Litar ransomware is a file locking virus that belongs to the notorious malware family Djvu

Litar ransomware is a type of computer infection that focuses on money extortion by locking personal pictures, documents, databases, image, video, and other files. The encryption process is performed with the help of AES-256[1] or another strong encryption algorithm, and all files are appended with a .litar file extension, which prevents victims from using their data.
Litar ransomware was first spotted at the end of June, and it belongs to one of the most prevalent malware families around – STOP/Djvu. While email address and the appended extension vary, the goal of the string remains the same – to make users pay $980/$490 ransom in Bitcoin. Crooks ask victims to contact them via gornetos@bitmessage.ch, ferast@firemail.cc or @datarestore (Telegram) on a compiled ransom note _readme.txt, which is placed into each folder that contains compromised data.
While the decryption process might be complicated, many security vendors recognize[2] the threat as TR/AD.InstaBot.arm, Trojan-Ransom.Win32.Stop.ba, Trojan.MalPack.GS.Generic, etc., so Litar ransomware removal can be performed using anti-malware tools.
| Name | Litar |
| Type | Ransomware |
| Family | STOP/Djvu |
| Cipher | AES |
| Extension | .litar |
| Ransom note | _readme.txt |
| Related files | 8312fe0b372ea144637254f5c27fbcc0.virobj |
| Contact | gornetos@bitmessage.ch, ferast@firemail.cc, @datarestore (Telegram) |
| Decryptable? | Might be possible with the STOPdecrypter [] by Michael Gillespie |
| Termination | Use anti-malware software like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes |
Litar ransomware authors use a variety of deceptive and sophisticated techniques to distribute the malicious payload in order to infect more users around the world, consequently maximizing the chance of ransom transfers. A few examples of the most popular methods include:
- Exploit kits
- Web injects
- Fake updates
- Software cracks
- Spam emails
- Brute-force attacks, etc.
To find how to avoid ransomware infections in the future, please refer to the second section of this article.
Once Litar virus enters the host computer, it performs several changes to it, such as modification of Windows registry, shadow volume copies removal, and others. These adjustments allow the malware to perform file encryption undisturbed. Additionally, some versions might even disable security software and install secondary payload like AZORult trojan.
After that, Litar ransomware encrypts all personal files on the hard drive, solid state drive, or any other connected storage devices. Users are unable to open any data, although the installed programs and system files that require Windows to operate are left untouched. The ransom note is dropped into every folder where locked data is located, and it states:
ATTENTION!
Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-hvv30uAtTY
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.To get this software you need write on our e-mail:
gorentos@bitmessage.chReserve e-mail address to contact us:
ferast@firemail.ccOur Telegram account:
@datarestore
Do not pay the ransom, as hackers behind Litar ransomware might simply take your money and never send the decryptor back. Besides, it would only encourage them to produce more viruses and infect more people around the world.

Therefore, rather remove Litar ransomware with adequate tools, such as FortectIntego or SpyHunterCombo Cleaner, although other security applications can be used as well. After that, you can try several file recovery methods if you do not have backups.
Ransomware avoidance recommendations
Ransomware is possibly one of the most devastating malware categories, as the ramifications of its presence are left behind even after its removal. While regular users can lose access to precious photos or valuable worksheets, companies might end up paying a much higher price – they spend millions of dollars for the recovery operations and IT infrastructure renewal.
While there are no malware prevention techniques that would protect you 100%, the reduction of the infection possibility can be reduced drastically, as long as you follow these simple recommendations from industry experts:[3]
- Do not use outdated operating systems like Windows 7 or XP – they are not safe;
- Update Windows as soon as patches are released, along with all the installed software;
- Beware of spam email attachments and hyperlinks – phishing emails are often used by criminals to inject malware into users' devices;
- Do not download pirated software and cracks/keygens;
- Install ad-blocker;
- Use strong passwords for all your accounts and enable two-factor authentication where possible;
- Make sure you keep comprehensive anti-malware software running at all times.
Get rid of Litar ransomware to have a chance at file recovery

Be aware that you need to remove Litar ransomware before attempting file recovery. As we previously mentioned, cryptoviruses lock the data on the host computer, as well as all connected storage devices. Thus, if you attempt to add any new files while the machine is still infected, you will lose them as well – including the backups. Therefore, make sure you enter Safe Mode with Networking and use anti-malware software for full Litar ransomware removal.
While there is no definite decryptor for Litar virus, you can try a decryption tool that was developed by an independent security researcher. In case the encryption process was performed offline, there is a good chance of recovering data for free. Alternatively, you can try third-party tools that might be able to retrieve at least some of your pictures, documents, videos, etc.
Was this guide helpful?
Be the first to comment