MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 20 posts ] 
Author Message
 Post subject: About this crypto virus locky
PostPosted: March 14th, 2016, 8:53 
Offline

Joined: December 16th, 2015, 12:37
Posts: 99
Location: GCC
Hi ,

Goodday my friends ..
i have nas storage inf acted with Virus locky .. have u face this virus before .. there is any solution ?

thanks for help


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: March 14th, 2016, 9:32 
Offline

Joined: January 31st, 2014, 8:46
Posts: 242
Location: India
http://howtoremove.guide/locky-virus-fi ... n-removal/


READ THIS TOPIC


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: March 14th, 2016, 10:01 
Offline

Joined: December 16th, 2015, 12:37
Posts: 99
Location: GCC
Thanks Galaxy for ur help ..

but it's not a computer .. it's Nas storage ..
i will read and see ..

thanks


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: March 14th, 2016, 10:38 
Offline
User avatar

Joined: December 8th, 2013, 4:48
Posts: 838
Location: Pakistan
read here.
http://www.kmitldss.org/kmitldss/articles/fde_p3.pdf

_________________
Data Recovery Pakistan


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: March 22nd, 2016, 1:23 
Offline

Joined: March 7th, 2009, 12:43
Posts: 1091
Location: Angel Data Recovery
galaxy wrote:
http://howtoremove.guide/locky-virus-file-encryption-removal/


READ THIS TOPIC


This artical advertising RECUVA software to buy it. It doesn't help to decrypt affected files. It helps only to restore some deleted files which wasn't encrypted, this can do any other data recovery software, and IMHO RECUVA is not the best one

_________________
Angel Data Recovery


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 5th, 2016, 11:21 
Offline

Joined: May 5th, 2016, 11:05
Posts: 5
Location: Bulgaria
Hello, me and my brother got hit by Locky, a few days ago. We had many files on a NAS too. We called an IT expert and he was able to find out how it entered our PC. He asked us if we have a backup but we said no, as our NAS was infected as well. He left a note in English about it, that we thought to share:

"TROJ_LOCKY.DLDRA is the name of the trojan. Downloaded through svchost.exe. Locky Ransomware new version was installed. Files encrypted with .locky extension."

Now that we know about this ransomware, we are trying to find if we can restore our files. Recuva software did not work. :( We are searching the internet for information about the file restoration. Any help will be valued.


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 6th, 2016, 3:28 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3547
Location: Greece
There is absolutely no way to decrypt locky. Yet.

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 8th, 2016, 3:58 
Offline

Joined: March 11th, 2008, 4:35
Posts: 1052
Location: Bangladesh
northwind wrote:
There is absolutely no way to decrypt locky. Yet.


Agree

_________________
__________
There is no substitute for education and experience
THANK YOU
SHAHI
shahi.mahbub@gmail.com


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 9th, 2016, 5:56 
Offline

Joined: December 6th, 2012, 8:49
Posts: 291
Location: españa
The encrypted file name is changed to random characters or just add .locky ???


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 9th, 2016, 6:00 
Offline

Joined: May 5th, 2016, 11:05
Posts: 5
Location: Bulgaria
So, we have found the following article where some methods for restoring files from Locky were mentioned at the end.

http://sensorstechforum.com/remove-lock ... ted-files/

Stellar Phoenix Data Recovery mentioned there, worked! It only restored a few pictures and documents, but it is something!

http://www.stellarinfo.com/

@northwind and @shahij - we also didn't find any working decryption method, but with some Data Recovery software it appears you can restore a tiny portion of files...


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 9th, 2016, 8:44 
Offline

Joined: December 6th, 2012, 8:49
Posts: 291
Location: españa
if encrypted files keep the original name , not the locky authentic and whether they can be decrypted .
if the name is changed to random characters , can not be decrypted


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 10th, 2016, 4:05 
Offline

Joined: May 5th, 2016, 11:05
Posts: 5
Location: Bulgaria
@colanco, the extension is .locky of every file, but they are all locked. Me and my brother couldn't find any decryption method (at least for now - we'll continue looking).

Apparently the ransomware deletes original files and locks their copies, so that's how a Data recovery program can recover some files. I wonder why the effect was so little if all files got deleted. Maybe it doesn't delete all files but uses a random principle?


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 10th, 2016, 15:24 
Offline

Joined: December 6th, 2012, 8:49
Posts: 291
Location: españa
The extension is .locky, ok, but the file name is the original or changed by random characters ????


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 11th, 2016, 8:22 
Offline

Joined: May 5th, 2016, 11:05
Posts: 5
Location: Bulgaria
colanco wrote:
The extension is .locky, ok, but the file name is the original or changed by random characters ????


The file names are the same as before. Only the extensions are changed (like .doc is now .doc.locky).

EDIT: We have tried reverting the names back by deleting the locky extension and also trying burning the files to DVDs if we can change them somehow but that doesn't work...


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 11th, 2016, 10:20 
Offline

Joined: March 19th, 2015, 15:01
Posts: 1388
Location: isreal
after_dark wrote:
but that doesn't work...

Of course not, the files are encrypted


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 11th, 2016, 14:55 
Offline

Joined: December 6th, 2012, 8:49
Posts: 291
Location: españa
is AutoLocky , can be decrypt.

Quote:
AutoLocky is a new ransomware written in the popular scripting language AutoIt. It tries to imitate the complex and sophisticated Locky ransomware, but is nowhere near as complex and sophisticated, which makes decryption feasible.

Victims of AutoLocky will find their files encrypted and renamed to *.locky. Unlike the real Locky ransomware however, AutoLocky will not change the base name of the file. So if a file named picture.jpg is encrypted, AutoLocky will rename it to picture.jpg.locky while the actual Locky ransomware will change it to a random name.


PM sent.


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: May 12th, 2016, 11:47 
Offline

Joined: May 5th, 2016, 11:05
Posts: 5
Location: Bulgaria
@jermy - now we know.

@colanco - THANK YOU! It worked and all files seem to be restored - some files on the NAS are still encrypted, but they might be corrupt and they are not too important. We will try to copy them and decrypt on a PC...


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: June 15th, 2016, 5:03 
Offline

Joined: December 31st, 2010, 8:51
Posts: 23
Location: India
I HAVE PROBLEM OF CRYPZ EXTENSION AFTER THE ORIGINAL FILE NAME. PLEASE SUGGEST HOW TO DECRYPT THE FILES.

THANKS


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: June 16th, 2016, 6:09 
Offline

Joined: September 1st, 2012, 6:16
Posts: 198
Location: Universe
Hi
From Where in India. We can recover partial data. PM your details.


Top
 Profile  
 
 Post subject: Re: About this crypto virus locky
PostPosted: June 16th, 2016, 8:45 
Offline

Joined: December 6th, 2012, 8:49
Posts: 291
Location: españa
It is CryptXXX 3.x.

There are several partial methods, with different result, but not a complete solution at this time


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 20 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 67 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group