Home > Ransomware > Remove Lortok Ransomware and Freely Decrypt .Crime Encrypted Files

Remove Lortok Ransomware and Freely Decrypt .Crime Encrypted Files

password-brute-force-stforumRansomware, meant for Russian speaking users, named Lortok has been reported to encrypt the files on the devices it infects by using an AES-256 cipher. When the files are encrypted, they are modified, and the .crime file extension is added to them. In addition to that, Lortok ransomware adds a ransom note written entirely in Russian and in it, the crooks behind the virus demand only 5 dollars to decrypt the files. Either way, there is a decrypter released for Lortok ransomware, and we suggest to read this article on how to remove it and decrypt your files for free.

Threat Summary

Name Lortok
Type Ransomware
Short Description Uses a strong AES-256 cipher to encode user files. Demands 5 dollars as a ransom money.
Symptoms Files are encrypted and become inaccessible. A ransom note with instructions for paying the ransom shows as a .txt file.
Distribution Method Spam Emails, Email Attachments, File Sharing Networks.
Detection Tool See If Your System Has Been Affected by malware


Malware Removal Tool

User Experience Join our forum to Discuss Lortok Ransomware.
Data Recovery Tool Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Lortok Ransomware – Infection Mechanisms

In order to infect users successfully, Lortok may use a so-called process obfuscation mechanisms. They conceal the malicious file from any security software which may prevent the encryption process.

To spread its malicious .exe files successfully, Lortok may use spam bots to either send out spam messages or comment on different sites. The content may be malicious URLs or archives which contain the malicious executables. So far it is a mystery on what content has been used to deceive users, but it is strongly believed that the deception is more than one. For example, malicious URLs may be spread via recipients that resemble the following:

  • PayPal.
  • eBay.
  • Amazon.
  • BestBuy.
  • A reputable bank.

Lortok Ransomware Viewed In Detail

After successful infection the ransomware drops the two following files on the victim`s computer:

  • C:\Users\Administrator\AppData\Roaming\installdir\help.exe
  • C:\Users\Administrator\AppData\Roaming\update_{Ransom alpha-numerical code}.exe

N.B. The cyber-criminals may change the names and location of the files for different infections.

After creating the malicious files, Lortok encrypts the user’s files. It may look for the following file types:


After modifying the files, Lortok may add two file extensions to the encrypted files – .crime and an extension with random number, for example:

  • New Text Document.txt.crime
  • New Text Document.txt.55sd3f3

After encrypting the files, Lortok adds a ransom note written entirely in Russian:

