Locky Decrypter is a misleading data decryption tool sold by cyber criminals

Locky Decryptor is a tool created by the same cyber criminals who developed the infamous Locky virus[1]. This decrypter is sold for 0,5, 1 or 2,5 BTC[2] for people whose files have been encrypted by .locky, .asasin, .ykcol, .diablo6, .osiris, .odin, .thor, .zepto, .shit, .aesir, .loptr or another Locky variant. Nevertheless, white hats do not recommend paying the ransom because the real locky decrypter functions might be related to malware distribution and creation of backdoors.[3]
| Name | Locky Decryptor |
| Type | Ransomware-related |
| Symptoms | Personal files locked with .locky or other Locky ransomware variant. The ransom note _Locky_recover_instructions instructs to pay Locky Decryptor |
| Distribution | This ransomware decryptor can only be purchased from Locky developers for a particular amount of Bitcoins |
| Price | Varies. Maximum demand 2.5 Bitcoins |
| Related processes | locky _decrypter.exe |
| Elimination | Locky Decryptor can download other malware or initiate system's changes to make it vulnerable. To fix that, download FortectIntego and run a full system scan with it. |
Along with the evolution of the malware, the software has been renewed as well. It presents a wide choice of alternative language options for non-native English speakers. The price for file decrypting services varies. The maximum payback about has been registered in 2016 when victims were asked to pay 2.5 BTC[2], so currently the sum in USD would exceed 8000. According to victim's reports, Locky Decrypter is currently sold for 0.25 Bitcoin.
Interestingly, that one of the latest variations, Lukitus ransomware[4], which emerged along with Diablo6 campaign, both known under one IKARUSdilapidated campaign, also uses the identical tool. Thus, it is recommended to remove Locky Decrypter right away.
Speaking about the very ransomware, Locky virus operates as a seriously dangerous ransomware that is currently spreading panic all around the world. This virus is distributed via infected email attachments, allegedly containing some invoice information. Reportedly, the virus comes in a ZIP file carrying the infected Word or JavaScript document.

This virus is distributed via infected email attachments, allegedly containing some invoice information. Reportedly, the virus comes in a ZIP file carrying the infected Word or JavaScript document.
Once Locky gets into the victim’s computer and is activated, it starts scanning the system for a variety of different file extensions and encrypts the located files using the RSA-2048 and AES-128 algorithms. After this virus encrypts the files, it adds a .txt document, titled _Locky_recover_instructions to every folder on the computer containing the infected files.
The note explains that now, the files on the computer are locked and there is no way to unlock them without a decryption key. “Luckily”, the developers of this fraudulent program propose a solution. They offer you to buy a Locky Decrypter software which will supposedly help you to unlock the encrypted documents.

All you have to do is to connect to an anonymous Tor network and to purchase Locky Decrypter on an indicated website. Also, the victim is threatened to pay up in one week's time, or else, the price of the decrypter will double. This is pure blackmail. Therefore, Locky Decrypter removal should be performed right away.
Sadly, a lot of people opt for this option out of the desperation to retrieve their lost files. However, we highly advise you not to make any transactions, because you are dealing with cyber criminals, so there is no guarantee that the tool will decrypt locky ransomware. In this case, you'll be left with no data and no money.
You may need to spend more than $300 or even $600 (which equal 0,5 and 1 bitcoin respectively) for it. What is more, even if you receive the promised software, you cannot be sure if it will successfully decrypt the files. Therefore, if you are infected with this virus, it is better that you remove it immediately rather than try to buy out your files.
By doing that, you only support the scammers and their malicious future creations. We recommend using a reputable antivirus like FortectIntego or MalwarebytesMalwarebytes to remove Locky ransomware and its decrypter from your computer.
Promotion ways
Once you open the ransom note, you will notice multiple links to the websites, where you can obtain the Locky Decrypter. The decryptor can only be downloaded from websites, accessible through an anonymous Tor network, which is favoured by a variety of online scammers, hackers, and other crooks.

It is extremely dangerous to interact with any of these links because they may redirect you to some other infectious websites and contaminate your system with trojans, viruses, and worms. Note that deleting .locky decrypter or locky _decrypter.exe files will not help eradicate the very malware.
More information is provided below. Therefore, it is wiser to initiate about Locky removal than risk causing your computer additional problems.
Get rid of Locky Decrypter
The functionality of Locky Decryptor is highly questionable. Nevertheless, even if you have already purchased the program and managed to decrypt your files, we highly recommend you to remove Locky Decrypter virus along with the Locky virus from your system. To do that, you can follow three fundamentals steps.

First, you should obtain a reputable antivirus tool, such as FortectIntego or MalwarebytesMalwarebytes. Then, disconnect your PC from the network because your computer may be more vulnerable to the Locky processes when it is online.
Lastly, run a thorough scan of your system with the obtained antivirus software, which will detect and remove Locky virus and all of its components from your machine. If you are experiencing any difficulties, you can also check the Locky removal guide also provided on our website.
Did this guide help?
5 comments
KenethLouis
Things are getting really serious with this Locky virus doesnt it?
Pauline Bales
Do antivirus tools protect from such viruses?
Harry1313
Some of them do. Well at least the better ones :D You just need to keep your virus database updated.
Alison W.
I dont think you can rely merely on antivirus. As they say in the article, youve got to take precautions yourself.
Cihan
hi, does anyone have solution for .locky files (except autolocky) ?