HomeinetDecrypt infected files by DecryptorMax without paying ransom

Decrypt infected files by DecryptorMax without paying ransom

Fabian Wosar of Emisoft has managed to develop a tool that is capable of decrypting files encrypted by the DecryptorMax ransomware, also known as CryptInfinite.decrypt cryptinfinite DecryptorMax

The infection occurs when victims open a Word document and enable macros in order to view the file properly. Word macros are a known security issue used by many malware developers to distribute malware to Windows computers.

So if the ransomware is installed on the victim's computer, it immediately begins encrypting the files it encounters, adding the .crinf extension to all corrupted files.

Immediately after, Ransom informs the user that they have 24 hours to send the ransom via PayPal or MyCash to one of three email addresses: silasw9pa[at]yahoo.co.uk, decryptor171[at]mail2tor.com and decryptor171[at]scramble.io.

Additionally, the ransomware changes the desktop wallpaper with a ransom note, then deletes all Volume Shadow copies, and disables Windows Startup Repair so that the victim cannot restore previous backups.

This is where Wosar's tool, called DecryptInfinite, comes in. It's quite easy to use. It will allow you (if you've been infected by DecryptorMax) to unlock your files without paying the ransom.

The tool will calculate the decryption key required to decrypt the files. This is of course a time-consuming process, and you will need to be patient when using DecryptInfinite.

More details on how to use DecryptInfinite and how the tool works can be found in a Bleeping Computer.

Download the tool

https://emsi.at/DecryptCryptInfinite

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS