0

My Windows 10 Surface Laptop 1 i7 has been affected by a ransomware that says it has encrypted my hard drive. Here is what the README says:

---=== Welcome. Again. ===---



[+] Whats Happen? [+]



Your files are encrypted, and currently unavailable. You can check it: all files on you computer has expansion lktja99122.

By the way, everything is possible to recover (restore), but you need to follow our instructions. Otherwise, you cant return your data (NEVER).



[+] What guarantees? [+]



Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will not cooperate with us. Its not in our interests.

To check the ability of returning files, You should go to our website. There you can decrypt one file for free. That is our guarantee.

If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause just we have the private key. In practise - time is much more valuable than money.



[+] How to get access on website? [+]



You have two ways:



1) [Recommended] Using a TOR browser!

  a) Download and install TOR browser from this site: https://torproject.org/

  b) Open our website: http://aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion/7D97B3B78C58FCA2



2) If TOR blocked in your country, try to use VPN! But you can use our secondary website. For this:

  a) Open your any browser (Chrome, Firefox, Opera, IE, Edge)

  b) Open our secondary website: http://decryptor.cc/7D97B3B78C58FCA2



Warning: secondary website can be blocked, thats why first variant much better and more available.



When you open our website, put the following data in the input form:

Key:

xF0MUmXzlKqebAAK/24bgM9Aal4Ik6rlqeClUW/p0yh/OCd5YAGMgHbiHuagEE12
GaY/M8GfIdimKGG9OZI9HrPO0A+LaOF7Ej3K+vJP5LKaKFmwzg2qwX9vIi1yvDsT
YZPvFzew9lWGhQ4x/zzj8k6zY21aMt77Bs8K1z3m6buBcHzmrPH84t9Xjdtl1TCX
Mx6KbR3ySi/1bbSywXoh8+R3wsAkQGfkFeHIjaD1FJt2fYm8iG7ErHFWFp2+MTcj
z7QgvJ5URjlhEwal5DBzUQlXKfWzEG/l3qmH1Vhnf7Y67xqwor9jdExgiax3q+Yu
XtzMQyMrTnQ2Kq77IDoourWOtLpg6pX7qsI5G+danWHLQiBuVMYSKkTax6ADXSiY
kIGpKt2J/2dshSKyuNKtxb8pSJjs/3P96YuKtm4cGdpDlwpcYx/D7HMU5NQLoGJm
ULmwF5PEkW7S1m9VTryosciLdZJzstLwHXzKn0kUnnsFiPLimMRil+jsVQSspUUH
xLyy/F2n4AL9PKXpYHrnK7JVINo5p5A+E17+FzdhANZd6ukJLBEHMincOQCenY66
oe9YPX+fJ4gbIXTRZK/35xVOhfgqlRJ78bmdIwWuWJ3D0xtc7bkClwudFALJ9qOp
7tQn6Og/AJPtznt9/E9iUyNILmk/Yh3w+/s7afYSLXZTJ/nNrXQzDGrpVORHpxeE
C/d5tgIiV8KjMIupuxTZu+PTaLK+lzI8URbDHSg08Zs435Dr/hvfj4zr03PJqM+z
LbEvfqEtw2OeGZMtYPnH5LWlEwTmmWPsC9BjrLwRXFLIEKGPZzyUvKjHNjg+0aFG
YxvoO3YxZZZYCIoh41awPIkxrBR0nnXmDT2WLiE8FUIdFNvqZjx67k8eRXcwdfyg
9iKwufhmh6uaKIj3297Fmvn2xDEN/9FX/CWL5ql3gwevcRnrwsum7WcLe1bzU2YK
MGM49eodvZYWvJ8TWQNVi6l+dpwShSObOD0Gwpf69aKtjgIyPdNqRvyU32P1MYnG
XFqkDT+ZFMlSKv3wDISbqaUhle0FtOZKMO1HRmIP4U19nI2/sD/IM2sULIbR1T4M
+RzhcMM918cscbo+6NzINsCkNmisB8VDP5mEW1XtYyXR4P84hc8ZzvUMhmWaBGor
T9dQ9NW/0E636rgyMmnn8tgfiSqvPh685T1wHlY2mqpzgsXZ1r/XQ68UOgdjstxa
u1J0K7gEwA1hwxlsUcsateFCR0XFqsli3B29ADuxdUMpe8t/or3aodtRal+PtWnU
rsiSNdwh+ZRsv87tJLGc9mOWBs/5A34Ft4O5grCk/pH1mSgkx80sH6KqDjg=







Extension name:



lktja99122



-----------------------------------------------------------------------------------------



!!! DANGER !!!

DONT try to change files by yourself, DONT use any third party software for restoring your data or antivirus solutions - its may entail damge of the private key and, as result, The Loss all data.

!!! !!! !!!

ONE MORE TIME: Its in your interests to get your files back. From our side, we (the best specialists) make everything for restoring, but please should not interfere.

!!! !!! !!!

So, how can I restore my data (without paying)?

schroeder
  • 125,553
  • 55
  • 289
  • 326
tommyaq
  • 1
  • 1
  • Unfortunately, we are not a malware/ransomware removal site. The duplicate provides tips on what to do next. – schroeder Apr 28 '20 at 13:00
  • Looks like you have: REvil / Sodinokibi There is currently no tool to decrypt. At least that's what https://id-ransomware.malwarehunterteam.com/ has to say. – HelpingHand Apr 29 '20 at 21:00

0 Answers0