Jump to content

RSA-2048 still on my computer


Recommended Posts

Looks like you've been infected with the Osiris variant of Locky then. Sadly, there's no way to decrypt the files encrypted with this variant for free. The best you can do is to back them up and wait for a solution to be found in the future.

https://www.bleepingcomputer.com/news/security/locky-ransomware-switches-to-egyptian-mythology-with-the-osiris-extension/

Link to post
Share on other sites

If you're talking about getting rid of the ransom notes, you can do so easily using RansomNoteCleaner.

https://www.bleepingcomputer.com/forums/t/617257/ransomnotecleaner-remove-ransom-notes-left-behind/

If you're talking about decrypting your encrypted files for free, if a solution is ever found and I remember this thread, I can post in it. Otherwise, you would have to follow the development of the Locky ransomware and its variants.

Link to post
Share on other sites

Files that have the .osiris extension are files that got encrypted by Locky, they aren't ransom notes. I think the ransom notes are now named like this:

Quote

DesktopOSIRIS.bmp, DesktopOSIRIS.htm, OSIRIS-[4_numbers].htm, and OSIRIS-[4_numbers].htm.

https://www.bleepingcomputer.com/news/security/locky-ransomware-switches-to-egyptian-mythology-with-the-osiris-extension/

Link to post
Share on other sites

The only way to "fix" this is for someone to release a decrypter for files encrypted with the Osiris variant of Locky. Unfortunately, I doubt Malwarebytes is working on one, since no Locky variants have been broke to my knowledge. You can be sure that there's other security vendors working on a decrypter, but without the keys and/or a flaw in the encryption process, a decrypter cannot be made.

And do you know how you were infected exactly? Via a program you installed, a file you downloaded from the web, an Excel attachment you opened in an email and enabled the macro? The latter is how the Osiris variant of Locky spreads.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.