“Здравствуйте, все ваши файлы зашифрованы, свяжитесь с нами для их восстановления.
Для этого выполните следующие действия:
1) Загрузите ‘Tor Browser for Windows’, скачать можно тут https://www.torproject.org/download/download-easy.html.en
2) Установите и запустите ‘Tor Browser’
3) Перейдите по ссылке ‘хппт://3qo5aqjlesrudfm3.onion/?id=…’ в ‘Tor Browser’ – (ВНИМАНИЕ, САЙТ ДОСТУПЕН ТОЛЬКО ЧЕРЕЗ ‘Tor Browser’)
4) Следуйте инструкциям на сайте
Для авторизации на сайте используйте:
ID: 55sd3f3
HashID: 4pbf28d2s
1) Внимание, ‘переустановка/откат’ windows не поможет восстановить файлы но может окончательно их повредить и тогда даже мы не сможем их восстановить.
2) Антивирусы nod32, drweb, kaspersky и т.д вам не помогут расшифровать файлы, даже если вы купите у них лицензию на 10 лет, они вам все равно не восстановят файлы.
3) Для шифрования файлов используется AES который был создан в 1998г, за 17 лет никто на планете земля не смог взломать алгоритм шифрования, даже АНБ.
4) Ключ других пользователей вам не подойдет, так как у каждого пользователя уникальный ключ, поэтому не ждите что кто-то оплатит и выложит ключ для расшифровки файлов.
Коротко о шифрование ‘AES256’ на примере ‘Winrar’, каждый файл помешается в архив ‘Winrar’, на архив ‘Winrar’ ставится пароль из 256 символов:
1) Открыть архив можно только введя пароль
2) Удалив ‘Winrar’ файл остается в архиве и открыть его нельзя.
3) Даже если перенести архив на другой windows, он все еще будет требовать пароль для открытия.
4) Если вы ‘переустановите/откатите’ windows, архив ‘Winrar’ останется архивом и для его открытия все еще потребуется ‘Winrar’ и пароль из 256 символов.
Вы можете ждать пока кто-то через лет 60 взломает алгоритм шифрования AES256 и через 60 лет восстановить файлы или же оплатить ключ и восстановить файлы за пару часов, выбор за вами!
English Translation:
Hello, all your files are encrypted, please contact us to restore them.
The cost of decrypting files is $ 5
To do this, follow these steps:
1) Download the ‘Tor Browser for Windows’, you can download it here https://www.torproject.org/download/download-easy.html.en
2) Install and run ‘Tor Browser’
3) Click on the link ‘http //3qo5aqjlesrudfm3.onion/ Id = …’ in the ‘Tor Browser’ – (ATTENTION, the site is available only through the ‘Tor Browser’)
4) Follow the instructions on the website
————————————————– ————
To login to the site using:
ID: 55sd3f3
HashID: 4pbf28d2s
————————————————– ————
1) Attention, ‘Overwrite / rollback’ of windows does not help to restore files but can ultimately damage them, and even then we will not be able to restore them.
2) Antivirus nod32, drweb, kaspersky, etc. will not help you decrypt the files, even if you buy them a license for 10 years, they will still not restore files.
3) To encrypt files using AES which was established in 1998, for 17 years, no one on Earth could not crack the encryption algorithm, even the NSA.
4) The key to other users you will not work, since each user a unique key, so do not expect that someone will pay and will lay the key to decrypt the files.
————————————————– ————
About encryption ‘AES256’ see on ‘Winrar’ example, each file was placed in the file ‘Winrar’, to archive ‘Winrar’ enter password of 256 characters:
1) You can open the file only by typing your password
2) Delete ‘Winrar’ file is archived and can not open it.
3) Even if you move the file to another Windows, it will still require a password to open.
4) If you ‘reinstall / revert’ windows, the archive ‘Winrar’ will archive and to open still need ‘Winrar’ and password of 256 characters.
————————————————– ————
You can wait until someone through 60 years will crack AES256 encryption algorithm, and after 60 years to restore the files, or to pay for the key and restore files in a couple of hours, the choice is yours!

Remove Lortok Ransomware and Decrypt Your Files for Free

To remove Lortok, please follow the instructions for removal which are prepared in a methodological order for you after this paragraph. For maximum effectiveness for the removal of Lortok from your computer, we strongly advise you to download an advanced anti-malware tool which will delete any malicious files belonging Lortok on your computer.

To decrypt your files, please follow carefully step 3 of those instructions – “Restore files encrypted by Lortok.” They contain a web link for Kaspersky’s “Rakhni decryptor” that will help you decrypt your files instead of paying 5$ for the cyber-criminals.

Ventsislav Krastev

Ventsislav is a cybersecurity expert at SensorsTechForum since 2015. He has been researching, covering, helping victims with the latest malware infections plus testing and reviewing software and the newest tech developments. Having graduated Marketing as well, Ventsislav also has passion for learning new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management, Network Administration and Computer Administration of System Applications, he found his true calling within the cybersecrurity industry and is a strong believer in the education of every user towards online safety and security.

More Posts - Website

Follow Me:

Attention! SensorsTechForum strongly recommends that all malware victims should look for assistance only by reputable sources. Many guides out there claim to offer free recovery and decryption for files encrypted by ransomware viruses. Be advised that some of them may only be after your money.

