How to remove DecYourData ransomware and decrypt _all-files-encrypted files

Article’s Guide

  1. What does _all-files-encrypted stand for?
  2. DecYourData ransomware encryption process.
  3. How to remove DecYourData Ransomware from your computer
  4. How to decrypt _all-files-encrypted files
  5. Data Recovery
  6. Automated decryption tools
  7. Other software

What does “_all-files-encrypted” mean?

If you see, that your files are unreadable and have got new extension “id-[*email*]_all-files-encrypted”, it means that your device is infected with DecYourData ransomware. The function of DecYourData is to prevent users from the accessing to definite file formats. This virus has already infected a great number of computers and potentially everyone can become infected with it. This is achieved by the means of ways it’s spread. The most widely used one is the creating of fake installators and email attachments. By the means of fake messages and various frauds hackers trick users into downloading and opening such files. However, nowadays remote access software become more and more popular. Such software, as ScreenConnect allows them to install the virus directly. This soft is usually installed by trojan viruses, and it’s really difficult to recognize such an attack. That’s why it’s necessary to have an up-to-date antivirus protection. In the case, if your computer is already infected with this virus, don’t try to remove DecYourData ransomware or to decrypt _all-files-encrypted files without special tools. Every modification, made on an infected computer, can lead to different difficulties.



DecYourData encryption process.

The encryption, that DecYourData proceeds, can be divided into several steps. At first the virus creates new keys in the Registry Folder in order to make the system think, that all executed processes are legitimate. Then it infects system processes, by the means of which it searches and modifies files. DecYourData encrypts only definite file formats, such as documents, media files, archives, databases and etc. Moreover, it attacks website files, such as .xlsx format. As the result, the files are unreadable and have got new extensions – “id-*ID* [decyourdata@protonmail.com]_all-files-encrypted”. There is one unusual feature: DecYourData doesn’t use a dot in the extension. The purpose of this attack is to make a victim pay for the decryption services provided by hackers. For this purpose they usually drop the ransom note called “Help for decrypting id-*ID* [decyourdata@protonmail.com].txt”. As the rule, hackers try to assure victims, that the only way to restore files is to get the decryption key. Unfortunately, due to the novelty of this virus, it’s really the only method to restore 100% of encrypted files. However, in the most cases, hackers stop all contacts with the victims, once the’ve been paid. Moreover, they can easily send a malicious software instead of the decryptor and make the situation much worse. That’s why we strongly recommend you to avoid all contacts with them. Specially for this case, we’ve prepared the detailed guide on how to remove DecYourData ransomware and decrypt _all-files-encrypted files!


"] All your data have been locked. Want restore your data?
Fill subject with your ID like this: id-xxxxx
Email: decyourdata@protonmail.com



How to remove Tor+ Ransomware from your computer?

We strongly recommend you to use a powerful anti-malware program that has this threat in its database. It will mitigate the risks of the wrong installation, and will remove DecYourData from your computer with all of its leftovers and register files.

Solution for Windows users: our choice is Norton 360 . Norton 360 scans your computer and detects various threats like DecYourData, then removes it with all of the related malicious files, folders and registry keys.

Download Norton windows compatible

If you are Mac user, we advise you to use Combo Cleaner.


How to decrypt _all-files-encrypted files?

Once you’ve removed the virus, you are probably thinking how to decrypt _all-files-encrypted files or at least restore them. Let’s take a look at possible ways of decrypting your data.

Restore _all-files-encrypted files with Data Recovery

Data Recovery

  1. Download and install Data Recovery
  2. Select drives and folders with your files, then click Scan.
  3. Choose all the files in a folder, then press on Restore button.
  4. Manage export location.

Download Stellar Data Recovery

The download is an evaluation version for recovering files. To unlock all features and tools, purchase is required ($49.99-299). By clicking the button you agree to EULA and Privacy Policy. Downloading will start automatically.


Decrypt _all-files-encrypted files with other software

Unfortunately, due to the novelty of DecYourData ransomware, there are no decryptors that can surely decrypt encrypted files. Still, there is no need to invest in the malicious scheme by paying a ransom. You are able to recover files manually.
You can try to use one of these methods in order to restore your encrypted data manually.

Decrypt _all-files-encrypted files with Emsisoft decryptor

This software includes information about more than 100 viruses of STOP(DJVU) family and others. All that you need are two files or some luck. You can freely use it as it distributes free of charge. If it doesn’t work for you, you can use another method.

Restore _all-files-encrypted files with Windows Previous Versions

This feature is working on Windows Vista (not Home version), Windows 7 and later versions. Windows keeps copies of files and folders which you can use to restore data on your computer. In order to restore data from Windows Backup, take the following steps:

  1. Open My Computer and search for the folders you want to restore;
  2. Right-click on the folder and choose Restore previous versions option;
  3. The option will show you the list of all the previous copies of the folder;
  4. Select restore date and the option you need: Open, Copy and Restore.

Restore _all-files-encrypted files with System Restore

You can always try to use System Restore in order to roll back your system to its condition before infection infiltration. All the Windows versions include this option.

  1. Type restore in the Search tool;
  2. Click on the result;
  3. Choose restore point before the infection infiltration;
  4. Follow the on-screen instructions.

Was this tutorial helpful?
[Total: 0 Average: 0]

Leave a Comment

Time limit is exhausted. Please reload CAPTCHA.