Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Anyways around to decrypt TorrentLocker encrypted files?


  • This topic is locked This topic is locked
1 reply to this topic

#1 ylms

ylms

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:11:45 AM

Posted 17 March 2016 - 11:54 AM

Hello everyone,

So today in my university some of the computers got crypto locked. After some of my researches I have figured out it is called TorrentLocker.

 

So far I have found this topic on the forum. However even though I decrypted file successfully it was still unavailable to open. So I am assuming I have been hit by the never version of TorrentLocker.

http://www.bleepingcomputer.com/forums/t/547708/torrentlocker-ransomware-cracked-and-decrypter-has-been-made/

 

Also I have tried RannohDecryptor  Kaspersky, and it kept saying the encrypted file and the original file is not same size, so it wasn't available to decrypt my files.

 

To sum up, we have lost many important files due this. And I am wondering if there is any work around at the moment. 

I'd be glad if you guys could update me and help me to decrypt my files.

 

Edit: Forgot to mention, the encrypted files has .encrypted suffix.

 

Thank you for your time.


Edited by ylms, 17 March 2016 - 12:07 PM.


BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,467 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:05:45 AM

Posted 17 March 2016 - 03:36 PM

Any files that are encrypted with TorrentLocker (Crypt0L0cker) will have the .encrypted extension appended to the end of the affected filename. When the encryption process is done, all of your computer drive letters will display a window that contains the ransom note and instructions on how to get your files back. TorrentLocker leaves files (ransom notes) named DECRYPT_INSTRUCTIONS.HTML. Crypt0L0cker is a newer version of TorrentLocker.

A repository of all current knowledge regarding TorrentLocker is provided by Grinler (aka Lawrence Abrams), in this topic: TorrentLocker (fake CryptoLocker) Ransomware Information Guide and FAQ

Unfortunately, decryption of TorrentLocker (Crypt0L0cker)...is impossible since there is no way to retrieve the private key that can be used to decrypt your files without paying the ransom. The only methods you have of restoring your files is from backup, file recovery software, or from Shadow Volume Copies as explained in the FAQ: How to restore files encrypted by TorrentLocker...but there is no guarantee that will work.

However, you may want to read this BC News article: Dr.Web quietly decrypting TorrentLocker for paid customers or distributors.
Updated policy from Dr.Web (11/25/15): Free file decryption assistance only for PCs protected by Dr.Web at the moment of infectionAs with most ransomware infections...the best solution for dealing with encrypted data is to restore from backups. If that is not a viable option, the only other alternative is to save your data as is and wait for a possible breakthrough...meaning, what seems like an impossibility at the moment (decryption of your data), there is always hope someday there may be a potential solution so save the encrypted data and wait until that time.

There are ongoing discussions in these topics where you can ask questions and seek further assistance.Rather than have everyone start individual topics, it would be best (and more manageable for staff) if you posted any questions, comments or requests for assistance in that support topic discussion. Doing that will also ensure you receive proper assistance from our crypto malware experts since they may not see this thread. To avoid unnecessary confusion...this topic is closed.

Thanks
The BC Staff
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users