The RannohDecryptor utility allows decrypting files affected by Trojan-Ransom.Win32.Rannoh infection.
- Download RannohDecryptor.exe;
How to use the utility
- Run RannohDecryptor.exe.
- Click Start scan to begin the process.
- To delete copies of encrypted files named like “locked-<original_name>.<4 random characters>” after a successful decryption, use the option Delete crypted files after decryption.
- By default, the utility log is saved on system disk (the one with the operating system installed).
Log file name is UtilityName.Version_Date_Time_log.txt.
For example, C:\RannohDecryptor.22.214.171.124_02.05.2012_15.31.43_log.txt
Command line options:
-l <log_file_name> – create a log file with given name.
-y – close the utility after decryption.