTANT !!!.txt»
DECRYPTING AES_NI

Understanding Alcatraz Locker:
Alcatraz Locker is a virus that was discovered in November 2016. To encrypt your files, this ransomware uses AES-256 encryption combined with Base64 encoding.
Changing file names: Files encrypted by this virus have the extension «.Alcatraz»
Ransom note: The ransom note is a file called ransomed.html which appears on the user’s PC.
DECRYPTING ALCATRAZ LOCKER

Unravelling Apocalypse:
Apocalypse is a ransomware strain that first appeared in June 2016.
Changing file names: Files encrypted by this virus have the extensions «.encrypted», «.FuckYourData», «.locked», «.Encryptedfile» or «.SecureCrypted»
Ransom note: The ransom note is a file with the extension «.How_To_Decrypt.txt» «, ».README.txt«, ».Contact_Here_To_Recover_Your_Files.txt«, ».How_to_Recover_Data.txt« or ».Where_my_files.txt’
DECIPHERING THE APOCALYPSE

Understanding AtomSilo & LockFile:
AtomSilo and LockFile use a very similar encryption scheme. Our decryptor covers both variants.
Changing file names: Encrypted files have the following file extensions: .ATOMSILO or .lockfile
Ransom note: In every folder containing at least one encrypted file, there is a ransom note named README-FILE-%ComputerName%-%Number%.hta or LOCKFILE-README-%ComputerName%-%Number%.hta.
DECRYPTING ATOMSILO / LOCKFILE

Deciphering Babuk:
Babuk is a Russian ransomware programme.
Changing file names: Your files have one of the following extensions: .babuk, .babyk or .doydo
Ransom note: In every folder containing at least one encrypted file, you will find the file ‘Help Restore Your Files.txt’
DECIPHERING BABUK

Understanding BadBlock
BadBlock is a ransomware strain discovered in May 2016.
Changing file names: BadBlock does not rename your files.
Ransom note: The ransom note is a file called Help Decrypt.html (usually a message displayed on a red background).
DECRYPTING BADBLOCK

Understanding Bart:
Bart is a ransomware strain that first appeared in late June 2016.
Changing file names: Bart adds the extension «.bart.zip» to the end of each file. This turns your files into encrypted ZIP archives.
Ransom note: The ransom note consists of a file called ‘recover.bmp’ and a file called ‘recover.txt’
UNDERSTANDING BART

Unravelling BigBobRoss:
BigBobRoss encrypts files using the AES128 protocol.
Changing file names: The files have the extension .obfuscated
Ransom note: The BigBobRoss ransomware creates a text file called «Read Me.txt»
DECIPHERING BIGBOBROSS

Understanding BTCWare:
This ransomware has five variants that use two encryption methods: RC4 and AES-192
Changing file names: File names are encrypted using the following variants: foobar.docx.[sql772@aol.com].theva, foobar.docx.[no.xop@protonmail.ch].cryptobyte, foobar.bmp.[no.btc@protonmail.ch].cryptowin, foobar.bmp.[no.btcw@protonmail.ch].btcware, foobar.docx.onyon
Ransom note: Once your files have been encrypted, your computer’s desktop background changes to display a ransom note on a red background.
DECRYPTING BTCWARE

Decrypting Crypt888:
Crypt888 (also known as Mircop) is a type of ransomware first discovered in June 2016.
Changing file names: Crypt888 adds «Lock.» to the start of each file (e.g. Filename.doc = Lock.Filename.doc)
Ransom note: The ransom note appears as a new wallpaper.
DECRYPT CRYPT888

Unravelling CrySis:
CrySis (also known as JohnyCryptor, Virus-Encode or Aura) is a ransomware strain that first appeared in September 2015. It uses AES-256 encryption combined with RSA-1024 encryption.
Changing file names: Encrypted files have various file extensions, such as: «.johnycryptor@hackermail.com.xtbl», «.ecovector2@aol.com.xtbl», «.systemdown@india.com.xtbl» «, ».Vegclass@aol.com.xtbl«, ».{milarepa.lotos@aol.com}.CrySiS«, ».{Greg_blood@india.com}.xtbl«, ».{savepanda@india.com}.xtbl«, ».{arzamass7@163.com}.xtbl”
Ransom note: The ransom note appears as a file named «Decryption instructions.txt», «Decryptions instructions.txt» or «*README.txt»
DECIPHERING CRYSIS

