Emsisoft Decrypter for CryptON

Enables you to rebuild the encryption parameters for files that have been hijacked by the CryptON ransomware using brute force attacks.

  • Emsisoft Decrypter for CryptON
  • Version :1.0.0.41
  • License :Freeware
  • OS :Windows All
  • Publisher :Emsisoft GmbH

Download Now

Emsisoft Decrypter for CryptON Description

The Russian-originated CryptON ransomware reaches a system using attacks via RDP. It then erases system restore points to eliminate the possibility of recovering a file using its shadow copy and encrypts your files using three different algorithms, namely RSA, SHA-256 and AES-256. In order to avoid having to pay the requested ransom to retrieve data in your encrypted files, you can try using the Emsisoft Decrypter for CryptON instead.

Remove the infection, then start unlocking your files

If the CryptON infected your system, there should be files that have strange extensions appended to their name (such as “.id-<id>_locked”). If you face this symptom, then what you should do first is initiate a scan using your antivirus to remove the malware and make sure no additional user account was added, in case you got infected in a remote session.

To use the decrypter, you need an encrypted file of at least 128 KB and the original, unencrypted file, which is usually 16 bytes smaller than the first. The application performs comparisons to re-build the encryption keys and recover the rest of your data. Once you have these two file, just drag and drop them on top of the application’s icon.

Uses brute force to find the encryption key and unlock your files

Emsisoft Decrypter for CryptON performs brute force attacks to find the encryption key. Once the key is retrieved, the sequence is displayed in a separate window. It is not 100% sure that the key is correct, so you are advised to try unlocking a few files before processing entire folders.

Once you have the key, the application can proceed to unlocking files in different locations on your computer. Since no information is saved by the ransomware before the files are locked, there is no guarantee that the original files match the recovered ones. Therefore, Emsisoft Decrypter for CryptON is configured not to delete encrypted files, an option that can be disabled in the ‘Options’ tab.

Recover data in your files after getting the CryptON ransomware

Also known as Nemesis or X3M, the CryptON ransomware can do a lot of damage and have you lose important data. And while you should keep a reliable security solution on the lookout at all times, the Emsisoft Decrypter for CryptON can provide a post-infection solution to recovering infected files, one that is worth a try.

Leave a Reply

Your email address will not be published.