如果您正在寻找一种方法来解密被勒索软件加密的文件,那么这个勒索(Ransomware)软件解密和删除工具(Ransomware decrypt & removal tools)的完整列表将帮助您在Windows计算机上解锁被勒索软件加密或锁定的文件。勒索软件(Ransomware)的威胁正在上升,每隔一天我们就会看到它——无论是WannaCrypt、Petya 还是 Locky 勒索软件。这类恶意软件现在似乎是最受欢迎的,因为它非常有利可图——锁定用户的文件和数据,然后要求资金解锁。
虽然可以采取一些基本步骤来防止勒索(prevent ransomware)软件,包括使用一些免费的反勒索软件(free anti-ransomware software),但您仍然可能最终成为某些勒索软件的受害者。
那么,在您的 Windows 计算机上遭到勒索软件攻击后该怎么办?(what does one do after a Ransomware attack)(Well, what does one do after a Ransomware attack on your Windows computer?)
你能解密勒索软件吗?
如果勒索软件解密工具(Ransomware Decryption Tool)可用于锁定您文件的恶意软件,那么您将能够解密和恢复文件的机会非常高。如果没有这样的工具可用,那么最好的选择是使用您的备份文件。如果您决定付款,那么他们给您的私钥几乎总是可以工作并帮助解密文件。
勒索软件解密工具
首先,确定感染您计算机的勒索软件。为此,您可以使用名为ID Ransomware的免费在线服务(ID Ransomware)
如果您能够识别勒索软件,请检查是否有适用于您的勒索软件类型的勒索软件解密工具。目前,可以使用以下解密工具。
You may go through the entire list or press Ctrl+F and search for a specific ransomware name.
在使用这些工具之前,请使用任何好的防病毒软件或勒索软件删除工具来删除勒索软件。只有这样,您才应该使用这些勒索软件文件解密工具。但是,如果您已将加密文件移动到另一个隔离的安全系统,则可以直接使用这些工具。
1] HydraCrypt 和 UmbreCrypt 勒索软件的解密器:HydraCrypt和UmbreCrypt是(UmbreCrypt)CrypBoss 勒索软件(CrypBoss Ransomware)系列中的两个新勒索软件(Ransomware)变体。一旦成功破坏了您的 PC 安全,HydraCrypt和UmbreCrypt可以锁定您的计算机并拒绝访问您自己的文件。
2] CryptoLocker 解密工具:这款免费的 Decryptlocker(Decryptlocker)或CryptoLocker 解密(CryptoLocker Decryption)在线工具来自FireEye和Fox-IT,用于解密Cryptolocker加密文件。更新:(UPDATE:)该网站似乎已被删除。
3] Petya 勒索软件解密工具和密码生成器:PETYA 勒索软件是 PC 用户最近的在线威胁之一。它是一种恶意软件,它会覆盖您 PC 的MBR(主引导记录(Master Boot Record))并使其无法启动,并且还不允许在安全模式下(Safe Mode)重新启动 PC 。
4] Operation Global III Ransomware Decryption Tool : 该勒索软件攻击您的系统,然后显示一个让用户别无选择,只能支付赎金金额。您所有的加密文件扩展名都更改为 .EXE 并感染了恶意代码。
5]使用Emsisoft 的此工具(this tool)解锁被(Unlock)Decrypt Protect勒索软件锁定的文件。
6] Emsisoft发布了几个用于勒索软件的解密工具。该列表目前包括勒索软件解密工具,用于:
AutoLocky,Aurora,Nemucod,DMALocker2,HydraCrypt,UmbreCrypt,DMALocker,CrypBoss,Gomasom,LeChiffre,KeyBTC,Radamant,CryptInfinite,PClock,CryptoDefense,Harasom,Xorist,777,BadBlock,DApocalypse,ApocalypseVM,Philadelphia, Stampado ,Fabian(Stampado),Stampado(Fabiansomware)FenixLocker、Al-Namrood、Globe、OzozaLocker、Globe2、NMoreira或(NMoreira)XRatTeam(PewCrypt)或 XPan 