The Paradise Ransomware is not decryptable without paying the ransom. It is not currently known how Paradise infects a computer, but from entries in the event log of an infected computer, it may be via hacked Remote Desktop services. It will then generate a unique RSA-1024 key that is then used to encrypt all of the files on each drive on the computer. This encryption process is very slow, which hopefully allows a victim time to detect the encryption taking place and stop it. The ransom note will contain the affiliate email address and instructions on how to make the payment.
Source: https://www.bleepingcomputer.com/news/security/paradise-ransomware-uses-rsa-encryption-to-encrypt-your-files/

