Jump to content

Virus encrypted files with .locky extention

BeyondRico

hi there,

 

So someone out of my family just called me to tell that his pc was having a virus. the virus is deleted now but all his pictures and word documents are encrypted with a .locky extention.

does one of you know a way to decrypt those files, there is no backup so i would love if someone could help me with this problem.

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

Try renaming the .locky extension to .docx or .png or something like that.

 

Ryzen 5 3600 stock | 2x16GB C13 3200MHz (AFR) | GTX 760 (Sold the VII)| ASUS Prime X570-P | 6TB WD Gold (128MB Cache, 2017)

Samsung 850 EVO 240 GB 

138 is a good number.

 

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, themctipers said:

Try renaming the .locky extension to .docx or .png or something like that.

 

i think it's not that easy, all those files are locked with a  RSA-2048 and AES-128 encryption. 

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, RSmeets said:

i think it's not that easy, all those files are locked with a  RSA-2048 and AES-128 encryption. 

Well you're screwed..

Ryzen 5 3600 stock | 2x16GB C13 3200MHz (AFR) | GTX 760 (Sold the VII)| ASUS Prime X570-P | 6TB WD Gold (128MB Cache, 2017)

Samsung 850 EVO 240 GB 

138 is a good number.

 

Link to comment
Share on other sites

Link to post
Share on other sites

I think locky isn't hacked yet. And since its already a little older there isn't anything to be expected.
So you have two options: Hope that there will be a way to decrypt the files or delete everything and create backups the next time. (like you / your family member should've done anyway)

~ ThxAndBye

"You should remove any cats from the vicinity, because cats will cause all kinds of problems doing CPU installation." -Linus

delid i7-3770k @ 4.2Ghz @ 1.265V | EVGA z77 FTW | GTX 680 2way-SLI | 16GB Corsair Dominator Platinum @ 1866MHz | 240GB SSD RAID 0 | Full Custom Water Loop with two 360mm radiators  -> live temps <-

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, RSmeets said:

. . .all his pictures and word documents are encrypted with a .locky extention. . .

And this is why I am paranoid.

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Thx And Bye said:

I think locky is not hacked yet. And since its already a little older there isn't anything to be expected.
So you have two options: Hope that there will be a way to decrypt the files or delete everything and creates backups the next time. (like you should've done anyway)

it's not my pc so i know they should have made a backup, but it's too late for a backup now.....

anyways i am going to wait and hope there will be an decrypter soon

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, RSmeets said:

anyways i am going to wait and hope there will be an decrypter soon

You can put all the encrypted files (any the key you get from locky, without the key you are out of luck in any possibe way) to a other drive, but like i said: Since locky is already pretty old (more than 4 weeks) don't expect anything to be released for decrypting.

Petya took ~2 weeks to be hacked and the ransomware "Jigsaw" was pretty much instantly hacked.

I don't know of any other ransomware out of my memory.

 

EDIT: As i recall correctly there is more than one locky version out there. (not 100% sure) So even if there might be a decrypter in the future, it might not apply to your version.

~ ThxAndBye

"You should remove any cats from the vicinity, because cats will cause all kinds of problems doing CPU installation." -Linus

delid i7-3770k @ 4.2Ghz @ 1.265V | EVGA z77 FTW | GTX 680 2way-SLI | 16GB Corsair Dominator Platinum @ 1866MHz | 240GB SSD RAID 0 | Full Custom Water Loop with two 360mm radiators  -> live temps <-

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Thx And Bye said:

You can put all the encrypted files to a other drive, but like i said: Since locky is already pretty old (more than 4 weeks) don't expect anything to be released for decrypting.

Petya took ~2 weeks to be hacked and the ransomware "Jigsaw" was pretty much instantly hacked.

I don't know of any other ransomware out of my memory.

on some other forums i found a program that could decrypt those files. only the link is not working anymore(this is the other site).

 

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, RSmeets said:

on some other forums i found a program that could decrypt those files. only the link is not working anymore(this is the other site).

 

Locky is much newer than 31 May 2015. So if they haven't had a time machine, that does not apply to your files anyways.

~ ThxAndBye

"You should remove any cats from the vicinity, because cats will cause all kinds of problems doing CPU installation." -Linus

delid i7-3770k @ 4.2Ghz @ 1.265V | EVGA z77 FTW | GTX 680 2way-SLI | 16GB Corsair Dominator Platinum @ 1866MHz | 240GB SSD RAID 0 | Full Custom Water Loop with two 360mm radiators  -> live temps <-

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Thx And Bye said:

Locky is much newer than 31 May 2015. So if they don't have had a time machine, that does not apply to your files anyways.

oke thanks anyways. i hope they  will find a way to decrypt those files

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

 

50 minutes ago, RSmeets said:

hi there,

 

So someone out of my family just called me to tell that his pc was having a virus. the virus is deleted now but all his pictures and word documents are encrypted with a .locky extention.

does one of you know a way to decrypt those files, there is no backup so i would love if someone could help me with this problem.