、OpenToYou或OpenToDecrypt、GlobeImposter、MRCR、Globe3、Marlboro、OpenToYou、CryptON、Damage、Cry9、Cry128、Amnesia、Amnesia2、Nemucodew (NemucodAES)AES(BigBobRoss)、BigB加密宠物小精灵,ZQ Ransomware , MegaLocker , JSWorm 2.0 , GetCrypt , Ims00rry , ZeroFks , JSWorm 4.0(JSWorm 4.0) , WannaCryFake , Avest , Muhstik , HildaCrypt , STOP Djvu , Stop Puma , Paradise , Jigsaw , Hakbit , TurkStatik , ChernoLocker , Ransomwared , KokoR(KokoKrypt) , Zorab(JavaLocker) , Java (RedRum)Red(Zorab) ,SpartCrypt、CheckMail7、Crypt32、Cyborg、Ziggy、Avaddon、SynAck、Ragnatok。
您可以在他们的官方网站(official website)上免费获得它们以及详细的使用指南。
7]思科(Cisco)还为TeslaCrypt 勒索软件受害者(TeslaCrypt Ransomware Victims)提供免费的解密工具(Decryption Tool)。这个TeslaCrypt 解密工具(TeslaCrypt Decryption Tool)是一个开源命令行实用程序,用于解密TeslaCrypt勒索软件加密的文件,以便用户的文件可以恢复到原始状态。在此处(here)阅读更多信息。
8] Cisco Talos发布了PyLocky勒索软件解密工具。该解密器旨在为受勒索软件 PyLocky(PyLocky)影响的受害者解密文件。
9] TeslaCrack 可在GitHub 上(GitHub)获得。它将帮助您解密使用最新版本的TeslaCrypt勒索软件加密的文件。
10] Trend Micro AntiRansomware Tool将帮助您通过删除受感染计算机上的勒索软件来收回计算机的所有权。要使用此工具,请进入带网络连接的(Networking)安全模式(Safe Mode)。下载(Download)反勒索(Anti-Ransomware)软件并将其保存到您的桌面。接下来双击它进行安装。安装完成后,重新启动计算机并进入勒索软件锁定屏幕的正常模式。 现在通过按以下键触发反勒索软件:(Anti-Ransomware)Left CTRL+ALT+T+I。运行扫描(Scan),清理(Clean)然后重新启动(Reboot)你的电脑。此工具在ICE 勒索软件(ICE Ransomware)感染的情况下很有用。
11]趋势科技勒索软件屏幕解锁工具(Trend Micro Ransomware Screen Unlocker Tool)将让您访问勒索软件阻止的计算机。
12] Trend Micro Ransomware File Decryptor工具将尝试解密由某些 Ransomware 系列加密的文件,例如(Ransomware)CryptXXX 、(CryptXXX) Crysis 、(Crysis) DemoTool 、(DemoTool) DXXD 、(DXXD) TeslaCrypt 、(TeslaCrypt) SNSLocker 、(SNSLocker) AutoLocky 、(AutoLocky) BadBlock 、(BadBlock) 777、XORIST、Teamxrat/Xpan、XORBAT、CERBER、Stampado、Nemucod , Chimera , LECHIFFRE , MirCop , Jigsaw , Globe/Purge, V2:, V3: 等
13] HitmanPro.Kickstart是一款免费的勒索软件删除工具(Ransomware Removal Tool),可帮助您拯救被勒索的 PC。它允许您从USB闪存驱动器启动计算机,以删除已勒索或锁定您的计算机并且不允许您访问它的恶意软件。
14] Shade Ransomware Decryption Tool将帮助解密具有以下扩展名的文件:.xtbl、.ytbl、.break_bad(.breaking_bad)、.heisenberg。从McAfee Intel获取。
15] McAfee Ransomware Recover是一种工具和平台,不仅可以解锁用户文件、应用程序、数据库和其他加密文件,而且还可供安全社区使用。
16] AVG还发布了针对以下勒索软件的勒索软件解密工具:
Apocalypse, Bart ransomware, BadBlock, Crypt888, Legion, SZFLocker, TeslaCrypt.
