Jump to content

Cant find dropper or txt for Locky Infection


Recommended Posts

Hi,

 

Ive tried your Decryptor for Autolocky and I get the error message

 

The decryptor could not determine a valid key from your system.

 

The OS is Windows 2008 Server but I dont believe the infections was launched from the server. Ive found a pc on the network which has also been infected and the user reported an odd attachment so Ive search that PC for the .txt file but I cannot find it anywhere? 

Do I need this txt file to decrypt the files back on the server or do you have another version of the decryptor which can be run on my server to decrypt the file?

 

I have shadow copy loaded and for now Im able to resurrect the files as and when users report them missing but I would like to just run the decryptor on the server just to reverse the effects of LOCKY

 

Thanks

DW

 

 

post-43295-0-85145800-1461917836_thumb.png

Link to post
Share on other sites

Hello,

If this is indeed the latest Locky variant, then decryption is not possible unfortunately. Can you please tell me what the name of the ransom note is (if you find one) and what the format is of affected files, so I can determine what ransomware variant you are dealing with?

Link to post
Share on other sites

Hi,

I can confirm the file extension is .locky. 

 

This is what I found

 

++$-_
            !!! IMPORTANT INFORMATION !!!!
 
All of your files are encrypted with RSA-2048 and AES-128 ciphers.
More information about the RSA and AES can be found here:
    
Decrypting of your files is only possible with the private key and decrypt program, which is on our secret server.
To receive your private key follow one of the links:
 
If all of this addresses are not available, follow these steps:
    1. Download and install Tor Browser: https://www.torproject.org/download/download-easy.html
    2. After a successful installation, run the browser and wait for initialization.
    3. Type in the address bar: 25z5g623wpqpdwis.onion/C4E805EA8E7C3DCC
    4. Follow the instructions on the site.
 
!!! Your personal identification ID: C4E805EA8E7C3DCC !!!
+~.$+.
._~*..*-|.=.||+$*.+$
+=-..$_+
*~*=.
Link to post
Share on other sites

In that case unfortunately decryption is not possible due to the way the files are encrypted and the complexity of the encryption algorithm. To restore your files you'd have to use a recent backup.

 

Please let me know if you have further questions about this.

Link to post
Share on other sites
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...