Chances are the system is gone. Ransomware is one of the most evil hacks designed... My best suggestion is to format the hard drive and reinstall with a fresh OS. If you want to MAYBE recover the data, install a new HDD into the computer and save the infected HDD till you can find a decryption algorithm. That way at least the person can have a working system for the time being.

The only thing we have to fear is... Stupidity...

Link to comment
Share on other sites

Link to post
Share on other sites

And tell him to get a program that sandboxes his browser so this never happens again.

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, positivePXL said:

And tell him to get a program that sandboxes his browser so this never happens again.

Locky most probably comes via a word files that contains macros. So only sandboxing the browser wouldn't've helped anything if the document would be opened without the sandbox or coming as a attachment from an email.

Backups are pretty much the only thing you can to to ensure you won't have any data loss. (and that not only from ransomware)

~ ThxAndBye

"You should remove any cats from the vicinity, because cats will cause all kinds of problems doing CPU installation." -Linus

delid i7-3770k @ 4.2Ghz @ 1.265V | EVGA z77 FTW | GTX 680 2way-SLI | 16GB Corsair Dominator Platinum @ 1866MHz | 240GB SSD RAID 0 | Full Custom Water Loop with two 360mm radiators  -> live temps <-

Link to comment
Share on other sites

Link to post
Share on other sites

Which is also why I refuse to install Office, or download attachments off of emails (from anybody).

Link to comment
Share on other sites

Link to post
Share on other sites

I have recently had a network hit with this virus, depends on how desperate you are to retrieve the data and if you're willing to pay but the guys below were great and managed to decrypt over 16,000 files. 

 

http://www.redmosquito.co.uk/services/data-recovery-2-2

 

Good luck! 

CPU Intel i7 3770K   Motherboard ASUS Maximus V Extreme   Memory 32GB Corsair Vengance LP 1600MHz   GPU Gigabyte GeForce GTX 960 G1 Gaming 4GB   Case Fractal Design Define R4   HDD Samsung Evo 250GB, 2 x Seagate Barracuda 4TB (RAID 1)   PSU Corsair RM650i   Display 2 x Samsung LS24D590 23.6" LED   Cooling Be Quiet BK018 Dark Rock 3, 4 x Noctua NF-A14   Keyboard Razer Blackwidow Ultimate   Mouse Razer DeathAdder   Sound Razer Kraken Pro   OS Windows 10 Professional

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, VulcanAndroid said:

 

Chances are the system is gone. Ransomware is one of the most evil hacks designed... My best suggestion is to format the hard drive and reinstall with a fresh OS. If you want to MAYBE recover the data, install a new HDD into the computer and save the infected HDD till you can find a decryption algorithm. That way at least the person can have a working system for the time being.

the os is fine the only thing is those encrypted files. so i need to decrypt them that's it

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, LeeFazackerley said:

I have recently had a network hit with this virus, depends on how desperate you are to retrieve the data and if you're willing to pay but the guys below were great and managed to decrypt over 16,000 files. 

 

http://www.redmosquito.co.uk/services/data-recovery-2-2

 

Good luck! 

is it available in the netherlands?

My Red/Black rig: CM Storm Trooper Window - i5 4690K - Asus GTX 980 Strix DCU - Asus VII Formula z97 - Corsair H100i - 16GB Vengeance pro 2400MHz -Samsung 850 Pro 256GB(os) - Seagate barracuda 2TB - crucial BX200 250GB SSD - Cooler Master v850.----  Dell XPS 13: i5-5500u - 256GB SSD - 8GB DDR3L.

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, RSmeets said:

is it available in the netherlands?

I don't see why not, they operate via you uploading your 'locked' files in their Dropbox account, they do the fiddling around and drop it back to you! 

CPU Intel i7 3770K   Motherboard ASUS Maximus V Extreme   Memory 32GB Corsair Vengance LP 1600MHz   GPU Gigabyte GeForce GTX 960 G1 Gaming 4GB   Case Fractal Design Define R4   HDD Samsung Evo 250GB, 2 x Seagate Barracuda 4TB (RAID 1)   PSU Corsair RM650i   Display 2 x Samsung LS24D590 23.6" LED   Cooling Be Quiet BK018 Dark Rock 3, 4 x Noctua NF-A14   Keyboard Razer Blackwidow Ultimate   Mouse Razer DeathAdder   Sound Razer Kraken Pro   OS Windows 10 Professional

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, RSmeets said:

the os is fine the only thing is those encrypted files. so i need to decrypt them that's it

I wish you luck in your attempts. My attempts have all failed in the past. Perhaps you will do better.

The only thing we have to fear is... Stupidity...

Link to comment
Share on other sites

Link to post
Share on other sites

  • 1 month later...

I had problems with Locky virus and free ShadowExplorer tool helped me to restore 50% of encrypted files from shadow copies!

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×