Press Ctrl-F to Search
CryptoStopper Stops Ransomware
Buy Now

Ransomware Decryptor Collection

The Definitive Collection of Ransomware Decryptors on the Web

WatchPoint has scoured the web and created the largest collection of ransomware decryptors available. This list is updated regularly so if the decryptor you need isn't available check back in the future and it may be available.

 Decryptor Download
Read Me 
Encrypted File Extension 
 Creator/Contributor
 777
 *.777
 Emsisoft
 777
 {Original file name}.777
 Trend Micro
 {sequential number}.R4A or {sequential number}.R5A
  .8block8
 Bleeping Computer
  
 Kaspersky
 *.Alcatraz
 Avast
Alfa
N/A
*.bin (Decryption currently not possible)
 
Adds 5 random characters at the end of each file and a unique 8 character victim ID
PhishLabs
*.unavailable, *.disappeared
Emisoft
Alpha
N/A
*.bin (Decryption currently not possible)
 
*.encrypt
Bleeping Computer
*.encrypted, *.FuckYourData, *.Encryptedfile, *.SecureCrypted
Emsisoft
*.encrypted, *.FuckYourData, *.Encryptedfile, *.SecureCrypted
AVG
*.encrypted, *.FuckYourData, *.Encryptedfile, *.SecureCrypted
Avast
*.encrypted, *.FuckYourData, *.Encryptedfile, *.SecureCrypted
Avast
*.encrypted, *.locked
Emsisoft
*.encrypted, *.FuckYourData, *.Encryptedfile, *.SecureCrypted
AVG
 
Kaspersky
{Original Filename}@<mail server>_.<random_set_of_characters>.
Kaspersky
*.locky
Emsisoft
{Original file name}.locky
Trend Micro
Renames files "<original_name>@<mail server>_.<random_set_of_characters>"
Kaspersky
Doesn't change file extension. Look for BadBlock in ransom note
AVG
Doesn't change file extension. Look for BadBlock in ransom note
Emsisoft
Doesn't change file extension. Look for BadBlock in ransom note
Trend Micro
32-bit
Doesn't change file extension. Look for BadBlock in ransom note
 
64-bit 
Doesn't change file extension. Look for BadBlock in ransom note
Avast
Bandarchor
N/A
[filename].id-[ID]_fud@india.com (Decryption currently not possible)
 
Instructions>
*.bart.zip
AVG
*.bart.zip
Avast
*.clf
Kaspersky
 
Kaspersky
 
Kaspersky
*.bitstak
Bleeping Computer
Black Shades
N/A
*.silent (Decryption currently not possible)
 
Booyah
N/A
(Decryption currently not possible)
 
{10 random characters}.cerber
Trend Micro
{10 random characters}.cerber
Kaspersky
 {Original file name}.crypt
Trend Micro
{Original file name}.crypt
Kaspersky
Trojan-Ransom.Win32.Crypmodadv.cj
Kaspersky
Infected with Trojan-Ransom.Win32.Cryakl also tags end of file name with {CRYPTENDBLACKDC}
Kaspersky
Infected with Trojan-Ransom.Win32.Crybola
Kaspersky
*.crypt, *.R16M01D0
Emsisoft
CryLocker
N/A
*.cry (Decryption currently not possible)
 
 
 
 
 
 
 
This ransomware adds Lock. to the beginning of file names
AVG
This ransomware adds Lock. to the beginning of file names
Avast
 
 
Michael Gillespie
Crysis
.{id}.{email address}.xtbl, crypt
Trend Micro
 
Kaspersky
 
 
ESET
 
Avast
 
*.CRYPTOSHIELD, *.rdmk, *.lesli, *.scl, *.code, *.rmd *.rscl
Avast
*.CRINF
Emsisoft
Crypt0l0cker
N/A
*.encrypted or *.enc (Decryption currently not possible)
 
Identifes as CryptoDefense leaves note HOW_DECRYPT.txt
Emsisoft
CryptoLocker
Discontinued
*.encrypted, *.cryptolocker (Decryption currently not possible)
FireEye & Fox-IT
*.CRYPTOSHIELD, *.rdmk, *.lesli, *.scl, *.code, *.rmd *.rscl
Avast
locks files and creates HowDecrypt.txt and HowDecrypt.gif
Bleeping Computer
 
 
Bleeping Computer
Cryptowall
N/A
(Decryption currently not possible)
 
{original file name}.crypt, cryp1, crypz, or 5 hexadecimal characters
Trend Micro
Infected with Trojan-Ransom.Win32.CryptXXX
Kaspersky
 {MD5 Hash}.5 hexadecimal characters
Trend Micro
CryPy
N/A
*.cry (Decryption currently not possible)
 
CTB-Locker
 
 
 
 
 
 
 
 
Emsisoft
 
Check Point
DMALocker with ID “DMALOCK 41:55:16:13:51:76:67:99
Emsisoft
DMALocker2 with ID “DMALOCK 43:41:90:35:25:13:61:92
Emsisoft
 *._date-time_$address@domain$.777 OR *._date-time_$address@domain$.legion
Kaspersky
 .demoadc
Trend Micro
 
Kaspersky
 {Original file name}.{Original extension}dxxd
Trend Micro
*.encrypted
Emsisoft
*.centrumfr@india.com!!
Emsisoft
*.crypt
Avast
Infected with  Trojan-Ransom.Win32.Fury
Kaspersky
 
 
Bleeping Computer
{Original file name}.purge
Trend Micro
*.ACRYPT, *.GSupport[0-9], *.blackblock, *.dll555, *.duhust, *.exploit, *.frozen, *.globe, *.gsupport,

 

