You're welcome.
Posted 02 September 2022 - 02:24 PM
You're welcome.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 28 November 2022 - 10:24 AM
I'm confused I wasn't asking for a way to decrypt the data nor if I was affect by loki or not. I was asking how to use file recovery that is recommended on the post template from posts like these and my topic was closed. Also, I found it odd it didn't lock every file and folder of my drive. My question is how do I use file recover to recover the videos and possible the locked cbr/cbz comics.?
What I meant is do I delete windows clean install ( I don't care about the c drive there is nothing there I cannot restore even the plex metadata)? Download recuva and work on the loki locked externals? Also, why isn't every file and folder locked? Do these drives still have malware? I'm confused about loki and that was what my topic was about. I'm currently using linux and a mac to view these drives.
Edited by mikozee, 28 November 2022 - 10:39 AM.
Posted 28 November 2022 - 03:18 PM
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 28 November 2022 - 05:09 PM
I just realized something. If two identical disks as identified by win merge were hit by loki, will Winmerge still identify them as identical despite being encrypted post ransomware? This is what happened to me as 2 out of 4 different disks were online while 2 out of 4 with some obsolete content were offline. My set up works in pairs and I forgot to take at least one of it offline before the event. So I'm missing about a weeks worth of content I can't identify.But my backups are not that old so it's not a huge issue.
Posted 24 March 2023 - 12:44 AM
DO NOT PAY LOKI LOCKER
Lokisupp0rt@yandex.com, lokiloki@mailfence.com
Hello All,
I am one of the victims of LokiLoker, they are scammers. These guys locked my files lokiloki@mailfence.com, and the ransom note had these 2 email ID's Lokisupp0rt@yandex.com, lokiloki@mailfence.com. We paid them twice as they did not send the decrypter after receiving the first payment and we had to make another payment to get the decrypter. After receiving both the payments these guys sent a decrypter but the decrypter which they sent did not work my files.And the worst part is they are asking access to my machine to decrypt the files saying the problem is with my computer when i had clearly explained to them that i had tried to decrypt the files on a clean computer.
Posted 24 March 2023 - 04:43 AM
I have merged your topic into the primary support topic for victims of this ransomware.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 18 July 2023 - 05:52 AM
Hello Community,
Please I need help to recover the files encrypted by killer ransomware. all files are crypted and have the .kill extension
I attach an encrypted file and also the file with instructions done by the hackers
I did lot of research for a decryptor but this ransomware is not recongnized by decryptors
Best Regards
Posted 18 July 2023 - 07:27 AM
The contents of your ransom note are similar to what we have seen with some variants of Loki Locker Ransomware.
Your #FILES-ENCRYPTED.txt
!!!All of your files are encrypted!!!To decrypt them send e-mail to this address: Decryption.helper@aol.comIn case of no answer in 24h, send e-mail to this address: helper@cyberfear.comYour System ID : 689DBE54!!!Deleting "xor.689DBE54.kill" causes permanent data loss.....
+Ways to contact us:Our Email:Decryption.helper@aol.comhelper@cyberfear.comYour System ID: 689DBE54
Loki Locker (BlackBit) - Restore-My-Files.txt
!!!All of your files are encrypted!!!To decrypt them send e-mail to this address: spystar@onionmail.orgIn case of no answer in 24h, send e-mail to this address: spystar1@onionmail.comYou can also contact us via Telegram: @Spystar_SupportAll your files will be lost on Thursday, October 20, 2022 9:51:06 AM.Your SYSTEM ID : 8E4A8CF5!!!Deleting "Cpriv.BlackBit" causes permanent data loss.
Loki Locker - Restore-My-Files.txt
!!!All of your files are encrypted!!!To decrypt them send e-mail to this address: Lollooki@protonmail.comIn case of no answer in 24h, send e-mail to this address: Lollooki@yandex.comAll your files will be lost on Wednesday, 28 December 2022 4:30:12 am.Your SYSTEM ID: 52294877!!!Deleting "Cpriv.Loki" causes permanent data loss.
Is .kill the full extension appended to the end of the encrypted data filename or is there an .[email], an ID number with random characters (.id-A04EBFC2, .id[4D21EF37-2214]), an ID number with an email address (.id-BCBEF350.[<email>], .id[7A9B748C-1104].[<email>]), an ID number with a person's name (.[a7fth62bc1].[<name>]) or just a series of random characters (.8SLV8GMp-hjqo9v3s) preceding the extension?
Any files that are encrypted with Loki Locker Ransomware will have an [<email>][<ID 8 random characters>]<filename>.[extension] followed by the .Loki, .BlackBit, .Rainman, .PayForKey, .Adair, .Boresh, .onion700, .DATA extension appended to the end of the encrypted data filename and typically will leave files (ransom notes) named Restore-My-Files.txt, info.hta as explained here by Amigo-A (Andrew Ivanov). These are some examples.
