Use Kaspersky's RakhniDecryptor utility to decrypt your files in case they are encrypted by the following types of malware:
- Trojan-Ransom.Win32.Rakhni
- Trojan-Ransom.Win32.Agent.iih
- Trojan-Ransom.Win32.Autoit
- Trojan-Ransom.Win32.Aura
- Trojan-Ransom.AndroidOS.Pletor
- Trojan-Ransom.Win32.Rotor
- Trojan-Ransom.Win32.Lamer
- Trojan-Ransom.Win32.Cryptokluchen
- Trojan-Ransom.Win32.Democry
- Trojan-Ransom.Win32.Bitman version 3 and 4
- Trojan-Ransom.Win32.Libra
- Trojan-Ransom.MSIL.Lobzik
- Trojan-Ransom.MSIL.Lortok
- Trojan-Ransom.Win32.Chimera
- Trojan-Ransom.Win32.CryFile
- Trojan-Ransom.Win32.Nemchig
- Trojan-Ransom.Win32.Mircop
- Trojan-Ransom.Win32.Mor
- Trojan-Ransom.Win32.Crusis
- Trojan-Ransom.Win32.AecHu
- Trojan-Ransom.Win32.Jaff
How to use the tool:
To decrypt the files, do the following:
- Download the RakhniDecryptor.zip archive, using a file archiver (for example, 7zip).
- Run the RakhniDecryptor.exe file on the infected computer.
- In the Kaspersky RakhniDecryptor window click the Change parameters link.
- In the Settings window select the objects to scan (hard drives / removable drives / network drives).
- Select the checkbox Delete crypted files after decryption (the utility will be deleting copies of original files with the .locked, .kraken and .darkness extensions).
- Click ОК.
- In the Kaspersky RakhniDecryptor, click Start scan.
- In the Specify the path to one of encrypted files, select the file you need to restore and click Open.
- The utility will start recovering the password. Please mind the Warning! window message.
- Wait until the utility is done with decrypting the file (do not exit the program or shut down the computer).