Author Topic: llmxpyc -- ransomware effects  (Read 2208 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
llmxpyc -- ransomware effects
« on: June 08, 2015, 06:10:50 PM »
Greetings !!

I have a customer with all the files (xls/pdf/doc/etc...) crypted by a ransomware that changed the extensions to llmxpyc.

Anyone have an idea from which malware this come from ?

The crypted datas may be cracked if I knew the algorithm family it is declined from.



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: llmxpyc -- ransomware effects
« Reply #1 on: June 08, 2015, 06:28:22 PM »
i think newer ransomware versions encrypt with randome file extension

Essexboy may have some info when online



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: llmxpyc -- ransomware effects
« Reply #3 on: June 08, 2015, 07:03:41 PM »
It is mainly spread through the web by showing the user something like "It is recommended to update your video player".

Here are three decryption tools you could try:
https://noransom.kaspersky.com/
http://blogs.cisco.com/security/talos/teslacrypt
http://tinyurl.com/oxtlmvv

REDACTED

  • Guest
Re: llmxpyc -- ransomware effects
« Reply #4 on: June 09, 2015, 11:14:50 PM »
thx, I will try something...


REDACTED

  • Guest
Re: llmxpyc -- ransomware effects
« Reply #5 on: June 16, 2015, 06:40:29 PM »
Still not have news about SERIOUS unlocker... it's a shame that some idiots are refering to things like Stellar ... WDR or SpyHUNTER to DECRYPT llmxpyc crypted files...

I got two key.dat files... if I could help people who try to fight this crypting algo... lemme know.





 

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: llmxpyc -- ransomware effects
« Reply #6 on: June 16, 2015, 07:04:05 PM »
Only/best thing you can do is send all info you have to companies like avast, Kaspersky, Avira and such as well as sending it to cybercrime devisions of police worldwide.

Here is the contact form for Interpol:
http://www.interpol.int/Forms/Contact_INTERPOL