Lezp Virus (. Lezp File) – Decrypt & Removal Tool

What is “Lezp” virus?

Ransomware is a kind of virus that encrypts your documents and then forces you to pay to restore them. DJVU (aka STOP) ransomware family was first revealed and analyzed by virus analyst Michael Gillespie">2.

Lezp is similar to other representatives of ransomware like: Lalo, Mpaj, Jope. It encrypts all popular file types. Hence, users cannot work with the your documents or photos. Lezp adds its particular “.lezp” extension into all files. For example, the file “video.avi”, will be changed into “video.avi.lezp”. As soon as the encryption is successfully accomplished, Lezp drops a specific file “_readme.txt” and drop it into all folders that contain the modified files.

Ransomware family3DJVU/STOP4 ransomware
Extension.lezp
Ransomware note_readme.txt
RansomFrom $490 to $980 (in Bitcoins)
Contact,
Detection5Trojan:Win32/Mokes.PVD!MTB, BScope.TrojanPSW.Coins, Trojan.Win32.Garvi.pu
SymptomsYour files (photos, videos, documents) have a .lezp extension and you can’t open it
Fix ToolSee If Your System Has Been Affected by .lezp file virus

This text asking payment is for restore files via decryption key:

The scary alert demanding from users to pay the ransom to decrypt the compromised data contains these frustrating warnings

The cryptography algorithm used by Lezp is AES-256. So, if your documents got encrypted with a specific decryption key, which is totally distinct and there are no other copies. The sad reality is that it is impossible to restore the information without the unique key available.

In case if Lezp worked in online mode, it is impossible for you to gain access to the AES-256 key. It is stored on a remote server owned by the frauds who promote the Lezp infection.

For receiving decryption key the payment should be $980. To obtain the payment details the victims are encouraged by the message to contact the frauds by email ().

Do not pay for Lezp!

_readme.txt file also indicates that the computer owners must get in touch with the Lezp representatives during 72 hours starting from the moment of files where encrypted. On the condition of getting in touch within 72 hours users will be granted a 50% rebate, thus the ransom amount will be minimized down to $490). Yet, stay away from paying the ransom!

I definitely advise that you do not contact these frauds and do not pay. The one of the most real working solution to recover the lost data – just using the available backups, or use Decrypter tool.

It’s highly-desirable you not to contact ransomware distributors. Their target is your money, so they will do everything you to pay them. For some victims, they put on act that they will really decrypt your files, offering to decrypt one or two files. Of course, they can, but no one can force them to decrypt all your files after your payment and not to force you to pay more for some reasons.

Croocks also have a very mean practise. They are collecting e-mails of all victims who contacted them, and then selling this database to other ransomware distributors or, maybe, just spammers, who will fill your mailbox with spam, advetisering or so.

Some of the users who contacted croocks told us about one strange message. That was a ranting, where ransomware distributors told about encryption as a punishment for everyone who are using cracked software. Proper revengers, exactly.

The peculiarity of all such viruses apply a similar set of actions for generating the unique decryption key to recover the ciphered data.

Thus, unless the ransomware is still under the stage of development or possesses some hard-to-track flaws, manually recovering the ciphered data is a thing you can’t really perform. The only solution to prevent the loss of your valuable data is to regularly make backups of your crucial files.

Lezp ransomware, like all STOP/Djvu ransomware family, usually gets to user’s PC unactive. It can be “asleep” for a long time, until it wouldn’t get a “start encryption” command from ransomware distributor’s server. So, that’s a big risk that you can create a backup with ransomware inside, and using it for system restoration after ransomware attack will not have any effect.

But already created backups can be contaminated, too. Ransomware can just encrypt it’s files, so you cant use this backup anymore. But, fortunatelly, Lezp ransomware usually cannot completely encrypt your backup, so you can try to pull out some important files.

Lezp ransomware can also disable or even delete your backups, if they were created with basic Windows tools. It usually check the default folder where the backups are stored, so the best way is to use any other creation tool, or to store your backups in the safe place, external drive, for example.

There also were a lot of reports saying about hosts file editing. Lezp ransomware adds Microsoft update server to this file. Hence, Windows will not be able to get an update, which can wipe out some changes ransomware did to system files and registry.

Note that even if you do maintain such backups regularly, they ought to be put into a specific location without loitering, not being connected to your main workstation.

For instance, the backup may be kept on the USB flash drive or some alternative external hard drive storage. Optionally, you may refer to the help of online (cloud) information storage.

Lezp ransomware has a specific (but quite easy) mechanism that prevents encryption process interuption by reboots. It adds itself to RunOnce registry key, so every time you are starting your PC, Lezp will start with it. Such trick can be avoided by starting the system in “safe mode”. It prevents any software launch in spite of proprietary Windows programs.

Needless to mention, when you maintain your backup data on your common device, it may be similarly ciphered as well as other data.

For this reason, locating the backup on your main PC is surely not a wise idea.

Chloe Bennett

Chloe Bennett

Culture, Media & Entertainment Columnist

Chloe Bennett explores the intersection of pop culture, streaming entertainment, digital trends, and contemporary lifestyle. Her weekly commentary reaches thousands of culture enthusiasts.

Share this article
Twitter Facebook Pinterest