去把他们都拿来(here)。
17] Check Point发布了Cerber Ransomware 解密工具(Cerber Ransomware Decryption Tool)。这是一个在线工具,您必须在其中上传文件。更新:此Cerber 勒索软件解密工具已失效。CheckPoint(from CheckPoint)的 Merry X-Mas Decryptor可以解密由Merry X-Mas勒索软件加密的文件。BarRax解密工具旨在解密由BarRax加密的文件。可(Available)在CheckPoint获得。
18] NoobCrypt勒索软件的解密密钥已在Twitter上发布。如果您的计算机被感染,请使用这些解锁密钥ZdZ8EcvP95ki6NWR2j或lsakhBVLIKAHg 。
19] Bitdefender发布了以下勒索软件解密工具:Bart Ransomware Decryptor | Linux.Encoder.3 | Darkside 勒索软件解密工具| Linux.Encoder.1 | 比特币(BTCWare)| GandCrab 解密器 | 安娜贝尔解密器(Annabelle Decryptor)。
20] CoinVault解密工具解密由Coinvault和Bitcryptor加密的文件。ChimeraDecryptor工具旨在解密由Chimera加密的文件。从NoMoreransome.org(NoMoreransome.org)获取它们。
21] Vindows Ransomware Decryption Tool将帮助解密被Vindows Locker锁定的文件。在这里(here)下载。
22]从BleepingComputer下载 Decryptor(Download Decryptor)以解密 8lock8 勒索软件加密文件。
23] Crypren(Decryptor)勒索软件加密文件的解密器可在此处(Crypren)获得(here)。
24] Crypt38(Decryptor)勒索软件加密文件的解密器可在此处(Crypt38)获得(here)。
25] CryptInfinite或DecryptorMax(Decryptor)的解密(DecryptorMax)器可在此处(here)获得。
26] 对于CryptoHost ,您可以使用由(CryptoHost)Michael Gillespie创建的密码生成器。该文件托管在Dropbox上。
27]用于 my-Little-Ransomware 的解密器可在Github(Decryptor)上(Github)找到。
28] CERT-PL为CryptoMix 解密器发布了一个(CryptoMix Decryptor)
29]爆米花解密工具(Popcorn Decryptor Tool)可在此处获得。
30] Avast发布了以下勒索软件的解密工具:
AES_NI, Alcatraz Locker, Apocalypse, AtomSilo & LockFile, Babuk, BadBlock, Bart, BigBobRoss, BTCWare, Crypt888, CryptoMix, CrySiS, EncrypTile, FindZip, Fonix, GandCrab, Globe, HiddenTear, Jigsaw, LambdaLocker, Legion, NoobCrypt, Stampado, SZFLocker, TeslaCrypt, Troldesh, Shade, XData.
