Bad news: Locky hides under .zzzzz file extension
.zzzzz file extension virus has been revealed to be another version of the menacing Locky virus [1] . The current events show that Locky has successfully reclaimed its title of the most dangerous cyber threat. Interestingly, that there is visible competition between the hackers of this menace and Cerber which introduced their 6th installment – Cerber 4.1.6 – as well. Locky developers might be praised for their sense of humor as they shifted from mythology-inspired infections, such as ODIN and Thor to such viruses as .shit virus, .aesir, and .zzzzz file extension threats. The new version has been named after the appended extension accordingly. However, there is no need to panic as you should concentrate on .zzzzz virus removal. Do not waste time and install FortectIntego to speed up the process.

While there have been occasional stories of this ransomware hijacking the databases of medical institutions and major companies, ordinary users may not have worried much about their cyber safety. It was only a matter of time when the authors of this frightening cyber infection would launch a more insidious campaign. The news about the detected virus on Facebook in the disguise of .svg file quickly went viral [2]. On this occasion, the crooks launched a “back-up“ – .zzzzz malware. There are not many updated features, the main one is the altered extension attached to the corrupted data. Now valuable documents, image file, audio and media files are labeled with [8_random_characters]-[4_random_characters]-[4_random_characters]-[4_random_characters]-[12_random_characters].zzzzz extensions. The virus presents its demands in INSTRUCTION.html, _6-INSTRUCTION.html, and -INSTRUCTION.bmp files.
$|$+$**
|+__.-
!!! IMPORTANT INFORMATION !!!
All of your files are encrypted with RSA-2048 and AES-128 ciphers.
More information about RSA and AES can be found here:
hxxp://en.wikipedia.org/wiki/RSA (cryptosystem)
hxxp://en.wikipedia.org/wiki/Advanced Encryption Standard
Decrypting of your files is only possible with the private key and decrypt program, which is on our secret server.
To receive your private key follow one of the links:
If all of this addresses are not available, follow these steps:
1. Download and install Tor Browser: hxxp://www.torproject.org/download/download-easy.html
2. After a successful installation, run the browser and wait for initialization.
3. Type in the address bar:
4. Follow the instructions on the site.
_$+=$.$-*$$$
+*-++|| *==_*-a-
__+$|+++-$-.+
Speaking of the ransom note, the current ransom is set on 740 USD, while it still varies depending whether the infected user is an ordinary or corporate one. Unfortunately, the data breach involving the Office of Personnel Management only facilitated the cyber campaign of .zzzzz hijack. After the crooks had obtained the personal data of millions of federal employees, they came up with much more destructive infection techniques. No matter how perilous this virus may look, remove .zzzzz ransomware right away. Lastly, we would like to warn not to install Locky Decrypter promoted by the hackers. There is no guarantee that you will retrieve the files after transferring the money [3]. The program may decrypt the files but in exchange leave the infected files on the system which would reactivate the hijack in the future.
How can the PC get infected with the virus?
The ransomware empowered its distribution channels by targeting users via email attachments. Unfortunately, they remain the profitable tool to deliver .zzzzz virus hijack. The recent cases reveal that the malware might disguise under Amazon and send you the email with a .zip attachment which supposedly includes information about your order. Alternatively, some emails may falsely accuse of detected illegal activity sent from the OPM. Do not fall for such deception and instead, update your security applications. Keep in mind that the virus spreads via trojans. The latter might lurk in the websites promoting pirated content or similar P2P file-sharing domains [4].
Getting rid of .zzzzz ransomware
Since the infection possesses an elaborate structure, you should not waste time on manual .zzzzz removal procedure. Instead, install and update anti-spyware applications, such as FortectIntego or MalwarebytesMalwarebytes, which are able to detect the trojans carrying the ransomware as well. After you remove .zzzzz virus completely, look up the recommendations to recover the data. The best way to do that is to use the backup copies. If you do not have them use the following recommended utilities. Lastly, pay attention to the received spam [5] and ordinary email messages. Even if you get the message from the well-known company, look for grammar and typos. They might be hints that one of the Locky versions attempts to assault your device.
Was this guide helpful?
4 comments