Lost all your files to some nasty ransomware?

We're here to fix that.

Download one of our free decrypter tools to recover your files without paying the ransom

I need removal help
icon
[Nov, 29, 2016] - Version: 1.0.0.8

Emsisoft Decrypter for NMoreira

NMoreira, also known as XRatTeam or XPan, is a file encrypting ransomware. It uses a mix of RSA and AES-256 to encrypt your files. Encrypted files have either the extension *.maktub or *.__AiraCropEncrypted!. In addition, the ransomware will create one of the following ransom notes.

Portugese version used by the *.maktub variant using the file name "Recupere seus arquivos. Leia-me!.txt":

Olá, seus arquivos foram criptografados.

A única forma de tê-los de volta, é atraves de um software juntamente com sua chave privada.

Caso haja interesse em recuperar seus arquivos, entre em contato pelo seguinte email: contatomaktub@email.tg

No campo do email, me envie sua chave pública que está logo abaixo.

Te responderei o mais rápido possível e lhe darei a garantia de recuperação dos arquivos.

Att


Chave pública: CC638AF6DE4D9B9998E74D00252862E512277575BA644D28D9320952F2C2193A

English version used by the *.__AiraCropEncrypted! variant using the file name "How to decrypt your files.txt":

Encrypted Files!

All your files are encrypted. Using encryption AES256-bit and RSA-2048-bit.
Making it impossible to recover the files without the correct private key.
If you are interested in getting is key, and retrieve your files



For information on how to reverse the file encryption
send email to:
airacrop@vpn.tg
enter your KEY in the subject or email body.

=======================================================
Remember your email is not answered within 24 hours,
visit one of the link below to get a new mail contact
https://6kaqkavhpu5dln6x.onion.to/
https://6kaqkavhpu5dln6x.onion.link/
https://qsx72kun2efdcli2.onion.to/
https://qsx72kun2efdcli2.onion.link/


Alternative link:

http://6kaqkavhpu5dln6x.onion
http://qsx72kun2efdcli2.onion

To access the alternate link is mandatory to use the TOR browser available on the link
https://www.torproject.org/download/download



Key:
=======================================================
EF0771674764DDAAB32A83F51239B6286FBC61265393AAA051CCC1881942616F
=======================================================

Keep in mind that due to the complexity of the used encryption scheme, decrypting files can be very time-consuming. In addition, due to the fact that the ransomware doesn't leave anything behind, that would allow verification that the file was decrypted properly, the decrypter tries to guess whether or not the file has been decrypted properly. This guessing process can be prone to error and may not work correctly. It also means, that if the decrypter does not know the file format, it will also be unable to decrypt it reliably. At the moment the decrypter supports over 3000 different binary file formats, but especially text-based formats, that lack a unique identifier in the first 16 bytes of the file, will not be recognised.

Download
31567 downloads
icon
[Nov, 23, 2016] - Version: 1.0.0.25

Emsisoft Decrypter for OzozaLocker

Use this decrypter if your files have been renamed to *.locked and you find a ransom note named "HOW TO DECRYPT YOU FILES.txt" on your desktop. Double clicking an encrypted file will also display a message box instructing you to contact "santa_helper@protonmail.com". To use the decrypter you will require an encrypted file of at least 510 bytes in size as well as its unencrypted version. To start the decrypter select both the encrypted and unencrypted file and drag and drop them onto the decrypter executable.
Download
1669 downloads
icon
[Oct, 8, 2016] - Version: 1.0.0.13

Emsisoft Decrypter for Globe2

Globe2 is a ransomware kit that was first discovered at the beginning of October. Globe2 encrypts files and optionally file names using RC4. Since the extension of encrypted files is configurable, several different file extensions are possible. The most commonly used extensions are .raid10, .blt, .globe, .encrypted and .[mia.kokers@aol.com]. To use the decrypter you will require a file pair containing both an encrypted file and its non-encrypted original version. Select both the encrypted and unencrypted file and drag and drop both of them onto the decrypter file in your download directory. If file names are encrypted, please use the file size to determine the correct file. Encrypted and original file will have exactly the same size.
Download
15979 downloads
icon
[Oct, 1, 2016] - Version: 1.0.0.10