把它们都弄到这里(here)。
31] ESET Crysis Decryptor是一款针对(ESET Crysis Decryptor)Crysis勒索软件受害者的免费解密工具。从Eset下载。它还将删除Dharma勒索软件。他们还发布了用于CryCryptor勒索软件的(Decryptor)解密(CryCryptor)器,可在Github上找到。
32]如果勒索软件完全阻止对您计算机的访问,甚至限制对某些重要功能的访问,(Ransomware)卡巴斯基 WindowsUnlocker会很有用,因为它可以清理受勒索软件感染的注册表。
33]卡巴斯基的(Kaspersky)RannohDecryptor将帮助解密由 Rannoh、AutoIt、Fury、Crybola、Cryakl、CryptXXX、CryptXXX v.2、CryptXXX v.3、MarsJoke、 Polyglot、Dharma勒索软件加密的文件。从这里(here)下载。
34]卡巴斯基(Kaspersky)还发布了其他几个解密工具,如Rector Decryptor、Rakhni Decryptor、Wildfire Decryptor、Scraper Decryptor、Shade Decryptor、Scatter Decryptor、Xoris Decryptor等——去这里(here)获取它们。他们将解密由Rakhni、Agent.iih、Aura、Autoit、Pletor、Rotor、Lamer、Lortok、Cryptokluchen、Democry、Bitman、TeslaCrypt和其他勒索软件。
35] Kaspersky Ransomware Decryptor将自动解密CoinVault和Bitcryptor受害者的所有文件。在这里(here)得到它。对于Cryakl(Cryakl)勒索软件,它也有帮助。
36] 访问Kaspersky NoRansom网页,了解他们是否为您的勒索软件发布了解密工具。目前,该页面显示WildfireDecryptor工具、ShadeDecryptor工具、RakhniDecryptor、RannohDecryptor工具和CoinVaultDecryptor工具的可用性。还包括有关勒索软件的手册操作方法和其他有用资源。英特尔迈克菲(Intel McAfee)还制作了Wildfire Decryptor。
RakhniDecryptor将帮助解密由Dharma、Crysis、Chimera、Rakhni、Agent.iih、Aura、Autoit、Pletor、Rotor、Lamer、Lortok、Cryptokluchen、Democry、Bitman ( TeslaCrypt ) 版本 3 和 4 勒索软件加密的文件。
37] Malwarebytes发布了Telecrypt Ransomware Decrypter Tool来解密受(Telecrypt Ransomware Decrypter Tool)Telecrypt Ransomware感染的文件。在这里(here)下载。
38]勒索软件研究人员Michael Gillespie发布了这些勒索软件解密工具:
Aurora Ransomware Decrypter, FilesLocker Ransomware Decrypter, InsaneCrypt Decryptor for desuCrypt Ransomware, GIBON Ransomware Decryptor, Striked Ransomware Decrypter, DCry Ransomware Decrypter, BitKangaroo Decrypter, BTCWare Ransomware Decrypter, Crypt38 Ransomware Decrypter, BitStak Ransomware Decrypter, Alpha Ransomware Decryptor, Unlock92 Ransomware Decrypter, Hidden Tear Ransomware Decrypter, Hidden Tear Brute Forcer Ransomware decryptor, PowerWare Locky Ransomware Decrypter, GhostCrypt Ransomware Decrypter, MicroCopy Ransomware Decryptor, Jigsaw Ransomware Decrypter, STOP Decrypter.
此外,他还发布了以下有用的工具:
- StupidDecryptor解密由各种屏幕储物柜加密的文件,这些文件很容易解密
- RansomNoteCleaner 可用于扫描勒索软件受害者的计算机以查找剩余的赎金记录并将其删除
- CryptoSearch 从勒索软件感染中清除您计算机上的加密文件和勒索记录。
39] TeslaCrypt 勒索软件的主密钥已发布。来自英特尔(Intel)的 Tesladecrypt将解密具有以下扩展名的TeslaCrypt加密文件:.mp3、 (TeslaCrypt).micro、.xxx和.ttt。
40] BTCWareDecrypter将解密由BTCWare Ransomware加密的文件。在这里(here)得到它。
41] 360 勒索软件解密工具可以解密被 80 多种勒索软件锁定的文件,包括GandCrab、Petya、Gryphon、GoldenEye和WannaCry勒索软件。
42] 在有利的条件下,WannaKey 和 WanaKiwi这两个WannaCrypt解密工具可以通过检索勒索软件使用的加密密钥来帮助解密WannaCrypt或WannaCry勒索软件加密的文件。(WannaCry Ransomware)
43]孤岛危机解密工具(Crysis Decrypting Tools)由Eset 和 Avast 开发。
44] QuickHeal的勒索软件解密工具将解密被以下勒索软件锁定的文件 –
Troldesh Ransomware [.xtbl], Crysis Ransomware [.CrySiS], Cryptxxx Ransomware [.crypt], Ninja Ransomware [@aol.com$.777], Apocalypse Ransomware [.encrypted], Nemucod Ransomware [.crypted], ODC Ransomware [.odcodc], LeChiffre Ransomware [.LeChiffre], Globe1 Ransomware [.hnyear], Globe2 Ransomware [.blt], Globe3 Ransomware [.decrypt2017], DeriaLock Ransomware [.deria], Opentoyou Ransomware [[email protected]], Globe3 Ransomware [.globe & .happydayzz], Troldesh Ransomware [.dharma], Troldesh Ransomware [.wallet], Troldesh Ransomware [.onion], Satan DBGer Ransomware [.dbger]. STOP Djvu Ransomware, GandCrab Ransomware.