As a site that has been dedicated to providing free removal instructions for ransomware and malware since 2014, SensorsTechForum’s recommendation is to only pay attention to trustworthy sources.

How to recognize trustworthy sources:

  • Always check "About Us" web page.
  • Profile of the content creator.
  • Make sure that real people are behind the site and not fake names and profiles.
  • Verify Facebook, LinkedIn and Twitter personal profiles.


with Anti-Malware
We recommend you to download SpyHunter and run free scan to remove all virus files on your PC. This saves you hours of time and effort compared to doing the removal yourself.
SpyHunter 5 free remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read EULA and Privacy Policy

About the Lortok Research

The content we publish on SensorsTechForum.com, this Lortok how-to removal guide included, is the outcome of extensive research, hard work and our team’s devotion to help you remove the specific malware and restore your encrypted files.

How did we conduct the research on this ransomware?

Our research is based on an independent investigation. We are in contact with independent security researchers, and as such, we receive daily updates on the latest malware and ransomware definitions.

Furthermore, the research behind the Lortok ransomware threat is backed with VirusTotal and the NoMoreRansom project.

To better understand the ransomware threat, please refer to the following articles which provide knowledgeable details.


1. How to Recognize Spam Emails with Ransomware
2. How Does Ransomware Encryption Work?
3. How to Decrypt Ransomware Files
4. Ransomware Getting Greedier and Bigger, Attacks Increase by 40%
5. 1 in 5 Americans Victim of Ransomware

Windows Mac OS X

How to Remove Lortok from Windows.

Step 1: Boot Your PC In Safe Mode to isolate and remove Lortok


Manual Removal Usually Takes Time and You Risk Damaging Your Files If Not Careful!
We Recommend To Scan Your PC with SpyHunter

Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter's EULA, Privacy Policy and Threat Assessment Criteria

1. Hold Windows Key + R.

2. The "Run" Window will appear. In it, type "msconfig" and click OK.

3. Go to the "Boot" tab. There select "Safe Boot" and then click "Apply" and "OK".

Tip: Make sure to reverse those changes by unticking Safe Boot after that, because your system will always boot in Safe Boot from now on.

4. When prompted, click on "Restart" to go into Safe Mode.

5. You can recognise Safe Mode by the words written on the corners of your screen.

Step 2: Uninstall Lortok and related software from Windows

Here is a method in few easy steps that should be able to uninstall most programs. No matter if you are using Windows 10, 8, 7, Vista or XP, those steps will get the job done. Dragging the program or its folder to the recycle bin can be a very bad decision. If you do that, bits and pieces of the program are left behind, and that can lead to unstable work of your PC, errors with the file type associations and other unpleasant activities. The proper way to get a program off your computer is to Uninstall it. To do that:

1. Hold the Windows Logo Button and "R" on your keyboard. A Pop-up window will appear.

2. In the field type in "appwiz.cpl" and press ENTER.

3. This will open a window with all the programs installed on the PC. Select the program that you want to remove, and press "Uninstall"

Follow the instructions above and you will successfully uninstall most programs.

Step 3: Clean any registries, created by Lortok on your computer.

The usually targeted registries of Windows machines are the following:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

You can access them by opening the Windows registry editor and deleting any values, created by Lortok there. This can happen by following the steps underneath:

1. Open the Run Window again, type "regedit" and click OK.

2. When you open it, you can freely navigate to the Run and RunOnce keys, whose locations are shown above.

3. You can remove the value of the virus by right-clicking on it and removing it.

Tip: To find a virus-created value, you can right-click on it and click "Modify" to see which file it is set to run. If this is the virus file location, remove the value.

Before starting "Step 4", please boot back into Normal mode, in case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.

Step 4: Scan for Lortok with SpyHunter Anti-Malware Tool

1. Click on the "Download" button to proceed to SpyHunter's download page.

It is recommended to run a scan before purchasing the full version of the software to make sure that the current version of the malware can be detected by SpyHunter. Click on the corresponding links to check SpyHunter's EULA, Privacy Policy and Threat Assessment Criteria.

