Victims of the CoinVault are able to decrypt their files with a free tool released by Kaspersky Lab and the Dutch police.

The tool can be found at the link: https://noransom.kaspersky.com. The application uses the decryption keys found by the Dutch police as part of the investigation.
Ransomware like CoinVault encrypts data on a disk or blocks access to a computer system. It is usually installed by exploiting a vulnerability on victims' computers through phishing emails or links to malicious websites.
Unlike other ransomware, CoinVault allows victims to view a list of encrypted files and decrypt one file for free in order to convince them to pay.
The Dutch police's National High Tech Crime Unit (NHTCU) recently obtained a database from a CoinVault command and control server containing decryption keys, Dutch police said in a news release. The information obtained from the database allowed Kaspersky to build a decryption tool.
The tool is not 100 percent effective, but as the investigation progresses, police hope to discover new keys and improve the tool's success rate, said Kaspersky Jornt van der Wiel, who helped create the decryption tool.
Dutch police have not made any arrests related to the ransomware but said they may soon make arrests, as the perpetrator behind the CoinVault ransomware is suspected to be in the Netherlands.
Ransomware victims are encouraged to report the attacks to police because reports from a company and an individual led to the discovery of the keys and a possible lead to a suspect, according to police.
