Lost all your files to some nasty ransomware?

We're here to fix that.

Download one of our free decryptor tools to recover your files without paying the ransom

No More Ransom

Associate Partner

I need removal help
[Mar, 22, 2016] - Version:

Emsisoft Decryptor for Nemucod

Nemucod is a JavaScript downloader malware that used to be used by TeslaCrypt for distributing TeslaCrypt binaries. Recent Nemucod versions dropped the TeslaCrypt payload in favour of its own ransomware implementation. The Nemucod ransomware encrypts the first 2048 bytes of a file using a 255 bytes XOR key. 

To use the decrypter you will require an encrypted file of at least 4096 bytes in size as well as its unencrypted version. To start the decrypter select both the encrypted and unencrypted file and drag and drop them onto the decrypter executable.