2. After you have installed SpyHunter, wait for it to update automatically.


3. After the update process has finished, click on the 'Malware/PC Scan' tab. A new window will appear. Click on 'Start Scan'.


4. After SpyHunter has finished scanning your PC for any files of the associated threat and found them, you can try to get them removed automatically and permanently by clicking on the 'Next' button.


If any threats have been removed, it is highly recommended to restart your PC.

Video Guide for Automatic and Fast Removal

Step 5 (Optional): Try to Restore Files Encrypted by Lortok.

Ransomware infections and Lortok aim to encrypt your files using an encryption algorithm which may be very difficult to decrypt. This is why we have suggested a data recovery method that may help you go around direct decryption and try to restore your files. Bear in mind that this method may not be 100% effective but may also help you a little or a lot in different situations.

1. Download the recommended Data Recovery software by clicking on the link underneath:

Simply click on the link and on the website menus on the top, choose Data Recovery - Data Recovery Wizard for Windows or Mac (depending on your OS), and then download and run the tool.

Step 6: How to Restore Files Encrypted by Ransomware (Video Guide)

Windows Mac OS X

Get rid of Lortok from Mac OS X.

Step 1: Uninstall Lortok and remove related files and objects

Manual Removal Usually Takes Time and You Risk Damaging Your Files If Not Careful!
We Recommend To Scan Your Mac with SpyHunter for Mac
Keep in mind, that SpyHunter for Mac needs to purchased to remove the malware threats. Click on the corresponding links to check SpyHunter’s EULA and Privacy Policy

1. Hit the ⇧+⌘+U keys to open Utilities. Another way is to click on “Go” and then click “Utilities”, like the image below shows:

2. Find Activity Monitor and double-click it:

3. In the Activity Monitor look for any suspicious processes, belonging or related to Lortok:

Tip: To quit a process completely, choose the “Force Quit” option.

4. Click on the "Go" button again, but this time select Applications. Another way is with the ⇧+⌘+A buttons.

5. In the Applications menu, look for any suspicious app or an app with a name, similar or identical to Lortok. If you find it, right-click on the app and select “Move to Trash


6. Select Accounts, after which click on the Login Items preference.

Your Mac will then show you a list of items that start automatically when you log in. Look for any suspicious apps identical or similar to Lortok. Check the app you want to stop from running automatically and then select on the Minus (“-“) icon to hide it.

7. Remove any left-over files that might be related to this threat manually by following the sub-steps below:

  • Go to Finder.
  • In the search bar type the name of the app that you want to remove.
  • Above the search bar change the two drop down menus to “System Files” and “Are Included” so that you can see all of the files associated with the application you want to remove. Bear in mind that some of the files may not be related to the app so be very careful which files you delete.
  • If all of the files are related, hold the ⌘+A buttons to select them and then drive them to “Trash”.

In case you cannot remove Lortok via Step 1 above:

In case you cannot find the virus files and objects in your Applications or other places we have shown above, you can manually look for them in the Libraries of your Mac. But before doing this, please read the disclaimer below:

Disclaimer! If you are about to tamper with Library files on Mac, be sure to know the name of the virus file, because if you delete the wrong file, it may cause irreversible damage to your MacOS. Continue on your own responsibility!

1: Click on "Go" and Then "Go to Folder" as shown underneath:

2: Type in "/Library/LauchAgents/" and click Ok:

3: Delete all of the virus files that have similar or the same name as Lortok. If you believe there is no such file, do not delete anything.

You can repeat the same procedure with the following other Library directories:

→ ~/Library/LaunchAgents

Tip: ~ is there on purpose, because it leads to more LaunchAgents.

Click the button below below to download SpyHunter for Mac and scan for Lortok:


SpyHunter for Mac

Step 3 (Optional): Try to Restore Files Encrypted by Lortok.