在这里(here)下载。
45] Ransomware Removal & Response Kit不是一种工具,而是与处理勒索软件有关的指南和各种资源的汇编,可以证明是有帮助的。这是一个 500 MB 的下载。在此处(here)阅读更多相关信息。
46] 一般来说,Anvi Rescue Disk可以帮助您卸载和删除勒索软件(Ransomware)。
解密勒索软件需要多长时间?
这取决于勒索软件解密工具(Ransomware Decryption Tool)的可用性。它可能从几天到几周不等。如果您决定付款,那么他们给您的私钥几乎总是可以工作并帮助立即解密文件。
All the best!
如果您有更多免费的勒索软件解密工具要添加,请在评论部分添加,链接到他们的官方主页或下载页面。
这篇文章更多地讨论了勒索软件攻击和其他常见问题解答(Ransomware Attacks & other FAQ)。(This post talks a little more about Ransomware Attacks & other FAQ.)
List of free Ransomware Decryption Tools to unlock files
If you are looking for a way to decrypt files encrypted by Ransomware then this complete liѕt of Ransomware decrypt & removal tools will help you unlock files encrypted or locked by ransomware on your Windows computer. Ransomware threats are on the rise, and every other day we get to read about it – whether it is WannaCrypt, Petya or Locky ransomware. This class of malware seems to be the favorite now as it is very profitable – lock down users’ files and data and then demand money to unlock them.
While there are some basic steps one can take to prevent ransomware, including making use of some free anti-ransomware software, it can still happen that you end up being a victim of some ransomware.
Well, what does one do after a Ransomware attack on your Windows computer?
Can you decrypt ransomware?
If a Ransomware Decryption Tool is available for the malware that has locked down your files then the chances are very high that you will be able to decrypt and recover your files. If no such tool is available, then the best bet would be to use your backup files. If you decide to pay then the private key that they give you is almost always known to work and help decrypt the files.
Ransomware Decryption Tools
First of all, identify the Ransomware which has infected your computer. For this, you may use a free online service called ID Ransomware
If you are able to identify the ransomware, check if a ransomware decrypt tool is available for your type of ransomware. Currently, the following decryptor tools are available.
You may go through the entire list or press Ctrl+F and search for a specific ransomware name.
Before you use these tools, use any good antivirus software or ransomware removal tool to remove the ransomware. Only then should you use these ransomware file decryptor tools. However, if you have moved your encrypted files to another isolated secure system, you directly use these tools.
1] Decrypter for HydraCrypt and UmbreCrypt Ransomware: HydraCrypt and UmbreCrypt are the two new Ransomware variants from the CrypBoss Ransomware family. Once successful in breaching your PC security, HydraCrypt and UmbreCrypt can lock your computer and deny access to your own files.
2] CryptoLocker Decryption Tool : This free Decryptlocker or CryptoLocker Decryption online tool from FireEye and Fox-IT to decrypt the Cryptolocker encrypted files. UPDATE: The site appears to have been taken down.
3] Petya ransomware decrypt tool & password generator: PETYA ransomware is one of the most recent online threats for PC users. It is a malware which overwrites the MBR (Master Boot Record) of your PC and leaves it unbootable and also disallows restarting the PC in Safe Mode.
4] Operation Global III Ransomware Decryption Tool: This ransomware attacks your system and then displays a leaving the user with no choice but to pay the ransom amount. All your encrypted file extensions are changed to .EXE and are infected with malicious codes.
5] Unlock files locked by Decrypt Protect ransomware using this tool from Emsisoft.
