Choose ransomware type
Our free ransomware decryption tools can help decrypt files encrypted by the following forms of ransomware. Just click a name to lớn see the signs of infection & get our free fix.
Bạn đang xem: Tải avast premier full key bản quyền đến 2023 đã test 100%
AES_NI
AES_NI is a ransomware strain that first appeared in December 2016. Since then, we’ve observed multiple variants, with different file extensions. For encrypting files, the ransomware uses AES-256 combined with RSA-2048.
Filename changes:
The ransomware adds one of the following extensions lớn encrypted files:.aes_ni.aes256.aes_ni_0day
In each thư mục with at least one encrypted file, the tệp tin "!!! READ THIS - IMPORTANT !!!.txt" can be found. Additionally, the ransomware creates a key file with name similar to:
The file “!!! READ THIS - IMPORTANT !!!.txt” contains the following ransom note:

Alcatraz Locker
Alcatraz Locker is a ransomware strain that was first observed in the middle of November 2016. For encrypting user"s files, this ransomware uses AES 256 encryption combined with Base64 encoding.
Filename changes:
Encrypted files have the ".Alcatraz" extension.
Ransom message:After encrypting your files, a similar message appears (it is located in a file "ransomed.html" in the user"s desktop):

Apocalypse
Apocalypse is a size of ransomware first spotted in June 2016. Here are the signs of infection:
Filename changes:
Apocalypse adds .encrypted, .FuckYourData, .locked, .Encryptedfile, or .SecureCrypted khổng lồ the end of filenames. (e.g., Thesis.doc = Thesis.doc.locked)
Ransom message:Opening a tệp tin with the extension .How_To_Decrypt.txt, .README.Txt, .Contact_Here_To_Recover_Your_Files.txt, .How_to_Recover_Data.txt, or .Where_my_files.txt (e.g., Thesis.doc.How_To_Decrypt.txt) will display a variant of this message:

AtomSilo và LockFile
AtomSilo&LockFile are two ransomware strains analyzed by Jiří Vinopal. These two have very similar encryption schema, so this decryptor covers both variants. Victims can decrypt their files for free.
Filename changes:
Encrypted files can be recognized by one of these extensions: .ATOMSILO .lockfileIn each folder with at least one encrypted file, there"s also ransom cảnh báo file, named README-FILE-%ComputerName%-%Number%.hta or LOCKFILE-README-%ComputerName%-%Number%.hta, e.g.: README-FILE-JOHN_PC-1634717562.hta LOCKFILE-README-JOHN_PC-1635095048.hta


Babuk
Babuk is a Russian ransomware. In September 2021, the source code leaked with some of the decryption keys. Victims can decrypt their files for free.
Xem thêm: Giải Bài Toán Bằng Cách Giải Phương Trình Lớp 8 Cực Hay, Có Đáp Án
Filename changes:
When encrypting file, Babuk appends one of the following extensions to lớn the tệp tin name: .babuk .babyk .doydoIn each folder with at least one encrypted file, the file Help Restore Your Files.txt can be found with the following content:

BadBlock
BadBlock is a size of ransomware first spotted in May 2016. Here are the signs of infection:
Filename changes:
BadBlock does not rename your files.
Ransom message:After encrypting your files, BadBlock displays one of these messages (from a file named Help Decrypt.html):