Ransomware infections and Lortok aim to encrypt your files using an encryption algorithm which may be very difficult to decrypt. This is why we have suggested a data recovery method that may help you go around direct decryption and try to restore your files. Bear in mind that this method may not be 100% effective but may also help you a little or a lot in different situations.

1. Download the recommended Data Recovery software by clicking on the link underneath:

Simply click on the link and on the website menus on top, choose Data Recovery - Data Recovery Wizard for Windows or Mac (depending on your OS), and then download and run the tool.

Lortok FAQ

What is Lortok ransomware and how does it work?

Lortok is a ransomware infection - the malicious software that enters your computer silently and blocks either access to the computer itself or encrypt your files.

Many ransomware viruses use sophisticated encryption algorithm how to make your files inaccessible. The goal of ransomware infections is to demand that you pay a ransom payment to get access to your files back.

How does Lortok ransomware infect my computer?

Via several ways.Lortok Ransomware infects computers by being sent via phishing e-mails, containing virus attachment.

This attachment is usually masked as an important document, like an invoice, bank document or even a plane ticket and it looks very convincing to users.

After you download and execute this attachment, a drive-by download occurs and your computer is infected with the ransomware virus.

Another way, you may become a victim of Lortok is if you download a fake installer, crack or patch from a low reputation website or if you click on a virus link. Many users report getting a ransomware infection by downloading torrents.

How to open .Lortok files?

You can't. At this point the .Lortok files are encrypted. You can only open them once they are decrypted.

Decryptor did not decrypt my data. What now?

Do not panic and backup the files. If a decryptor did not decrypt your .Lortok files successfully, then do not despair, because this virus is still new.

One way to restore files, encrypted by Lortok ransomware is to use a decryptor for it. But since it's a new virus, advised that the decryption keys for it may not be out yet and available to the public. We will update this article and keep you posted as soon as this decryptor is released.

How Do I restore ".Lortok" files (Other Methods)?

Yes, sometimes files can be restored. We have suggested several file recovery methods that could work if you want to restore .Lortok files.

These methods are in no way 100% guarantee that you will be able to get your files back. But if you have a backup, your chances of success are much greater.

How do I get rid of Lortok ransomware virus?

The safest way and the most efficient one for the removal of this ransomware infection is the use a professional anti malware software. It will scan for and locate Lortok ransomware and then remove it without causing any additional harm to your important .Lortok files.

Also, keep in mind that viruses like Lortok ransomware also install Trojans and keyloggers that can steal your passwords and accounts. Scanning your computer with an anti-malware software will make sure that all of these virus components are removed and your computer is protected in the future.

What to Do If nothing works?

There is still a lot you can do. If none of the above methods seem to work for you, then try these methods:

  • Try to find a safe computer from where you can can login on your own line accounts like One Drive, iDrive, Google Drive and so on.
  • Try to contact your friends, relatives and other people so that they can check if they have some of your important photos or documents just in case you sent them.
  • Also, check if some of the files that were encrypted it can be re-downloaded from the web.
  • Another clever way to get back some of your files is to find another old computer, a flash drive or even a CD or a DVD where you may have saved your older documents. You might be surprised what will turn up.
  • You can also go to your email account to check if you can send any attachments to other people. Usually what is sent the email is saved on your account and you can re-download it. But most importantly, make sure that this is done from a safe computer and make sure to remove the virus first.

More tips you can find on our forums, where you can also asks any questions about your ransomware problem.

How to Report Ransomware to Authorities?

In case your computer got infected with a ransomware infection, you can report it to the local Police departments. It can help authorities worldwide track and determine the perpetrators behind the virus that has infected your computer. Below, we have prepared a list with government websites, where you can file a report in case you are a victim of a cybercrime:

Cyber-security authorities, responsible for handling ransomware attack reports in different regions all over the world:

Reports may be responded to in different timeframes, depending on your local authorities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share