Decrypting EncrypTile:
This ransomware uses AES-128 encryption with a fixed encryption key for each computer or user.
Changing file names: This ransomware adds the word «EncrypTile» to the names of your files
Ransom note: This ransomware installs a file called «How to buy bitcoin_IL4NzIT321.txt»
DECRYPTING ENCRYPTILE

Understanding FindZip:
FindZip is a ransomware programme that spreads on Mac OS X (version 10.11 or later).
Changing file names: Encrypted files have the .crypt extension
Ransom note: A ransom note file named DECRYPT.txt, HOW_TO_DECRYPT.txt or README.txt is created on the user’s desktop.
DECRYPTER FINDZIP

Understanding Globe:
Globe is a ransomware programme that was discovered in August 2016. Depending on the version of Globe, the encryption method used is either RC4 or Blowfish.
Changing file names: Encrypted files have one of the following extensions: «.ACRYPT», «.GSupport[0-9] », «.blackblock», «.dll555», «.duhust», «.exploit», «.frozen», «.globe», «.gsupport», «.kyra », «.purged», «.raid[0-9]», «.siri-down@india.com», «.xtbl», «.zendrz» or «.zendr[0-9]»
Ransom note: The ransom note appears as a file called «How to restore files.hta» or «Read Me Please.hta»
DECRYPTER GLOBE

Unravelling Legion:
Legion is a ransomware strain that first appeared in June 2016.
Changing file names: Encrypted files have one of the following file extensions: «._23-06-2016-20-27-23_$f_tactics@aol.com$.legion» or «.$centurion_legion@aol.com$.cbf»
Ransom note: Legion changes your computer’s desktop background and displays a pop-up window asking you to send an email to a specific address.
DECIPHERING LEGION

Decrypting NoobCrypt:
Changes to file names: NoobCrypt does not change the file extensions of your files; however, these files can no longer be opened using their designated applications. (e.g. a .txt file can no longer be opened using Notepad).
Ransom note: The ransom note appears as a file called «ransomed.html»
DECRYPTING NOOBCRYPT

Understanding SZFLocker:
Changing file names: SZFLocker adds the «.szf» extension to your files.
Ransom note: When you try to open one of your encrypted files, a ransom note appears (usually in Polish).
DECRYPTING SZFLOCKER

Understanding TeslaCrypt:
TeslaCrypt is a ransomware strain that first appeared in February 2015.
Changing file names: The latest versions of TeslaCrypt do not rename your files.
Ransom note: A message appears on your PC asking you to follow the instructions to pay the ransom on one of the following websites: «u24er.ovaarmor.com», «123d.feustude.at» or «k234.ascotprue.com»
DECRYPTING TESLACRYPT

Deciphering HiddenTear:
It is one of the first open-source ransomware programmes to be hosted on GitHub in August 2015. Since then, hundreds of versions of HiddenTear have been produced. HiddenTear uses AES encryption.
Changing file names: Encrypted files have one of the following extensions: .locked, .34xxx, .bloccato, .BUGSECCCC, .Hollycrypt, .lock, .saeid, .unlockit, .razy, .mecpt, .monstro, .lok, .8lock8, .fucked, .flyper, .kratos, .krypted, .CAZZO, .doomed.
Ransom note: After encrypting the files, the ransomware displays the ransom note in the form of a file: READ_IT.txt, MSG_FROM_SITULA.txt, DECRYPT_YOUR_FILES.HTML
DECRYPTING HIDDENTEAR

