Lagos, Nigeria

How Do I Decrypt Files Encrypted by Ransomware? – Ask Leo!


… some of my files are gone, saying they have been encrypted with a public key. Files like my photos and so on. Of course they have a high fee in order for me to get them back. Do you have a solution?

That was a question I received in my morning email from a friend.

While there are a few straws to grasp at, the news is really not good. The whole point of ransomware is that there’s no easy, simple way to undo the damage. If there were, ransomware wouldn’t be a thing.

I’ll look at the few options you have, and then how prevention before ransomware happens can give you peace of mind.

Ransomware is malware that encrypts your files, making them unusable. They promise to decrypt the files if you pay a fee (or ransom). You may get lucky and find decryption keys for the ransomware you face in a public collection, but it’s unlikely. Backing up properly is the only sure-fire way to be able to recover from ransomware, next to avoiding it in the first place.

Encrypted by ransomware

Ransomware is a specific type of malware. It encrypts your files so you’re unable to access or use them, and then offers to decrypt them if you pay the ransom.

Unfortunately, the technology used — “public key encryption” — is generally good. It’s the same encryption technology you and I use to keep our data secure and our internet conversations private.

When done right, a file encrypted using public-key cryptography is essentially unrecoverable, unless you have the matching private key.

And needless to say, the hackers do it right. It’s essentially impossible to decrypt files encrypted by ransomware without their private key.

Ransomware private key collections

As the threat and impact of ransomware has grown, security pros and authorities have been working to track down the hackers and take down their operations. On occasion, they succeed, and that specific ransomware threat is stopped.

When this happens, the private keys the hackers had are sometimes, though not always, discovered, and made available to the public.

The No More Ransom Project maintains a database of known ransomware keys. Quoting their site:

… it is sometimes possible to help infected users to regain access to their encrypted files or locked systems without having to pay. We have created a repository of keys and applications that can decrypt data locked by different types of ransomware.

I’ve emphasized the word “sometimes” on purpose. There are no guarantees. In fact, in my experience, “sometimes” should really be “on rare occasions”.

If your files are encrypted by ransomware, that’s a straw worth grasping. In fact, if you haven’t prepared ahead of time, it’s really your only option.

Cures for ransomware

The best possible cure is to avoid having your files encrypted by ransomware in the first place. That means using the internet safely and all that entails. Avoid malware, phishing schemes, and all the other ways that hackers get ransomware on to your machine.

The second best cure is to have a backup. If you find your computer afflicted with ransomware and your files encrypted, restoring them from a backup is the only 100% reliable recovery method.

And since ransomware can, in some (fortunately infrequent) cases, even encrypt your backups, you need to understand and plan for a robust solution that allows you to recover. Normally this means automated daily backups and periodically making an offline copy, out of ransomware’s reach.

Recovering from ransomware

By far, the simplest, fastest, most reliable solution to recovering files encrypted by ransomware is to restore them from a backup taken before the ransomware took hold. You restore the backup image of your entire machine to its state prior to the infection, and it’s as if the ransomware never happened.

Hopefully, once restored, you’ll know not to do whatever it caused the infection in the first place.

If you don’t have a complete image backup of your machine, but you do have a backup of your data, recovery is possible, albeit somewhat more work. I recommend that you:

  • Take an image backup of the infected machine. This is to preserve a copy of the machine in its current state, in case it becomes necessary to recover something from it in the future.
  • Wipe the machine and install Windows from scratch.
  • Install your applications from scratch.
  • Restore your data.

If you have no backup of your data, things are significantly more dire.

Decrypting ransomware-encrypted files

There’s no magical solution for decrypting a strongly encrypted file. If you don’t find the decryption key in a service like No More Ransom, then you’re severely out of luck.

Which leaves the ultimate question: should you pay?

First, let’s be clear: these are criminals you’re thinking of dealing with. There’s no guarantee they’ll follow through, should you elect to make payment. It could be the equivalent of simply throwing your money away.

Or … it could recover your files.

Only you can decide whether or not to pay criminals the ransom.

My position is: don’t. Doing so only encourages their criminal enterprise, and puts even more people at risk of finding their files encrypted by ransomware.

Instead, learn from the experience. Most importantly, start backing up so this never has to happen to you again.

If you found this article helpful, I’m sure you’ll also love Confident Computing! My weekly email newsletter is full of articles that help you solve problems, stay safe, and give you more confidence with technology. Subscribe now and I’ll see you there soon,


10 Reasons Your Computer is Slow

Slow Computer?

Speed up with my FREE special report: 10 Reasons Your Computer is Slow, now updated for Windows 10.

No strings. No email. Here’s the direct download. (Just right-click and “Save As…”.)

This post was written by Leo Notenboom and was first posted to

Do you find this article helpful? Your Friend might too. So, please Share it with them using the Share button above.
Will you like to get notified when I post new updates? Then Follow me on any of my social media handles: Google News, Telegram, WhatsApp, Twitter, Facebook, Pinterest.
You can also drop your email address below if you wish to be notified by mail.

[newsletter_form type="minimal" lists="undefined" button_color="undefined"]

Tags: ,