Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

TorrentLocker Ransomware Cracked and Decrypter has been made


  • Please log in to reply
359 replies to this topic

#346 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:20 AM

Posted 14 May 2016 - 08:20 PM

You're welcome and good luck.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


BC AdBot (Login to Remove)

 


#347 Wallak

Wallak

  •  Avatar image
  • Members
  • 45 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Zaragoza, Spain
  • Local time:02:20 PM

Posted 15 May 2016 - 02:41 PM

Independent requests (not customers) to Dr.Web, takes long time, it seems it depends on their mood. They check email and domain, if you repeat (for example for business for your own customers, they will delay or simply won't answer). I received support from them normally on Sundays after changing three times of email... first, waiting 2 weeks and nothing, second 4 days and nothing, third, 2 hours and was acknowledged, and 2 hours more and solved, so ... good luck and ... if you don't see "acknowledged" on your status ticket, start to insist or call.

 

Now distributors / partners are the ones who receive the %, they directly solve some few cases. In that case, you can check if you have some partner/distributor in your area, check it here https://partners.drweb-av.es/distributors/find/

 

Best regards. Business must go on (or ... it was ... show must go on???)


Wallak (aka Alik)

Я меня зовут Алик

IT Specialist, Zaragoza, Spain

 

WEB

 


#348 adirem

adirem

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 20 May 2016 - 04:24 AM

Four your information. I hope this notice helps anyone.

 

Regards!

 

http://www.eset.com/us/resources/detail/eset-releases-decryptor-for-recent-variants-of-teslacrypt-ransomware/



#349 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:20 AM

Posted 20 May 2016 - 06:43 AM

TeslaCrypt is a different ransomware infection not related to TorrentLocker.

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#350 Wallak

Wallak

  •  Avatar image
  • Members
  • 45 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Zaragoza, Spain
  • Local time:02:20 PM

Posted 30 May 2016 - 05:02 PM

Cryptolocker never stops ... In Spain, a new way of distribution has been found, after a long time (more than a year) abusing of Correos (Spanish Post) false letter, now they have chosen Endesa (Spanish Electric Power company) false invoice (with high price cost to impress the user). They could follow the same path as Tesla developers and disappear from the net forever and stop boring people with this. Anyone interested on the JavaScript can PM me, it is interesting they new way to contact to C&C and build the EXE to start it from that first JS.

 

Best regards.


Wallak (aka Alik)

Я меня зовут Алик

IT Specialist, Zaragoza, Spain

 

WEB

 


#351 Amigo-A

Amigo-A

    Security specialist and Ransomware expert


  •  Avatar image
  • Members
  • 3,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bering Strait
  • Local time:06:20 PM

Posted 31 May 2016 - 12:33 PM

A new TorrentLocker campaign has been detected by Heimdal Security that is geographically focused on Sweden.
The email carries a single link to a web page that looks like a Telia landing page. This page contains a poisoned Captcha code, which, if activated, downloads the TorrentLocker ransomware - provided that the target's IP address is in Sweden. If the address is not in Sweden, the target is simply redirected to Google.

My site: The Digest "Crypto-Ransomware"  + Google Translate 

 


#352 pr3t0ryan

pr3t0ryan

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 07 June 2016 - 12:12 PM

Some help please? I'we just got bleeped by the torrentlocker

 

https://www.dropbox.com/sh/2qk7a52ork2xhmj/AADthbLSM1WVclsvli2wH5H8a?dl=0

 

how can i decript the files?

 

thanx



#353 Wallak

Wallak

  •  Avatar image
  • Members
  • 45 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Zaragoza, Spain
  • Local time:02:20 PM

Posted 07 June 2016 - 02:48 PM

Have you been hit in Spain by that 'Endesa' false invoice???

 

In that case you have solution (again) via the Russian antivirus company (I confirm you that they can solve it)

 

Read past posts on this same thread and you will be able to solve your problem (not for free, you must know it)

 

Anyway, all these Cryptolocker (torrentlocker) releases have a high probability to be solved by that company, someday I hope the 'secret' will be not a secret and stop with the mafia.

 

Best regards.

 

 

Some help please? I'we just got bleeped by the torrentlocker

 

https://www.dropbox.com/sh/2qk7a52ork2xhmj/AADthbLSM1WVclsvli2wH5H8a?dl=0

 

how can i decript the files?

 

thanx


Wallak (aka Alik)

Я меня зовут Алик

IT Specialist, Zaragoza, Spain

 

WEB

 


#354 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:20 AM

Posted 07 June 2016 - 04:18 PM

Unfortunately, decryption of TorrentLocker (Crypt0L0cker)...is not possible since there is no way to retrieve the private key that can be used to decrypt your files without paying the ransom. The only methods you have of restoring your files is from backup, file recovery software, or from Shadow Volume Copies as explained in the FAQ: How to restore files encrypted by TorrentLocker...but there is no guarantee that will work.

However, you may want to read this BC News article: Dr.Web quietly decrypting TorrentLocker for paid customers or distributors.
Updated policy from Dr.Web (11/25/15): Free file decryption assistance only for PCs protected by Dr.Web at the moment of infection

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif


#355 pr3t0ryan

pr3t0ryan

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 08 June 2016 - 06:07 AM

 

Have you been hit in Spain by that 'Endesa' false invoice???

