New CryptXXX ransomware cannot be removed even after purchasing decryption key
The new version of the CryptXXX ransomware cannot be removed even after purchasing a decryption key, according to several users. The previous two versions did not show this problem.
Several victims have complained to the BleepingComputer site, which reports that the ransomware has recently been updated to version 3.0. This would ensure, among other things, that the criminals themselves are not able to decrypt an affected system, so that victims buy a key for nothing.
CryptXXX has been flawed for some time and the security company Kaspersky was able to develop a free decryption tool for the previous two versions. However, such a tool is not yet available for the latest version. It is therefore advisable for victims to wait for Kaspersky to release a new tool, instead of purchasing a decryption key. It is unclear whether the people behind CryptXXX intentionally provide the wrong keys or whether they made a mistake themselves.
It was recently announced that the developers of the TeslaCrypt ransomware have given up on the project. They posted a notice on their page in which they published a universal decryption key and in which they apologized. They also recommended a decryption tool called TeslaDecoder in a later message. It is believed that the CryptXXX ransomware will be the replacement for TeslaCrypt. CryptXXX is mainly identified by the ‘.crypt’ extension of encrypted files.