Understanding Jigsaw:
Jigsaw is a ransomware strain that first appeared in March 2016. This ransomware is named after an online game, *The Jigsaw Killer*, and most variants of this ransomware display a ransom note featuring the game’s colour scheme.
Changing file names: The encrypted files have one of the following extensions: .kkk, .btc, .gws, .J, .encrypted, .porno, .payransom, .pornoransom, .epic, .xyz, .versiegelt, .encrypted, .payb, .pays, .payms, .paymds, .paymts, .paymst, .payrms, .payrmts, .paymrts, .paybtcs, .fun, .hush, .uk-dealer@sigaint.org, .gefickt.
Ransom note: After encrypting the files, the ransomware displays the ransom demand in the form of a message containing a timer, explaining that after a certain period of time has elapsed, files will be deleted until the ransom is paid.
DECIPHERING JIGSAW

Deciphering Stampado:
Stampado is a strain of ransomware that uses the AutoIt encryption tool. It first appeared in August 2016. It continues to be distributed on the dark web, which explains the resurgence of new versions. One of these versions is called Philadelphia.
Changing file names: This ransomware adds the .locked extension to your files.
Ransom note: A ransom note reading «Your files have been encrypted by Stampado» appears on your screen.
DECIPHERING STAMPADO

Is the ransomware that encrypted your files not on this list?
Avast is working with the NoMoreRansom project, a public-private initiative aimed at combating ransomware. It brings together all the available ransomware decryption solutions. You can view the list of all available decryption tools here:
https://www.nomoreransom.org/fr/decryption-tools.html
This list is updated regularly, as soon as a decryption solution is discovered for a new ransomware strain.

Ransomware FAQ:

If I am hit by a ransomware attack, should I pay the ransom?
No. Under no circumstances should you pay the ransom. This funds cybercrime, leaves you vulnerable to future attacks and offers no guarantee that you will get your files back.
If you are hit by a ransomware attack, you must isolate the infected device by disconnecting it from the internet and the network, to prevent your other devices from becoming infected. Then, report the attack on cybermalveillance.gouv.fr
For the encrypted files, note down the name of the file extension that was added to your files during the encryption process. Using the file extension of the encrypted files, you will be able to identify the name of the ransomware that has infected your system. Once you have identified the ransomware, try to check whether a decryption solution exists and use this decryption tool to clean your system and recover your files.
If there is no decryption tool available for your ransomware, reset your PC to its factory settings by deleting all data and restoring the operating system to its original configuration. Then, use your backups to recover your files.

Why is it so difficult to find a decryption solution for ransomware?
Ransomware uses robust encryption algorithms, designed specifically so that they cannot be easily decrypted (AES or RSA with very long keys). Only the hackers have the private key required for decryption, and without this key, it is very difficult to break their encryption algorithms.
However, entire teams of engineers are working full-time on the problem to provide you with decryption tools, even though these tools do not cover all variants of ransomware. That is why it is essential to protect yourself against ransomware with an antivirus programme that includes an anti-ransomware shield, such as Avast Premium Security, for private individuals and Avast Essential Business Security for businesses.

Who are the victims of ransomware?
Anyone can fall victim to ransomware. Hackers target both individuals with little protection and businesses with poorly secured infrastructure, who often pay the ransom out of fear of bad publicity or the disclosure of their customers’ data on the dark web.
Ransomware also targets local authorities and hospitals, which rely on uninterrupted service and store sensitive data.

How can you protect yourself effectively against ransomware?
The first line of defence is still the use of a comprehensive security suite that includes a ransomware shield such as Avast Premium Security, for private individuals or Avast Essential Business Security for businesses.
Make sure you back up your data regularly and never leave your backup devices connected all the time. Avast Business Cloud Backup is specifically designed to enable businesses to recover their data quickly in the event of an incident.
Be wary of suspicious attachments and links in your emails. Avast includes an Email Shield in all its antivirus solutions, which blocks malicious attachments and emails before they reach your inbox.
Ransomware can also find its way onto your devices via out-of-date software, which is why it is essential to keep your software up to date. The Software Updater from’Avast Premium Security automates the updating of third-party software (Java, Adobe, etc.). For businesses, Avast has designed Avast Business Patch Management which centralises the management of patches for all the software in your IT infrastructure via a centralised management console.
Finally, remember to raise your users’ awareness of cyber risks. Our Avast blog is packed with useful information on the various cyber security threats you may encounter, how to spot them and how to protect yourself against them.