This tool does not work if you restart your computer after the infection
Decryption tool for the LooCipher Ransomware
- Find the Process ID (PID) of the LooCipher ransomware
- Open
cmd
with elevated (Administrator) privileges - Move to the path where this tool was downloaded
- In the
cmd
prompt, typeZLAB_LooCipher_Decryptor.exe <PID>
Due to the continuing LooCipher infection campaign, we proceeded to release the decryptor in the shortest possible time in order to help the victims infected in the previous phase. So, the tool is a Beta release and it is still composed by an unsigned executable. We will provide to release some updates as soon as possible.