{"id":5860,"date":"2017-01-18T22:48:48","date_gmt":"2017-01-18T22:48:48","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/01\/18\/news-65\/"},"modified":"2017-01-18T22:48:48","modified_gmt":"2017-01-18T22:48:48","slug":"news-65","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/01\/18\/news-65\/","title":{"rendered":"Decryption Tool for CrySiS\/XTBL Ransomware"},"content":{"rendered":"<p>The decryption of CrySiS\/XTBL Ransomware is now possible thanks to the recent release of its master decryption keys needed to recover the files encrypted by the ransomware. While we couldn\u2019t guess the apparent reason behind the release, we decided to use this opportunity to help those who were affected by the ransomware.<\/p>\n<p>The Quick Heal Threat Research Labs has developed a CrySiS\/XTBL decryption tool (known as QH-Ransom-Decryptor) with the published keys. This tool comes for free and can be downloaded from the link mentioned below:<\/p>\n<p><strong>Download link:<br \/> <\/strong><a href=\"http:\/\/bit.ly\/2iCPtvW\" target=\"_blank\">QH Ransom Decryptor Tool<\/a><\/p>\n<p>As of now, the decryption tool works on files affected by the below-listed ransomware families.<\/p>\n<p>1. Troldesh Ransomware [.xtbl]<br \/> 2. Crysis Ransomware [.CrySiS]<br \/> 3. Cryptxxx Ransomware [.crypt]<br \/> 4. Ninja Ransomware [@aol.com$.777]<br \/> 5. Apocalypse Ransomware [.encrypted]<br \/> 6. Nemucod Ransomware [.crypted]<br \/> 7. ODC Ransomware [.odcodc]<br \/> 8. LeChiffre Ransomware [.LeChiffre]<\/p>\n<p>Note:<br \/> A Crysis\/XTBL encryption can be identified from the below pattern of encrypted file extension:<\/p>\n<ul>\n<li>File name.&lt;extension&gt;.&lt;id-number&gt;.&lt;email&gt;.xtbl\/.CrySiS)<\/li>\n<\/ul>\n<p>Example &#8211; \u201cavailable.txt.id-340D4C04.{green_ray@india.com}.xtbl&#8221;<\/p>\n<p><strong><u>Instructions to use the QH-Ransom-Decryptor<\/u><\/strong><strong><u>:<\/u><\/strong><\/p>\n<ol>\n<li>Download the <strong>QH-Ransom_Decryptor_v1.0.zip<\/strong> from the link shared earlier and extract it in the system having the encrypted files.<\/li>\n<\/ol>\n<ol start=\"2\">\n<li>Right click on the \u201cQH-Ransom_Decryptor_v1.0.exe\u201d file and Run it as &#8216;Administrator&#8217; to view the Decryption Window.<\/li>\n<\/ol>\n<ol start=\"3\">\n<li>Press <strong>Y<\/strong> to start the scan. The tool will automatically scan the entire system for supported encrypted files. When an encrypted file is found, the tool will decrypt the file in its respective folder while keeping a copy of the encrypted file at the same time.<\/li>\n<\/ol>\n<div id=\"attachment_83747\" style=\"width: 635px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-83747\" src=\"http:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2016\/12\/Decryption-Tool-for-CrySiS-Ransomware.jpg\" alt=\"decryption-tool-for-crysis-ransomware\" width=\"625\" height=\"125\" srcset=\"http:\/\/blogs.quickheal.com\/wp-content\/uploads\/2016\/12\/Decryption-Tool-for-CrySiS-Ransomware.jpg 590w, http:\/\/blogs.quickheal.com\/wp-content\/uploads\/2016\/12\/Decryption-Tool-for-CrySiS-Ransomware-300x60.jpg 300w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/p>\n<p class=\"wp-caption-text\">Fig1. Decrypted files will be present in the same folder along with their encrypted copies.<\/p>\n<\/div>\n<ol start=\"4\">\n<li>After the scanning is complete, the decryption tool will show the final status displaying the number of encrypted files found and how many were successfully decrypted. The detailed information about the decryption status of each file can be obtained from the \u2018Decryption.log\u2019 generated in the same folder of the tool.<\/li>\n<\/ol>\n<ol start=\"5\">\n<li>Thereafter, you can open the decrypted files and verify if they are accessible\/readable again.<\/li>\n<\/ol>\n<p>If you come across any difficulty in using the decryption tool, kindly give us a call on <strong>1800-121-7377<\/strong> or visit our <a href=\"http:\/\/www.quickheal.co.in\/support-center-faqs\/\" target=\"_blank\">Support Center<\/a> for further assistance.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"http:\/\/blogs.quickheal.com\/decryption-tool-crysisxtbl-ransomware\/\">Decryption Tool for CrySiS\/XTBL Ransomware<\/a> appeared first on <a rel=\"nofollow\" href=\"http:\/\/blogs.quickheal.com\">Quick Heal Technologies Security Blog | Latest computer security news, tips, and advice<\/a>.<\/p>\n<p><a href=\"http:\/\/blogs.quickheal.com\/decryption-tool-crysisxtbl-ransomware\/\" target=\"bwo\" >http:\/\/blogs.quickheal.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The decryption of CrySiS\/XTBL Ransomware is now possible thanks to the recent release of its master decryption keys needed to recover the files encrypted by the ransomware. While we couldn\u2019t guess the apparent reason behind the release, we decided to use this opportunity to help those who were affected by&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"http:\/\/blogs.quickheal.com\/decryption-tool-crysisxtbl-ransomware\/\">Decryption Tool for CrySiS\/XTBL Ransomware<\/a> appeared first on <a rel=\"nofollow\" href=\"http:\/\/blogs.quickheal.com\">Quick Heal Technologies Security Blog | Latest computer security news, tips, and advice<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10459,10378],"tags":[10486,3765,10487],"class_list":["post-5860","post","type-post","status-publish","format-standard","hentry","category-quickheal","category-security","tag-decryption-tool","tag-ransomware","tag-ransomware-decryption"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/5860","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=5860"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/5860\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=5860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=5860"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=5860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}