.rox Ransomware Decryption: What to Do When Your Files Are Encrypted

.rox Ransomware Decryption: What to Do When Your Files Are Encrypted
Last month, a trading company in Kwun Tong arrived at work to find every Excel quotation and PDF contract on their server renamed with a .rox extension — unopenable. Each folder contained a ransom note demanding 0.8 BTC (about HK$400,000 at the time) for a decryption tool. The boss called us, voice shaking: "All our client order data is in there. We have shipments going out tomorrow. What do we do?"
That case ended without paying the ransom — we recovered 90% of the files in three days. Here's a detailed walkthrough of what to do step by step after a .rox infection.
What is .rox and how does it get in?
.rox is a ransomware family that appends the .rox extension to encrypted files — e.g. Quotation2026.xlsx becomes Quotation2026.xlsx.rox. It uses AES-256 + RSA-2048 hybrid encryption; without the private key, brute force is effectively impossible.
From the dozen-plus .rox cases we've handled, there are three main infection vectors:
- Phishing email attachments (most common, ~60%): Disguised as "customs declarations", "invoices" or "SF Express delivery notices", with a .zip containing a hidden .exe or macro-enabled Office document. The Kwun Tong case started when their accountant opened a fake "shipping company" email.
- RDP brute force: Company servers with port 3389 exposed and weak passwords like
Admin123— attackers scan and break in within hours. A repair shop in Sham Shui Po lost everything overnight this way. - Pirated software / cracks: A freelance designer downloaded a "Photoshop crack" bundled with .rox and lost their entire portfolio.
First 10 minutes: 3 things you must NOT do
Panic causes mistakes that turn recoverable situations into hopeless ones:
- Don't immediately shut down or reinstall: Counterintuitive but correct. Decryption keys or memory traces may still be in RAM — a reboot wipes them. Unplug the network cable (isolate), keep the machine on, and photograph the ransom note.
- Don't delete the ransom note or encrypted files: The victim ID, contact email and Bitcoin address in the note are critical for identifying the malware family. One client deleted everything in anger, making identification ten times harder.
- Don't pay the ransom immediately: Payment doesn't guarantee a working decryptor — we've seen clients pay 0.5 BTC and never hear back. And paying funds the next attack. Exhaust the checks below first.
Are there free decryption tools for .rox?
The most-asked question. Answer: it depends on luck and version.
First, upload a ransom note + one encrypted file to No More Ransom (run by Europol) — it will identify the family and tell you if a public decryptor exists. You can also use ID Ransomware.
Honestly, newer .rox variants have no public free decryptor yet. But recovery without paying is possible when:
- Older version with a flaw: Some early .rox variants had weak key generation; researchers released decryptors. If ID Ransomware identifies an old version, there's hope.
- Volume Shadow Copies intact: In about 30% of cases the malware fails to delete Windows shadow copies — run
vssadmin list shadowsto check for restore points. The Kwun Tong case recovered most Excel files this way. - Offline backups exist: The safest bet. An external drive that's unplugged after backup can't be touched by ransomware.
Real case: Kwun Tong trading company recovers 90% in 3 days
Back to the opening case. The boss didn't pay. Here's what we did on-site:
- Isolated all 12 company PCs from the network; checked each one — only the server and two accounting PCs were infected, the rest had been "touched" but not executed.
- Confirmed via ID Ransomware: new .rox variant, no public decryptor.
- Checked Volume Shadow Copies: the server had a two-month-old restore point (last month's quotations missing); the accounting PC had last week's shadow copy.
- Accounting PC: restored from shadow copy, 95% of files recovered.
- Server: restored the two-month-old version, then manually rebuilt the last two months of orders from emails and paper records. The customer database was fully intact thanks to daily automated Google Drive backups (credit to their IT guy).
Three days total, HK$8,500 (emergency callout + data recovery). The boss said: "$8,500 versus a $400,000 ransom — and no dealing with criminals. Worth every cent." Afterwards we hardened their whole network: RDP port change + whitelist, staff phishing training, and proper 3-2-1 backups.
How to prevent the next one
- 3-2-1 backup: 3 copies, 2 media types, 1 offline. Always unplug the backup drive after backing up — otherwise it's as good as no backup.
- Don't expose RDP directly: Use VPN, or at minimum change the port + enable account lockout (lock for 30 minutes after 5 failed attempts).
- Email attachment vigilance: A .exe, .js or macro-enabled Office file inside a .zip is a trap 99% of the time. When in doubt, call the sender to verify.
- Regular offline scans: Run Windows Defender Offline Scan or Malwarebytes monthly.
FAQ
1. Q: Can I just rename .rox files back to the original extension?
A: No. The extension is just a name — the data inside is AES-encrypted and will still be gibberish. Don't rename randomly; it can interfere with later decryption identification.
2. Q: Does paying the ransom guarantee file recovery?
A: No. Statistics show only about 60% of ransom payers get their files back intact. Some criminals take the money and vanish; some decryptors are buggy and corrupt files. Payment is the absolute last resort.
3. Q: How much does your on-site ransomware service cost?
A: Emergency callout and assessment from HK$1,500 (urban areas); data recovery typically HK$3,000–15,000 depending on volume and difficulty. We quote upfront — no obligation if the price doesn't work for you.
4. Q: Can Macs get .rox?
A: .rox mainly targets Windows, but Macs have their own ransomware (e.g. ThiefQuest). Mac users shouldn't feel safe — keep Time Machine backups running.
5. Q: Can antivirus stop .rox?
A: Up-to-date mainstream antivirus (Bitdefender, Kaspersky, Windows Defender) blocks known variants reasonably well, but zero-day variants often slip past signatures and are only caught by behavioural detection. Don't rely on antivirus alone — backups are king.
Summary
If you're hit by .rox, stay calm: disconnect, photograph, don't touch anything, and don't rush to pay. Identify the malware first, then check for shadow copies or backups. Only call professionals when you're truly stuck. Remember, the best decryption is the one you never need — thanks to backups.
If you or your company has been hit, WhatsApp us immediately at +852 6558 6806 (24-hour emergency support), or check our Computer Repair and Data Recovery services. Our blog has more guides including the full ransomware protection guide.
Found this article helpful?
Feel free to share it with your friends or colleagues.