Emsisoft Decrypter for Globe

Globe is a ransomware kit that was first discovered at the end of August. Files are encrypted using Blowfish. Since the extension of encrypted files is configurable, several different file extensions are possible. The most commonly used extensions are .purge, .globe and .okean-1955@india.com.!dsvgdfvdDVGR3SsdvfEF75sddf#xbkNY45fg6}P{cg.xtbl. To use the decrypter you will require a file pair containing both an encrypted file and its non-encrypted original version. It is important to use a file pair that is as large as possible, as it determines the maximum file size up to which the decrypter will be able to decrypt your files. Select both the encrypted and unencrypted file and drag and drop both of them onto the decrypter file in your download directory.
Download
10953 downloads
icon
[Sep, 28, 2016] - Version: 1.0.0.51

Emsisoft Decrypter for Al-Namrood

The Al-Namrood ransomware is a fork of the Apocalypse ransomware. The group behind it primarily attacks servers that have remote desktop services enabled. Encrypted files are renamed to *.unavailable or *.disappeared and for each file a ransom note is created with the name *.Read_Me.Txt. The ransomware asks the victim to contact "decryptioncompany@inbox.ru" or "fabianwosar@inbox.ru". To decrypt your files the decrypter requires your ID. The ID can be set within the "Options" tab. By default the decrypter will set the ID to the ID that corresponds to the system the decrypter runs on. However, if that is not the same system the malware infection and encryption took place on, make sure to put in the ID as specified in the ransom note.
Download
5705 downloads
icon
[Sep, 18, 2016] - Version: 1.0.0.8

Emsisoft Decrypter for FenixLocker

Use this decrypter if your files have been encrypted by the FenixLocker ransomware. FenixLocker encrypts files and renames them by appending the ".centrumfr@india.com!!" extension. It leaves behind a ransom note named "CryptoLocker.txt" or "Help to decrypt.txt" on your Desktop, instructing you to contact "centrumfr@india.com". To start the decrypter simply drag and drop one of your encrypted files onto the decrypter executable.
Download
44033 downloads
icon
[Sep, 16, 2016] - Version: 1.0.0.31

Emsisoft Decrypter for Fabiansomware

Use this decrypter if your files have been encrypted and renamed to *.encrypted with ransom notes named *.How_To_Decrypt_Your_Files.txt. The ransom note asks you to contact "decryptioncompany@inbox.ru", "fwosar@mail.ru" or "fabianwosar@mail.ru". To use the decrypter you will require a file pair containing both an encrypted file and its non-encrypted original version. It is important to use a file pair that is as large as possible, as it determines the maximum file size up to which the decrypter will be able to decrypt your files. Select both the encrypted and unencrypted file and drag and drop both of them onto the decrypter file in your download directory.
Download
6012 downloads
icon
[Sep, 10, 2016] - Version: 1.0.0.8

Emsisoft Decrypter for Philadelphia

Philadelphia is a ransomware kit offered within various hacking communities. Written in AutoIt, it encrypts files using AES-256 encryption, file names using RC4 encryption and uses the *.locked file extension. It is based on a similar ransomware kit called "Stampado" that is written by the same author. To use the decrypter you will require a file pair containing both an encrypted file and its non-encrypted original version. Due to the file name encryption this can be a bit tricky. The best way is to simply compare file sizes. Encrypted files will have the size of the original file rounded up to the next 16 byte boundary. So if a the original file was 1020 bytes large, the encrypted file will be 1024. Select both the encrypted and non-encrypted file and drag and drop both of them onto the decrypter file in your download directory.
Download
5987 downloads
icon
[Jul, 22, 2016] - Version: 1.0.0.196

Emsisoft Decrypter for Stampado

Stampado is a ransomware kit offered within various hacking communities. Written in AutoIt, it encrypts files using AES-256 encryption and renames them to *.locked. Known variants of this ransomware ask victims to contact paytodecrypt@sigaint.org, getfiles@tutanota.com, successl@qip.ru, clesline212@openmailbox.org or ransom64@sigaint.org to facilitate payment. In order for the decrypter to work you will require both the email you are asked to contact as well as your ID. Please keep in mind that both are case sensitive, so proper capitalization does matter. Please put both information into the appropriate fields in the options tab. Since version 1.17.0 each Stampado infection also has a unique "salt" that is specific to the ransomware buyer. The salt can either be specified manually or detected automatically. In order to determine the salt automatically the ransomware has to be running on the system. Fill in the ID and email address and click the "Detect ..." button next to the salt input field. If the malware has already been removed, please don't attempt to reinfect yourself. Instead submit the malware file via email to fw@emsisoft.com so I can extract the correct salt for you. You can also try the pre-configured salts that have been used by known Stampado campaigns in the wild so far.
Download
12069 downloads
icon
[Jun, 18, 2016] - Version: 1.0.0.34