*.kyra, *.purged, *.raid[0-9], *.siri-down@india.com, *.xtbl, *.zendrz, *.zendr[0-9], *.hnyear

Avast
*.purge, *.globe, *.okean-1955@india.com.!dsvgdfvdDVGR3SsdvfEF75sddf#xbkNY45fg6}P{cg.xtbl.
Emsisoft
*.raid10, *.blt, *.globe, *.encrypted,*[mia.kokers@aol.com]
Emsisoft
{Original file name}.{email address + random characters}
Trend Micro
*.decrypt2017, *.hnumkhotep
Emsisoft
 Extension not fixed or file name encrypted
Trend Micro
*.crypt
Emsisoft
*.crypt
Emsisoft
*.html and note from Spamhaus or US Department of Justice
 
Emsisoft
*.locked, *.34xxx, *.bloccato, *.BUGSECCCC, *.Hollycrypt, *.lock, *.saeid, *.unlockit,
*.razy, *.mecpt, *.monstro, *.lok, *.????, *.8lock8, *.fucked, *.flyper, *.kratos, *.krypted, *.CAZZO, *.doomed.
 *.hyrdacrypt, *.umbrecrypt
 
FUN, .KKK,  .GWS, .BTC
Trend Micro
 
 .FUN, .KKK,  .GWS, .BTC
Check Point
 .FUN, .KKK,  .GWS, .BTC
Avast
 .FUN, .KKK,  .GWS, .BTC
Bleeping Computer
 
 
Dr. Web
Leaves ransom note called Decrypt_Your_Files.txt
Emsisoft
 
 
 
 
Kaspersky
*.LeChiffre
Emsisoft
 {Original file name}.LeChiffre
Trend Micro
Legion adds a variant of *._23-06-2016-20-27-23_$f_tactics@aol.com$.legion or *.$centurion_legion@aol.com$.cbf to end of filename
AVG
._23-06-2016-20-27-23_$f_tactics@aol.com$.legion or .$centurion_legion@aol.com$.cbfto the end of filename
Avast
 
 
BitDefender
 
 
BitDefender
 
 
Bleeping Computer
 
 
Trend Micro
 
Kaspersky
 
 
 
*.oops
Emsisoft
 
Kaspersky
Lock.{Original file name}
AVG
 Lock.{Original file name}
Trend Micro
*.PEGS1, *.MRCR1, *.RARE1, *.MERRY, *.RMCM1
Emsisoft
 
 
 
*.crypted
Emsisoft
 {Original file name}.crypted
Trend Micro
*.maktub, *._AiraCropEncrypted!
Emsisoft
NoobCrypt
 
 Decypt keys are ZdZ8EcvP95ki6NWR2j or lsakhBVLIKAHg
Jakub Kroustek
 
 
Bleeping Computer
*.-opentoyou@india.com
Emsisoft
 
 
Nathan Scott aka DecrypterFixer
*.locked
Emsisoft
Doesn't change extension look for enc_files.txt
Emsisoft
 
 
Leo Stone
*.locked
Emsisoft
 
Check Point
 
 
Bleeping Computer
 
Kaspersky
Infected with Trojan-Ransom.Win32.Polyglot
Kaspersky
 
EDA2
 
Elevenpaths
 
 
Palo Alto Networks
{Original file name}.purge
Trend Micro
{Original file name}.{email address + random characters}
Trend Micro
{Original file name}.{email address + random characters}
Trend Micro
*.rdm, *.rrk
Emsisoft
*.locked, *.kraken
Kaspersky
Renames files "locked-<original_name>.<four_random_letters>"
Kaspersky
 
Infected with Trojan-Ransom.Win32.Rector
Kaspersky
 
Kaspersky
 
Infected with Trojan-Ransom.BAT.Scatter
Kaspersky
 
Infected with Trojan-Ransom.Win32.Scraper
Kaspersky
 
*.xtbl, *.ytbl, *.breaking_bad, *.heisenberg.
Intel
 
*.xtbl, *.ytbl, *.breaking_bad, *.heisenberg.
Kaspersky
 {Original file name}.RSNSLocked
Trend Micro
*.locked
Emsisoft
 {Original file name}.locked
Trend Micro
 {Original filename}.__xratteamLucked
Trend Micro
{Original file name}
Trend Micro
 
 
Googulator
Decryptor for variant that doesn't rename files
AVG
 
 *.xxx, *.ttt, *.micro, *.mp3 
ESET
TeslaCrypt v1
 {original file name}.ECC
Trend Micro
TeslaCrypt v2
{original file name}.VVV, CCC, ZZZ, AAA, ABC, XYZ
Trend Micro
{original file name}.XXX or TTT or MP3 or MICRO
Trend Micro
File name and extension are unchanged
Trend Micro
 
*.xxx, *.ttt, *.micro, *.mp3 
Intel
 
 
Malwarebytes
 
 
Talos
 
 
Trend Micro
 
 *.encrypted, *.enc
DecryptFixer
 
 
Kaspersky
 
 
Intel
 *.hydracrypt, *.umbrecrypt
Emsisoft
 
 
MalwareBytes
 
*.wflx
Kaspersky
 {Original file name}.crypted
Trend Micro
*.EnCiPhErEd, *.0JELvV, *.p5tkjw, *.6FKR8d, *.UslJ6m, *.n1wLp0, *.5vypSa, *.YNhlv1
Emsisoft
 
 
Kaspersky
{Original file name}.xorist or random extension
Trend Micro
{Original filename}.__xratteamLucked
Trend Micro
*.CRYPTOSHIELD, *.rdmk, *.lesli, *.scl, *.code, *.rmd *.rscl
Avast