Tag Archives: AVG VirusLab

Don’t pay the Ransom! AVG releases six free decryption tools to retrieve your files

Ransomware has proven very lucrative for criminals. Many have extended their “business” models by adding ransomware to their malicious catalog. To help prevent personal data and files being held hostage by cybercriminals, we have previously, advised on how to avoid ransomware infections, and what to do if your files have already been held to ransom. In that article, we stated that:

“Many ransomware families contain weaknesses in their encryption algorithm, which may lead to decrypting your files even without paying the ransom! It may take some time to spot and exploit such weaknesses, but in the meantime don’t delete your encrypted files; there may still be hope.”

And now there is hope. With our new tools, you should be able to recover your files without paying the ransom.

Using the Ransomware Decryption Tools

Our new free tools are for the decryption of six current ransomware strains: Apocalypse, BadBlock, Crypt888, Legion, SZFLocker, and TeslaCrypt.

To use, follow our simple four step process to unlock your files:

  1. Run a full system scan on the infected PC.
  2. (Optional) Back-up the encrypted files on their own flash drive, so they can then be transferred to another PC for decryption.
  3. Identify which infection strain encrypted your files. See the descriptions of each strain below. If your ransomware infection matches the strain details, download the appropriate tool and launch it.
  4. The tool opens a wizard, which breaks the decryption process into several easy steps:

Follow the steps, and you should again be able to reclaim your files in most cases. After decryption, be sure to securely back up restored files on a flash drive or in the cloud.

Apocalypse

The Apocalypse ransomware appends “.encrypted”, “.locked”, or “.SecureCrypted” to names of encrypted files (e.g. example.docx.encrypted, example.docx.locked, example.docx.SecureCrypted). It also creates ransom messages in files with extensions “.How_To_Decrypt.txt”, “.README.Txt”, or “.Contact_Here_To_Recover_Your_Files.txt” (e.g. example.docx.How_To_Decrypt.txt, example.docx.README.Txt, or example.docx.Contact_Here_To_Recover_Your_Files.txt).

In those messages, you can find contact addresses such as [email protected], [email protected], [email protected], or [email protected]. For example:

We prepared two separate decryption tools for this strain: one for the early versions of Apocalypse and the other one for the current version:

http://files-download.avg.com/util/avgrem/avg_decryptor_Apocalypse.exe

http://files-download.avg.com/util/avgrem/avg_decryptor_ApocalypseVM.exe

BadBlock

BadBlock does not rename encrypted files. You can identify BadBlock by the ransom message named “Help Decrypt.html” and by the red windows with ransom messages, like the following ones:

The BadBlock decryption tool can be found here:

http://files-download.avg.com/util/avgrem/avg_decryptor_BadBlock32.exe

http://files-download.avg.com/util/avgrem/avg_decryptor_BadBlock64.exe

Crypt888

Crypt888 (aka Mircop) creates encrypted files with the prepended name “Lock.” (e.g. Lock.example.docx). It also changes your desktop’s wallpaper to the following image:

Unfortunately, Crypt888 is a badly written piece of code, which means some of the encrypted files or folders will stay that way, even if you pay the fine, as their “official decryptor” may not work.  The AVG decryptor can be found here:

http://files-download.avg.com/util/avgrem/avg_decryptor_Crypt888.exe

Legion

Legion encrypts and renames your files with names like “example.docx[email protected]$.legion”. It also changes the desktop wallpaper and displays a warning about your encrypted files:

Note: Don’t be confused by another ransomware strain that renames files to a similar name – “[email protected]”. It is NOT the same strain and it cannot be decrypted by this tool.

The decryptor is available here:

http://files-download.avg.com/util/avgrem/avg_decryptor_Legion.exe

SZFLocker

The name of this ransomware originates from a string that is appended to the names of encrypted files (e.g. example.docx.szf). The original files are rewritten with the following Polish message:

The decryptor for SZFLocker is available here:

http://files-download.avg.com/util/avgrem/avg_decryptor_SzfLocker.exe

TeslaCrypt

Last but not least, we prepared a decryptor for the infamous TeslaCrypt. This tool supports decryption of files encrypted by TeslaCrypt v3 and v4. The encrypted files come with different extensions, such as .vvv, .micro, .mp3, or with the original name only. It also displays a message like the following:

The decryptor can be found here:

http://files-download.avg.com/util/avgrem/avg_decryptor_TeslaCrypt3.exe

Conclusion

At AVG, we take ransomware threats very seriously. Be proactive by using multilayered protection, such as AVG Antivirus Pro, which detects and removes ransomware. Adding  decryption tools is a last resort for when your files are already encrypted by ransomware and you need to get your valuable data back.