Emsisoft Decrypter for ApocalypseVM

Use this decrypter if your files have been encrypted and renamed to *.encrypted or *.locked with ransom notes named *.How_To_Decrypt.txt, *.README.txt, *.How_to_Decrypt_Your_Files.txt or *.How_To_Get_Back.txt created for each encrypted file. The ransom note asks you to contact "fabiansomware@mail.ru", "decryptionservice@inbox.ru" or "decryptdata@inbox.ru" and contains a personal ID. To use the decrypter you will require an encrypted file of at least 4096 bytes in size as well as its unencrypted version. To start the decrypter select both the encrypted and unencrypted file and drag and drop them onto the decrypter executable.
Download
13465 downloads
icon
[Jun, 12, 2016] - Version: 1.0.0.24

Emsisoft Decrypter for Apocalypse

Use this decrypter if your files have been encrypted and renamed to *.encrypted, *.FuckYourData, *.Encryptedfile or *.SecureCrypted with ransom notes named *.How_To_Decrypt.txt, *.Where_my_files.txt, *.How_to_Recover_Data.txt or *.Contact_Here_To_Recover_Your_Files.txt created for each encrypted file. The ransom note asks you to contact "decryptionservice@mail.ru", "ransomware.attack@list.ru", "getdataback@bk.ru" or "recoveryhelp@bk.ru".
Download
13758 downloads
icon
[May, 28, 2016] - Version: 1.0.0.174

Emsisoft Decrypter for BadBlock

Use this decrypter if your files have been encrypted but not renamed. The malware identifies itself as BadBlock both in the red ransomware screen as well as in the ransomnote "Help Decrypt.html" that can be found on the Desktop.
Download
9708 downloads
icon
[May, 17, 2016] - Version: 1.0.0.24

Emsisoft Decrypter for Xorist

Use this decrypter if your files have been encrypted by the Xorist ransomware. Typical extensions used by Xorist include *.EnCiPhErEd, *.0JELvV, *.p5tkjw, *.6FKR8d, *.UslJ6m, *.n1wLp0, *.5vypSa and *.YNhlv1. The ransomnote can usually be found on the Desktop with the name "HOW TO DECRYPT FILES.txt". To use the decrypter you will require an encrypted file of at least 144 bytes in size as well as its unencrypted version. To start the decrypter select both the encrypted and unencrypted file and drag and drop them onto the decrypter executable.
Download
13870 downloads
icon
[May, 17, 2016] - Version: 1.0.0.29

Emsisoft Decrypter for 777

Use this decrypter if your files have been encrypted and renamed to *.777. It may be necessary to select the correct version of the malware in the options tab for the decrypter to work properly.
Download
9698 downloads
icon
[Apr, 16, 2016] - Version: 1.0.0.11

Emsisoft Decrypter for AutoLocky

Use this decrypter if your files have been encrypted and renamed to *.locky, but the file base name is still unchanged, and you find a ransom note named info.txt or info.html on your Desktop.
Download
100782 downloads
icon
[Mar, 22, 2016] - Version: 1.0.0.24

Emsisoft Decrypter for Nemucod

Use this decrypter if your files have been renamed to *.crypted and you find a ransomnote named DECRYPT.txt on your desktop. To use the decrypter you will require an encrypted file of at least 4096 bytes in size as well as its unencrypted version. To start the decrypter select both the encrypted and unencrypted file and drag and drop them onto the decrypter executable.
Download
35560 downloads
icon
[Feb, 18, 2016] - Version: 1.0.0.187

Emsisoft Decrypter for DMALocker2

Use this decrypter if your files have been encrypted but not renamed. The malware identifies itself as DMA Locker and the ID is "DMALOCK 43:41:90:35:25:13:61:92".
Download
7463 downloads