What is Xorist-EnCiPhErEd Ransomware

Xorist-EnCiPhErEd shed some light on the ransomware world a couple of years ago and still targets users until these days. Being part of the Xorist family, it encrypts data by using XOR or TEA algorithms and assigning .EnCiPhErEd extension to all files. For instance, 1.mp4 will suffer the change to 1.mp4.EnCiPhErEd. If you try to open any of the infected files, you will see a pop-up error window that displays ransom information. Unlike other ransomware, its developers ask victims to send an SMS message to the mentioned number. Besides that, the virus drops a text file called HOW TO DECRYPT FILES.txt which is identical to the pop-up window. Below, you can see the detailed example of the ransom note:

Xorist Ransomware (variation 1)Xorist Ransomware (variation 2)
Attention! All your files are encrypted!
To restore your files and access them, please send an SMS with the text XXXX to YYYY number.
You have N attempts to enter the code.
When that number has been exceeded, all the data irreversibly is destroyed.
Be careful when you enter the code!
Attention! All your files are encrypted!
To restore your files and access them, please send 2 Bitcoin to adress
1PqBLxDShLCBfjV9s4QkLzb3fi9siVZqDd
and email to j73419517739xu@163.com proof (screen or smth) of your payment.
After receiving the money, I will send you your password and decrypt instruction via email.
You have 20 attempts to enter the code.
When that number has been exceeded, all the data irreversibly is destroyed.
Be careful when you enter the code!

If you fail to enter the code within 5 attempts, your files will be deleted completely, as extortionists claim. Once done, you will more likely get a browser-based link to pay for the decryption software. However, there is no need to meet ransom demands because Fabian Wosar of Emsisoft has found a way to decrypt files encrypted by Xorist. This free removal guide will explain how to do this below.

xorist-enciphered ransomware

How Xorist-EnCiPhErEd Ransomware infected your computer

The way malware penetrates systems spreads over multiple channels like e-mail spam, trojans, fake software cracking tools, keyloggers, backdoors, unprotected RDP configuration, and others. Those who get infected through spam messages, usually click on the attached files (MS Office documents, PDFs, executables, JavaScript files, and ZIP archives) that are infected with ransomware. Fake software cracking tools are exploited by cybercriminals because most users yearn to bypass licensed programs. By doing so, they attract users to download fake software which ends up in the infection of malware. Be careful on the web and avoid unknown links or downloads. To backup your security, there are multiple anti-malware programs that include real-time protection and prevent you from stumbling upon malicious resources.

  1. Download Xorist-EnCiPhErEd Ransomware Removal Tool
  2. Get decryption tool for .EnCiPhErEd files
  3. Recover encrypted files with Stellar Data Recovery Professional
  4. Restore encrypted files with Windows Previous Versions
  5. Restore files with Shadow Explorer
  6. How to protect from threats like Xorist-EnCiPhErEd Ransomware

Download Removal Tool

Download Removal Tool

To remove Xorist-EnCiPhErEd Ransomware completely, we recommend you to use WiperSoft AntiSpyware from WiperSoft. It detects and removes all files, folders and registry keys of Xorist-EnCiPhErEd Ransomware and prevents future infections by similar viruses.

Alternative Removal Tool

Download SpyHunter 5

To remove Xorist-EnCiPhErEd Ransomware completely, we recommend you to use SpyHunter 5 from EnigmaSoft Limited. It detects and removes all files, folders and registry keys of Xorist-EnCiPhErEd Ransomware. The trial version of SpyHunter 5 offers virus scan and 1-time removal for FREE.

Xorist-EnCiPhErEd Ransomware files:


HOW TO DECRYPT FILES.txt
{randomfilename}.exe

Xorist-EnCiPhErEd Ransomware registry keys:

no information

How to decrypt and restore .EnCiPhErEd files

Use automated decryptors

Download Emsisoft Decryptor for Xorist

Emsisoft Decryptor for Xorist

Use following tool from Emsisoft called Emsisoft Decryptor for Xorist, that can decrypt .EnCiPhErEd files. Download it here:

Download Xorist Decryptor

There is no purpose to pay the ransom because there is no guarantee you will receive the key, but you will put your bank credentials at risk.

Dr.Web Rescue Pack

Famous antivirus vendor Dr. Web provides free decryption service for the owners of its products: Dr.Web Security Space or Dr.Web Enterprise Security Suite. Other users can ask for help in the decryption of .EnCiPhErEd files by uploading samples to Dr. Web Ransomware Decryption Service. Analyzing of files will be performed free of charge and if files are decryptable, all you need to do is purchase a 2-year license of Dr.Web Security Space worth $120 or less. Otherwise, you don’t have to pay.

If you are infected with Xorist-EnCiPhErEd Ransomware and removed it from your computer you can try to decrypt your files. Antivirus vendors and individuals create free decryptors for some crypto-lockers. To attempt to decrypt them manually you can do the following:

Use Stellar Data Recovery Professional to restore .EnCiPhErEd files

stellar data recovery professional

  1. Download Stellar Data Recovery Professional.
  2. Click Recover Data button.
  3. Select type of files you want to restore and click Next button.
  4. Choose location where you would like to restore files from and click Scan button.
  5. Preview found files, choose ones you will restore and click Recover.
Download Stellar Data Recovery Professional

Using Windows Previous Versions option:

  1. Right-click on infected file and choose Properties.
  2. Select Previous Versions tab.
  3. Choose particular version of the file and click Copy.
  4. To restore the selected file and replace the existing one, click on the Restore button.
  5. In case there is no items in the list choose alternative method.

Using Shadow Explorer:

  1. Download Shadow Explorer program.
  2. Run it and you will see screen listing of all the drives and the dates that shadow copy was created.
  3. Select the drive and date that you want to restore from.
  4. Right-click on a folder name and select Export.
  5. In case there are no other dates in the list, choose alternative method.

If you are using Dropbox:

  1. Login to the DropBox website and go to the folder that contains encrypted files.
  2. Right-click on the encrypted file and select Previous Versions.
  3. Select the version of the file you wish to restore and click on the Restore button.

How to protect computer from viruses, like Xorist-EnCiPhErEd Ransomware, in future

1. Get special anti-ransomware software

Use BitDefender Anti-Ransomware

bitdefender anti-ransomware

Famous antivirus vendor BitDefender released free tool, that will help you with active anti-ransomware protection, as additional shield to your current protection. It will not conflict with bigger security applications. If you are searching complete internet security solution consider upgrading to full version of BitDefender Internet Security 2018.

Download BitDefender Anti-Ransomware

2. Back up your files

idrive backup

As an additional way to save your files, we recommend online backup. Local storages, such as hard drives, SSDs, flash drives or remote network storages can be instantly infected by the virus once plugged in or connected to. Xorist-EnCiPhErEd Ransomware uses some techniques to exploit this. One of the best services and programs for easy automatic online backup is iDrive. It has the most profitable terms and simple interface. You can read more about iDrive cloud backup and storage here.

3. Do not open spam e-mails and protect your mailbox

mailwasher pro

Malicious attachments to spam or phishing e-mails is most popular method of ransomware distribution. Using spam filters and creating anti-spam rules is good practice. One of the world leaders in anti-spam protection is MailWasher Pro. It works with various desktop applications, and provides very high level of anti-spam protection.

Download MailWasher Pro
Previous articleHow to remove Locky Ransomware and decrypt .locky files
Next articleHow to remove Managed by your organization from Google Chrome