.crypted files restoral

posted in Viruses
Tuesday, March 22 2016, 12:13 PM
0
My server has been hit by a virus that added .crypted extension to all .tif and .pdf files rendering them unusable. How can I restore access to these files? Thank you.

Accepted Answer

Wednesday, March 23 2016, 08:26 AM - #permalink
0
PS. You can also try using a decrypter created by Fabian Wosar from Emsisoft - https://decrypter.emsisoft.com/nemucod Let me know if it works for you.
The reply is currently minimized Show
Responses (1)
  • Accepted Answer

    Wednesday, March 23 2016, 07:51 AM - #permalink
    0
    Hi Jan, according to Fortinet:

    The encrypted files can be decrypted as long as you have the XOR key that is embedded in the executable component.
    You can restore your PC using system restore.
    You can restore your files via Volume Shadow Copies.

    Here's their research on .crypted ransomware - https://blog.fortinet.com/post/nemucod-adds-ransomware-routine
    The reply is currently minimized Show
Your Reply