Switch to full style
Data recovery and disk repair questions and discussions related to old-fashioned SATA, SAS, SCSI, IDE, MFM hard drives - any type of storage device that has moving parts
Post a reply

About this crypto virus locky

March 14th, 2016, 8:53

Hi ,

Goodday my friends ..
i have nas storage inf acted with Virus locky .. have u face this virus before .. there is any solution ?

thanks for help

Re: About this crypto virus locky

March 14th, 2016, 9:32

http://howtoremove.guide/locky-virus-fi ... n-removal/


READ THIS TOPIC

Re: About this crypto virus locky

March 14th, 2016, 10:01

Thanks Galaxy for ur help ..

but it's not a computer .. it's Nas storage ..
i will read and see ..

thanks

Re: About this crypto virus locky

March 14th, 2016, 10:38

read here.
http://www.kmitldss.org/kmitldss/articles/fde_p3.pdf

Re: About this crypto virus locky

March 22nd, 2016, 1:23

galaxy wrote:http://howtoremove.guide/locky-virus-file-encryption-removal/


READ THIS TOPIC


This artical advertising RECUVA software to buy it. It doesn't help to decrypt affected files. It helps only to restore some deleted files which wasn't encrypted, this can do any other data recovery software, and IMHO RECUVA is not the best one

Re: About this crypto virus locky

May 5th, 2016, 11:21

Hello, me and my brother got hit by Locky, a few days ago. We had many files on a NAS too. We called an IT expert and he was able to find out how it entered our PC. He asked us if we have a backup but we said no, as our NAS was infected as well. He left a note in English about it, that we thought to share:

"TROJ_LOCKY.DLDRA is the name of the trojan. Downloaded through svchost.exe. Locky Ransomware new version was installed. Files encrypted with .locky extension."

Now that we know about this ransomware, we are trying to find if we can restore our files. Recuva software did not work. :( We are searching the internet for information about the file restoration. Any help will be valued.

Re: About this crypto virus locky

May 6th, 2016, 3:28

There is absolutely no way to decrypt locky. Yet.

Re: About this crypto virus locky

May 8th, 2016, 3:58

northwind wrote:There is absolutely no way to decrypt locky. Yet.


Agree

Re: About this crypto virus locky

May 9th, 2016, 5:56

The encrypted file name is changed to random characters or just add .locky ???

Re: About this crypto virus locky

May 9th, 2016, 6:00

So, we have found the following article where some methods for restoring files from Locky were mentioned at the end.

http://sensorstechforum.com/remove-lock ... ted-files/

Stellar Phoenix Data Recovery mentioned there, worked! It only restored a few pictures and documents, but it is something!

http://www.stellarinfo.com/

@northwind and @shahij - we also didn't find any working decryption method, but with some Data Recovery software it appears you can restore a tiny portion of files...

Re: About this crypto virus locky

May 9th, 2016, 8:44

if encrypted files keep the original name , not the locky authentic and whether they can be decrypted .
if the name is changed to random characters , can not be decrypted

Re: About this crypto virus locky

May 10th, 2016, 4:05

@colanco, the extension is .locky of every file, but they are all locked. Me and my brother couldn't find any decryption method (at least for now - we'll continue looking).

Apparently the ransomware deletes original files and locks their copies, so that's how a Data recovery program can recover some files. I wonder why the effect was so little if all files got deleted. Maybe it doesn't delete all files but uses a random principle?

Re: About this crypto virus locky

May 10th, 2016, 15:24

The extension is .locky, ok, but the file name is the original or changed by random characters ????

Re: About this crypto virus locky

May 11th, 2016, 8:22

colanco wrote:The extension is .locky, ok, but the file name is the original or changed by random characters ????


The file names are the same as before. Only the extensions are changed (like .doc is now .doc.locky).

EDIT: We have tried reverting the names back by deleting the locky extension and also trying burning the files to DVDs if we can change them somehow but that doesn't work...

Re: About this crypto virus locky

May 11th, 2016, 10:20

after_dark wrote:but that doesn't work...

Of course not, the files are encrypted

Re: About this crypto virus locky

May 11th, 2016, 14:55

is AutoLocky , can be decrypt.

AutoLocky is a new ransomware written in the popular scripting language AutoIt. It tries to imitate the complex and sophisticated Locky ransomware, but is nowhere near as complex and sophisticated, which makes decryption feasible.

Victims of AutoLocky will find their files encrypted and renamed to *.locky. Unlike the real Locky ransomware however, AutoLocky will not change the base name of the file. So if a file named picture.jpg is encrypted, AutoLocky will rename it to picture.jpg.locky while the actual Locky ransomware will change it to a random name.


PM sent.

Re: About this crypto virus locky

May 12th, 2016, 11:47

@jermy - now we know.

@colanco - THANK YOU! It worked and all files seem to be restored - some files on the NAS are still encrypted, but they might be corrupt and they are not too important. We will try to copy them and decrypt on a PC...

Re: About this crypto virus locky

June 15th, 2016, 5:03

I HAVE PROBLEM OF CRYPZ EXTENSION AFTER THE ORIGINAL FILE NAME. PLEASE SUGGEST HOW TO DECRYPT THE FILES.

THANKS

Re: About this crypto virus locky

June 16th, 2016, 6:09

Hi
From Where in India. We can recover partial data. PM your details.

Re: About this crypto virus locky

June 16th, 2016, 8:45

It is CryptXXX 3.x.

There are several partial methods, with different result, but not a complete solution at this time
Post a reply