6] Emsisoft has released several decryptor tools for ransomware. This list currently includes ransomware decryption tools for:
AutoLocky, Aurora, Nemucod, DMALocker2, HydraCrypt, UmbreCrypt, DMALocker, CrypBoss, Gomasom, LeChiffre, KeyBTC, Radamant, CryptInfinite, PClock, CryptoDefense, Harasom, Xorist, 777, BadBlock, DApocalypse, ApocalypseVM, Stampado, Fabiansomware, Philadelphia, FenixLocker, Al-Namrood, Globe, OzozaLocker, Globe2, NMoreira or XRatTeam or XPan, OpenToYou or OpenToDecrypt, GlobeImposter, MRCR, Globe3, Marlboro, OpenToYou, CryptON, Damage, Cry9, Cry128, Amnesia, Amnesia2, NemucodAES, BigBobRoss, PewCrypt, CryptoPokemon, ZQ Ransomware, MegaLocker, JSWorm 2.0, GetCrypt, Ims00rry, ZeroFks, JSWorm 4.0, WannaCryFake, Avest,Muhstik, HildaCrypt, STOP Djvu, Stop Puma, Paradise, Jigsaw, Hakbit, TurkStatik, ChernoLocker, Ransomwared, KokoKrypt, JavaLocker, RedRum, Zorab, SpartCrypt, CheckMail7, Crypt32, Cyborg, Ziggy, Avaddon, SynAck, Ragnatok.
You can get them all for free on their official website along with detailed usage guides.
7] Cisco also offers a free Decryption Tool for TeslaCrypt Ransomware Victims. This TeslaCrypt Decryption Tool is an open-source command-line utility for decrypting TeslaCrypt ransomware encrypted files so users’ files can be returned to their original state. Read more on it here.
8] Cisco Talos has released PyLocky ransomware decryptor tool. This decryptor is intended to decrypt the files for those victims affected by the ransomware PyLocky.
9] TeslaCrack is available on GitHub. It will help you decrypt files that were encrypted with the latest version of the TeslaCrypt ransomware.
10] Trend Micro AntiRansomware Tool will help you take back ownership of your computer by removing the ransomware on infected computers. To use this tool, enter Safe Mode with Networking. Download the Anti-Ransomware software and save it to your desktop. Next double-click on it to install it. Once it has been installed, restart your computer and go to the normal mode where the screen is locked by the ransomware. Now trigger the Anti-Ransomware software by pressing the following keys: Left CTRL+ALT+T+I. Run the Scan, Clean and then Reboot your computer. This tool is useful in cases of ICE Ransomware infections.
11] Trend Micro Ransomware Screen Unlocker Tool will give you access to a ransomware blocked computer.
12] Trend Micro Ransomware File Decryptor tool will attempt to decrypt files encrypted by certain Ransomware families like CryptXXX, Crysis, DemoTool, DXXD, TeslaCrypt, SNSLocker, AutoLocky, BadBlock, 777, XORIST, Teamxrat/Xpan, XORBAT, CERBER, Stampado, Nemucod, Chimera, LECHIFFRE, MirCop, Jigsaw, Globe/Purge, V2:, V3:, etc.
13] HitmanPro.Kickstart is a free Ransomware Removal Tool that will help you rescue a ransomed PC. It lets you start your computer from a USB flash drive to remove malware that has ransomed or locked your computer and does not allow you to access it.
14] Shade Ransomware Decryption Tool will help decrypt files with the following extensions: .xtbl, .ytbl, .breaking_bad, .heisenberg. Go get it from McAfee Intel.
15] McAfee Ransomware Recover is a tool and a platform that not only unlock user files, applications, databases, and other encrypted files but is also available for the security community.
16] AVG has also released ransomware decrypt tools for the following ransomware:
Apocalypse, Bart ransomware, BadBlock, Crypt888, Legion, SZFLocker, TeslaCrypt.
Go get them all here.
