Use Kaspersky's RakhniDecryptor utility to decrypt your files in case they are encrypted by the following types of malware:

  • Trojan-Ransom.Win32.Rakhni
  • Trojan-Ransom.Win32.Agent.iih
  • Trojan-Ransom.Win32.Autoit
  • Trojan-Ransom.Win32.Aura
  • Trojan-Ransom.AndroidOS.Pletor
  • Trojan-Ransom.Win32.Rotor
  • Trojan-Ransom.Win32.Lamer
  • Trojan-Ransom.Win32.Cryptokluchen
  • Trojan-Ransom.Win32.Democry
  • Trojan-Ransom.Win32.Bitman version 3 and 4
  • Trojan-Ransom.Win32.Libra
  • Trojan-Ransom.MSIL.Lobzik
  • Trojan-Ransom.MSIL.Lortok
  • Trojan-Ransom.Win32.Chimera
  • Trojan-Ransom.Win32.CryFile
  • Trojan-Ransom.Win32.Nemchig
  • Trojan-Ransom.Win32.Mircop
  • Trojan-Ransom.Win32.Mor
  • Trojan-Ransom.Win32.Crusis
  • Trojan-Ransom.Win32.AecHu
  • Trojan-Ransom.Win32.Jaff

How to use the tool:

To decrypt the files, do the following:

  1. Download the RakhniDecryptor.zip archive, using a file archiver (for example, 7zip).
  2. Run the RakhniDecryptor.exe file on the infected computer.
  3. In the Kaspersky RakhniDecryptor window click the Change parameters link.
  4. In the Settings window select the objects to scan (hard drives / removable drives / network drives).
  5. Select the checkbox Delete crypted files after decryption (the utility will be deleting copies of original files with the .locked, .kraken and .darkness extensions).
  6. Click ОК.
  7. In the Kaspersky RakhniDecryptor, click Start scan.
  8. In the Specify the path to one of encrypted files, select the file you need to restore and click Open.
  9. The utility will start recovering the password. Please mind the Warning! window message.
  10. Wait until the utility is done with decrypting the file (do not exit the program or shut down the computer).