.[lolooki@protnmail.com][7E09E942]<filename>.mp4.Loki
.[DecNow@TutaMail.Com][7E09E942]<filename>.pdf.Loki
.[spystar@onionmail.org][9ECFA84E]<filename>.jpg.BlackBit
.[Onion749@onionmail.org][52294877]<filename>.log.onion700.[crypter@firemail.de][43DE62EH]<filename>.jpg.kill
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 18 July 2023 - 09:45 AM
The contents of your ransom note are similar to what we have seen with some variants of Loki Locker Ransomware.
Your #FILES-ENCRYPTED.txt
!!!All of your files are encrypted!!!To decrypt them send e-mail to this address: Decryption.helper@aol.comIn case of no answer in 24h, send e-mail to this address: helper@cyberfear.comYour System ID : 689DBE54!!!Deleting "xor.689DBE54.kill" causes permanent data loss.....
+Ways to contact us:Our Email:Decryption.helper@aol.comhelper@cyberfear.comYour System ID: 689DBE54Loki Locker (BlackBit) - Restore-My-Files.txt
!!!All of your files are encrypted!!!To decrypt them send e-mail to this address: spystar@onionmail.orgIn case of no answer in 24h, send e-mail to this address: spystar1@onionmail.comYou can also contact us via Telegram: @Spystar_SupportAll your files will be lost on Thursday, October 20, 2022 9:51:06 AM.Your SYSTEM ID : 8E4A8CF5!!!Deleting "Cpriv.BlackBit" causes permanent data loss.
Loki Locker - Restore-My-Files.txt
!!!All of your files are encrypted!!!To decrypt them send e-mail to this address: Lollooki@protonmail.comIn case of no answer in 24h, send e-mail to this address: Lollooki@yandex.comAll your files will be lost on Wednesday, 28 December 2022 4:30:12 am.Your SYSTEM ID: 52294877!!!Deleting "Cpriv.Loki" causes permanent data loss.
Is .kill the full extension appended to the end of the encrypted data filename or is there an .[email], an ID number with random characters (.id-A04EBFC2, .id[4D21EF37-2214]), an ID number with an email address (.id-BCBEF350.[<email>], .id[7A9B748C-1104].[<email>]), an ID number with a person's name (.[a7fth62bc1].[<name>]) or just a series of random characters (.8SLV8GMp-hjqo9v3s) preceding the extension?
Any files that are encrypted with Loki Locker Ransomware will have an [<email>][<ID 8 random characters>]<filename>.[extension] followed by the .Loki, .BlackBit, .Rainman, .PayForKey, .Adair, .Boresh, .onion700, .DATA extension appended to the end of the encrypted data filename and typically will leave files (ransom notes) named Restore-My-Files.txt, info.hta as explained here by Amigo-A (Andrew Ivanov). These are some examples..[lolooki@protnmail.com][7E09E942]<filename>.mp4.Loki
.[DecNow@TutaMail.Com][7E09E942]<filename>.pdf.Loki
.[spystar@onionmail.org][9ECFA84E]<filename>.jpg.BlackBit
.[Onion749@onionmail.org][52294877]<filename>.log.onion700.[crypter@firemail.de][43DE62EH]<filename>.jpg.kill
Thanks for replying
The files are encrypted and the their names are changed as you said [Decryption.helper@aol.com][689DBE54].filename.kill
is there any way to decrypt them
Posted 18 July 2023 - 09:46 AM
Can I add two more files? one encrypted file and "xor.689DBE54.kill" into an archive, upload the archive to sendspace.com, and give us the archive download link in your message.
Posted 18 July 2023 - 10:32 AM
Can I add two more files? one encrypted file and "xor.689DBE54.kill" into an archive, upload the archive to sendspace.com, and give us the archive download link in your message.
Done
I've sent you the link
Posted 18 July 2023 - 10:39 AM
Agree with Global Moderator quietman7
With a high probability this is a variant of Loki Locker.
Check in the antivirus quarantine there should be a file called winlogon.exe.
This will be the body of the ransomware.
Posted 18 July 2023 - 03:49 PM
@Fighter84
Since the infection has been identified/confirmed and this is a new variant, I merged your topic into the primary support topic for victims of this ransomware.
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
Posted 02 August 2023 - 08:23 AM
I have recovered a huge part of my encrypted files.
So if someone has the same issue I can try to help, contact me with direct message
Posted 02 August 2023 - 08:27 AM
If you are able to assist other victims, then do so in this support topic.
By Bleeping Computer policy (Forum Rules), all help must be provided in the forums...specifically this part.
All help must be provided in the forums or on our Discord Server. We do not allow support to be provided or requested via personal message, email, or remote desktop control programs (Logmein, TeamViewer, etc).
Thanks,
The BC Staff
.
.
Microsoft MVP Alumni 2023, Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023
Microsoft MVP Consumer Security 2007-2015
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief
If I have been helpful & you'd like to consider a donation, click
0 members, 1 guests, 0 anonymous users