AVG Business kicks off Cybersecurity Month with free upgrade to 2016 Business Software Suite

AMSTERDAM – September 30, 2015 – AVG® Technologies N.V. (NYSE: AVG), the online security company™ for more than 200 million monthly active users, today announced the release of its 2016 Business Edition software suite with new versions of its AVG AntiVirus Business Edition and AVG Internet Security Business Edition products. The 2016 suite, central to the company’s expanded security strategy for business, provides enterprise scale security to channel partners and small to medium-sized businesses (SMBs) in the frontline defense against malware and online threats.

Available worldwide, the products include a free remote management console to provide businesses easy and efficient remote access to all systems on a network. Technical support is also included at no cost.

“Today’s release of our core AntiVirus and Internet Security products for business delivers new and advanced cybersecurity protections and we are excited to get these into the hands of our channel and small to medium businesses across the globe,” said Joanna Brace, VP of Marketing and Product Marketing, AVG Business. “Online security is our core expertise and it is a fundamental requirement for business growth and success in today’s connected world. With the release of these critical security solutions, we are once again demonstrating our online security leadership and commitment to our customers.”

Today’s news is timed with two industry initiatives European Cyber Security Month and National Cyber Security Awareness Month, underscoring AVG’s leadership in online security and its strong commitment to protecting devices, data and people at work and at home. In support of these initiatives, channel partners will receive free upgrades to the 2016 Business Edition with renewals of existing licenses. AVG Business is also hosting security webinars for SMBs and providing comprehensive reseller kits for partners.

Features of the new 2016 Business Edition upgrade include:

  • New Scanning Engine: Scans faster and smarter with cloud-based detection technology
    The 2016 scanning engine implements AVG’s most advanced algorithms, providing better protection and shorter scanning times. It is also driven by new cloud-based detection technologies that leverage the majority of AVG’s 200 million endpoints to rapidly recognize new and emerging threats and deliver virus updates in as close to real-time as possible.
  • New Real-Time Outbreak Detection: Uses crowd intelligence technology for better protection
    Crowd intelligence technology has been added to AVG’s cloud-based outbreak detection to identify even the newest malware variants and outbreaks in software, all in real-time.
  • New Artificial Intelligence Detection: Uses advanced intelligence to identify threats
    Advanced artificial intelligence has been added to proactively identify new threats in real-time before our AVG VirusLab team has catalogued the threats.
  • Online Shield: Uses the Cloud to guard against today’s threats
    The 2016 Online Shield delivers today’s best cloud-based detection to more quickly identify dangerous downloads.
  • Data Safe: Protects your company’s most valuable data
    Data Safe lets businesses create password-protected virtual disks on their system, ensuring they can confidently encrypt and protect folders, files and data securely.
  • File Shredder: Deletes data securely
    Industry-compliant File Shredder securely deletes data to help prevent unintended recovery.

The AVG AntiVirus Business Edition and AVG Internet Security Business Edition are available now.

Channel partners can work directly with their account managers and also download our comprehensive reseller kits at our Reseller Center: https://secure.avg.com/rc-login. SMBs can purchase from the AVG.com web site: http://www.avg.com/business-security.


The AVG Business Portfolio

The AVG Business portfolio includes AVG Business CloudCare™, a free cloud-based administration platform offering channel partners a simple way to implement and manage services such as antivirus, content filtering, online backup and email security services for their customers, using centralized and highly customizable policies; the 2016 AVG Business Edition, a suite of software solutions that includes AVG AntiVirus Business Edition and AVG Internet Security Business Edition and offers comprehensive security protection for channel partners and SMBs;  AVG Business Managed Workplace, a comprehensive remote monitoring and management (RMM) platform with integrated premium remote control for channel partners and their clients; and AVG Business Secure Sign-On, a next-generation mobile device management service.

Supported by a worldwide network of more than 10,000 partners, AVG’s strong IT security heritage complements its proven strength as an RMM provider and partner to help smaller IT companies and MSPs transition and flourish as fully-fledged managed services businesses.

To view our Press Kit, which includes product screenshots, video and other elements of this news, please visit http://now.avg.com/avg-2016-business-edition-press-kit.


About AVG Technologies (NYSE: AVG)

AVG is the online security company providing leading software and services to secure devices, data and people. AVG’s award-winning technology is delivered to over 200 million monthly active users worldwide. AVG’s Consumer portfolio includes internet security, performance optimization, and personal privacy and identity protection for mobile devices and desktops. The AVG Business portfolio – delivered by managed service providers, VARs and resellers – offers IT administration, control and reporting, integrated security, and mobile device management that simplify and protect businesses.

All trademarks are the property of their respective owners.

www.avg.com


Contacts:

Zoe Kine
Tel: +1 415-694-3654
Email: [email protected]

Zena Martin
Tel: +44 7496 638 342
Email: [email protected]

 

Press information: http://now.avg.com