Security researchers from Check Point announced over the weekend that they managed to decrypt Jigsaw ransomware, both in its new and older versions.
Jigsaw ransomware appeared last April, and it differed from the others because if the victim did not pay the ransom, it began deleting files from the user's computer. 
Researchers managed to develop a decryptor for Jigsaw ransomware almost immediately after its release, but it stopped working after updates to the ransomware software. It should be noted that Jigsaw is one of the most updated ransomware versions at the moment, with new versions being released almost weekly.
The Check Point team also claims to have identified a weakness not in the encryption process, but in how the malware handles ransom payments.
While other ransomware uses a Tor website to handle payments, Jigsaw only displays a Bitcoin address on the victim's computer with a ransom note and asks users to click "I made a payment, give me my files back!" after they make the payment.
Pressing this button initiates a request from the user's computer to an online API that checks whether the payment was accepted by the specific Bitcoin address.
Check Point created a tool that mimics a positive API response. The tool gives Jigsaw a fake API response and the ransomware thinks that the payment was made, immediately starting the decryption process that ends with unlocking all encrypted files and deleting the malware from the infected system.
You can download it from the link below.
Instructions for use:
1. Open JPS.zip.
2. In the Jigsaw Puzzle Solver folder, right-click on 'JPS.exe' and 'run as administrator'.
3. Follow the instructions.
https://blog.checkpoint.com/wp-content/uploads/2016/07/JPS_release.zip