 

In that case you have solution (again) via the Russian antivirus company (I confirm you that they can solve it)

 

Read past posts on this same thread and you will be able to solve your problem (not for free, you must know it)

 

Anyway, all these Cryptolocker (torrentlocker) releases have a high probability to be solved by that company, someday I hope the 'secret' will be not a secret and stop with the mafia.

 

Best regards.

 

 

Some help please? I'we just got bleeped by the torrentlocker

 

https://www.dropbox.com/sh/2qk7a52ork2xhmj/AADthbLSM1WVclsvli2wH5H8a?dl=0

 

how can i decript the files?

 

thanx

 

Yes... Endesa...

We are trying to restore our backup but we have some problems so i'm searching some alternative solution...

I don't find anyone there



#356 pr3t0ryan

pr3t0ryan

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 08 June 2016 - 06:08 AM

Unfortunately, decryption of TorrentLocker (Crypt0L0cker)...is not possible since there is no way to retrieve the private key that can be used to decrypt your files without paying the ransom. The only methods you have of restoring your files is from backup, file recovery software, or from Shadow Volume Copies as explained in the FAQ: How to restore files encrypted by TorrentLocker...but there is no guarantee that will work.

However, you may want to read this BC News article: Dr.Web quietly decrypting TorrentLocker for paid customers or distributors.
Updated policy from Dr.Web (11/25/15): Free file decryption assistance only for PCs protected by Dr.Web at the moment of infection

 

the kaspersky's software can't uncrypt the files... the utility said the files are uncrypted but when i try to open it, the program can't do it: error message



#357 Wallak

Wallak

  •  Avatar image
  • Members
  • 45 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Zaragoza, Spain
  • Local time:02:20 PM

Posted 08 June 2016 - 06:20 AM

Let's see, people when come here for help must follow the advices shown and stop trying decrypters randomly.

First, Quietman said clearly that there is not a solution (free) for this kind of torrentlocker.

Second, I told you the way to solve your problem (Russian antivirus)

So, now you know what to do. There is a solution, so get it.

Here you have the way, in spanish, maybe will be easier for you.

https://www.aliksi.es/blog/?p=1577


the kaspersky's software can't uncrypt the files... the utility said the files are uncrypted but when i try to open it, the program can't do it: error message


Wallak (aka Alik)

Я меня зовут Алик

IT Specialist, Zaragoza, Spain

 

WEB

 


#358 pr3t0ryan

pr3t0ryan

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:03:20 PM

Posted 08 June 2016 - 08:54 AM

Let's see, people when come here for help must follow the advices shown and stop trying decrypters randomly.

First, Quietman said clearly that there is not a solution (free) for this kind of torrentlocker.

Second, I told you the way to solve your problem (Russian antivirus)

So, now you know what to do. There is a solution, so get it.

Here you have the way, in spanish, maybe will be easier for you.

https://www.aliksi.es/blog/?p=1577

 

the kaspersky's software can't uncrypt the files... the utility said the files are uncrypted but when i try to open it, the program can't do it: error message

 

thank you

 

Either way, i not make deals with the mafia.

 

Ciao



#359 vegi

vegi

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  

Posted 28 June 2016 - 12:07 AM

Hello DecrypterFixer, 

 

All my files ( PDF,DOCX,XLSX,JPG,TXT,ZIP)  on my Laptop   infected by virus please see the below attachment document , there are some important documents are  there to DECRYPT , 

 

Please help me , i used most of the Apps  which are available on the internet nothing working for me . Now how i can DECRYPT my files . 

 

 

All my files extension are *.CRYPTED.

 

I already submitted my file to the following link 

http://www.bleepingcomputer.com/submit-malware.php?channel=163

 

 

ATTENTION!

 
All your documents, photos, databases and other important personal files
were encrypted using strong RSA-1024 algorithm with a unique key.
To restore your files you have to pay 0.39572 BTC (bitcoins).
Please follow this manual:
 
1. Create Bitcoin wallet here:
 
 
2. Buy 0.39572 BTC with cash, using search here:
 
 
3. Send 0.39572 BTC to this Bitcoin address:
 
      12t6LNtbtPRyemkAhKLJtRLQjsW2pvZRPW
 
4. Open one of the following links in your browser to download decryptor:
 
 
5. Run decryptor to restore your files.
 
PLEASE REMEMBER:
 
      - If you do not pay in 3 days YOU LOOSE ALL YOUR FILES.
      - Nobody can help you except us.
      - It`s useless to reinstall Windows, update antivirus software, etc.
      - Your files can be decrypted only after you make payment.
      - You can find this manual on your desktop (DECRYPT.txt).


#360 quietman7

quietman7

    Bleepin' Gumshoe


  •  Avatar image
  • Global Moderator
  • 62,063 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:09:20 AM

Posted 28 June 2016 - 05:45 AM

...All my files extension are *.CRYPTED....You can find this manual on your desktop (DECRYPT.txt).

xXToffeeXx advised here that you are infected with Nemucod.

Any files that are encrypted with Nemucod Ransomware will have the .crypted extension appended to the end of the encrypted data filename and leave files (ransom notes) named DECRYPT.TXT. There is an ongoing discussion in this topic where you can ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.From the above topic...a decryptor solution is provided by Fabian Wosar in Post #69...

.
.
Microsoft MVP Alumni 2023Windows Insider MVP 2017-2020, MVP Reconnect 2016-2023

Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators
Retired Police Officer, Federal Agent and Coast Guard Chief

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users