17] Check Point has released a Cerber Ransomware Decryption Tool. It is an online tool where you have to upload a file. UPDATE: This Cerber Ransomware Decryption Tool has been rendered ineffective. Merry X-Mas Decryptor from CheckPoint can decrypt files encrypted by the Merry X-Mas ransomware. BarRax decryptor tool is designed to decrypt files encrypted by BarRax. Available at CheckPoint.
18] The decryption keys for the NoobCrypt ransomware have been posted on Twitter. Use these unlock keys ZdZ8EcvP95ki6NWR2j or lsakhBVLIKAHg if your computer gets infected.
19] Bitdefender has released the following ransomware decryption tools: Bart Ransomware Decryptor | Linux.Encoder.3 | Darkside Ransomware Decryption Tool | Linux.Encoder.1 | BTCWare | GandCrab Decryptor | Annabelle Decryptor.
20] The CoinVault decryption tool decrypts files encrypted by Coinvault and Bitcryptor. ChimeraDecryptor tool is designed to decrypt files encrypted by Chimera. Get them all from NoMoreransome.org.
21] Vindows Ransomware Decryption Tool will help decrypt files locked by Vindows Locker. Download it here.
22] Download Decryptor from BleepingComputer to decrypt 8lock8 ransomware encrypted files.
23] Decryptor for Crypren ransomware encrypted files is available here.
24] Decryptor for Crypt38 ransomware encrypted files is available here.
25] Decryptor for CryptInfinite or DecryptorMax is available here.
26] For CryptoHost, you can use this password generator created by Michael Gillespie. The file is hosted on Dropbox.
27] Decryptor for my-Little-Ransomware is available on Github.
28] CERT-PL has released one for CryptoMix Decryptor
29] Popcorn Decryptor Tool is available here.
30] Avast has released decryption tools for the following ransomware:
AES_NI, Alcatraz Locker, Apocalypse, AtomSilo & LockFile, Babuk, BadBlock, Bart, BigBobRoss, BTCWare, Crypt888, CryptoMix, CrySiS, EncrypTile, FindZip, Fonix, GandCrab, Globe, HiddenTear, Jigsaw, LambdaLocker, Legion, NoobCrypt, Stampado, SZFLocker, TeslaCrypt, Troldesh, Shade, XData.
Get them all here.
31] ESET Crysis Decryptor is a free decryption tool for Crysis ransomware victims. Download it from Eset. It will also remove Dharma ransomware. They have also released a Decryptor for CryCryptor ransomware which is available on Github.
32] Kaspersky WindowsUnlocker can be useful if the Ransomware totally blocks access to your computer or even restrict access to select important functions, as it can clean up a ransomware-infected Registry.
33] RannohDecryptor from Kaspersky will help decrypt files encrypted by the Rannoh, AutoIt, Fury, Crybola, Cryakl, CryptXXX, CryptXXX v.2, CryptXXX v.3, MarsJoke, Polyglot, Dharma ransomware. Download it from here.
34] Kaspersky has also released several other decryptor tools like Rector Decryptor, Rakhni Decryptor, Wildfire Decryptor, Scraper Decryptor, Shade Decryptor, Scatter Decryptor, Xoris Decryptor, etc – go get them here. They will decrypt files encrypted by Rakhni, Agent.iih, Aura, Autoit, Pletor, Rotor, Lamer, Lortok, Cryptokluchen, Democry, Bitman, TeslaCrypt, and other ransomware.
35] Kaspersky Ransomware Decryptor will automatically decrypt all files for CoinVault and Bitcryptor victims. Get it here. It also helps in the case of Cryakl ransomware.
36] Visit the Kaspersky NoRansom web page to find out if they have released a decryption tool for your ransomware. Currently, the page shows the availability of WildfireDecryptor tool, ShadeDecryptor tool, RakhniDecryptor, RannohDecryptor tool and CoinVaultDecryptor tool. Also included are manual how-tos and other useful resources about ransomware. Intel McAfee has also made a Wildfire Decryptor.
RakhniDecryptor will help decrypt files encrypted by Dharma, Crysis, Chimera, Rakhni, Agent.iih, Aura, Autoit, Pletor, Rotor, Lamer, Lortok, Cryptokluchen, Democry, Bitman (TeslaCrypt) version 3 and 4 ransomware.
37] Malwarebytes has released a Telecrypt Ransomware Decrypter Tool to decrypt files infected with the Telecrypt Ransomware. Download it here.
38] Michael Gillespie, a ransomware researcher has released these ransomware decryptor tools:
Aurora Ransomware Decrypter, FilesLocker Ransomware Decrypter, InsaneCrypt Decryptor for desuCrypt Ransomware, GIBON Ransomware Decryptor, Striked Ransomware Decrypter, DCry Ransomware Decrypter, BitKangaroo Decrypter, BTCWare Ransomware Decrypter, Crypt38 Ransomware Decrypter, BitStak Ransomware Decrypter, Alpha Ransomware Decryptor, Unlock92 Ransomware Decrypter, Hidden Tear Ransomware Decrypter, Hidden Tear Brute Forcer Ransomware decryptor, PowerWare Locky Ransomware Decrypter, GhostCrypt Ransomware Decrypter, MicroCopy Ransomware Decryptor, Jigsaw Ransomware Decrypter, STOP Decrypter.
Plus he has also released the following useful tools:
- StupidDecryptor decrypts files encrypted by various screen-lockers that are fairly easy to decrypt
- RansomNoteCleaner can be used to scan a ransomware victim’s computer for leftover ransom notes and delete them
- CryptoSearch cleans up your computer of encrypted files and ransom notes from a ransomware infection.
39] Master Key for TeslaCrypt ransomware has been released. Tesladecrypt from Intel will decrypt TeslaCrypt encrypted files with the following extensions: .mp3, .micro, .xxx, and .ttt.
40] BTCWareDecrypter will decrypt files encrypted by BTCWare Ransomware. Get it here.
41] 360 Ransomware Decryption Tool can decrypt files locked by over 80 ransomware including GandCrab, Petya, Gryphon, GoldenEye and WannaCry ransomware.
42] Under favorable conditions, WannaKey and WanaKiwi, two WannaCrypt decryption tools can help decrypt WannaCrypt or WannaCry Ransomware encrypted files by retrieving the encryption key used by the ransomware.
43] Crysis Decrypting Tools have been developed by Eset as well as Avast.
44] The ransomware decryptor tool from QuickHeal will decrypt files locked by the following ransomware –
Troldesh Ransomware [.xtbl], Crysis Ransomware [.CrySiS], Cryptxxx Ransomware [.crypt], Ninja Ransomware [@aol.com$.777], Apocalypse Ransomware [.encrypted], Nemucod Ransomware [.crypted], ODC Ransomware [.odcodc], LeChiffre Ransomware [.LeChiffre], Globe1 Ransomware [.hnyear], Globe2 Ransomware [.blt], Globe3 Ransomware [.decrypt2017], DeriaLock Ransomware [.deria], Opentoyou Ransomware [[email protected]], Globe3 Ransomware [.globe & .happydayzz], Troldesh Ransomware [.dharma], Troldesh Ransomware [.wallet], Troldesh Ransomware [.onion], Satan DBGer Ransomware [.dbger]. STOP Djvu Ransomware, GandCrab Ransomware.
Download it here.
45] Ransomware Removal & Response Kit is not a tool, but a compilation of guides and various resources relating to dealing with ransomware, that can prove to be of help. It is a 500 MB download. Read more about it here.
46] Generally speaking, Anvi Rescue Disk can come to your rescue as it can help you uninstall & remove Ransomware.
How long does it take to decrypt ransomware?
This depends on the availability of the Ransomware Decryption Tool. It could range from a few days to a few weeks. If you decide to pay then the private key that they give you is almost always known to work and help decrypt the files right away.
All the best!
If you have any more free ransomware decryptor tools to add, please do so in the comments section, linking to their official home or download page.
This post talks a little more about Ransomware Attacks & other FAQ.