Evil ransomware – file locking malware written in JavaScript

Upon release, Evil ransomware[1] has caught malware researchers’ attention and immediately became a subject of investigation. Upon closer inspection, they confirmed that it mostly spreads via malicious email attachments, targets broad spectrum file types, encrypts them using AES[2] cipher, and demands to pay the ransom.
The threat is known as JavaScript-based ransomware, as it is written in this programming language. When it finds the entrance to the computer, it starts scanning the system looking for targeted files. In order to cause more damage to the victims and encourage them to pay the ransom, malware ruins the most popular file types, such as Microsoft Office documents, various image, audio, or video files, by appending the .file0locked extension.
| Name | Evil ransomware |
| Type | File locking virus |
| Programming language | JavaScript |
| Contact email | r6789986@mail.kz |
| File extension | .file0locked |
| Elimination | Use SpyHunterCombo Cleaner or another reputable anti-malware to delete ransomware from your system |
| System fix | Malware can seriously damage Windows system components, which later might bring to crashes, errors, and other instability issues. Thus, you can use FortectIntego repair tool to fix these issues automatically |
Malware also drops a ransom note titled HOW_TO_DECRYPT_YOUR_FILES.htm, which includes victims' ID and explains that they have to email it to r6789986@mail.kz address for further instructions. As usual, attackers are likely to ask for payment in Bitcoin cryptocurrency.
The whole list of targeted files includes:
.3fr, .accdb, .ai, .arw, .bay, .cdr, .cer, .certs, .cr2, .crt, .crw, .dbf, .dcr, .der, .dng, .doc, .dwg, .dxf, .dxg, .eps, .erf, .img, .indd, .jpg, .kdc, .mdb, .mdf, .mef, .mrw, .nef, .nrw, .odb, .odc, .odm, .odp, .ods, .odt, .orf, .p12, .p7b, .p7c, .pdd, .pef, .pem, .pfx, .ppt, .psd, .pst, .ptx, .pub, .r3d, .raf, .raw, .rtf, .rw2, .rwl, .sr2, .srf, .srw, .wb2, .wpd, .wps, .x3f, .xlk, .xls
Due to the appended file extension, the malware was given another alternative name – File0Locked virus. When it encrypts targeted files with an AES-based encryption algorithm.
The malware drops the ransom note in two different formats – TXT and HTML files. Both of them include the same information – the victim’s ID number and instructions on what to do to get back their files.
The creators of ransomware tell that it’s just a business, and victims have to purchase the decryption key. However, you should not be a part of this illegal business. Do not follow criminals’ instructions and do not contact them via provided email address to know your size of the ransom. The demanded amount of money might vary from the size and importance of the encrypted files.
However, you don’t need to know the worth of your files. Remove Evil virus from the computer and do not risk losing your money. There’s no guarantee that paying the ransom[3] will be an effective method; besides, transferred bitcoins motivate cybercriminals to continue developing illegal projects.
Hence, start ransomware removal with the help of SpyHunterCombo Cleaner, and our prepared instructions – only then should you try to restore data from backups or other methods listed below. Finally, scan your device with FortectIntego to remediate damaged Windows system files.
Email spam: the main ransomware distribution method
The developers of the ransomware mostly distribute the malicious file via malicious email attachments. It’s a popular and successful malware distribution[4] technique among all hackers. Crooks learned to persuade and convince people to open the attached document by pretending to be from various organizations or companies.
Some infected emails are not hard to recognize; however, sometimes cybercriminals perfectly copy the design and signature of the particular organization. Therefore, you should not trust any received email that urges you to open the provided document.
Always double-check the information before looking at what information the attachment hides. Bear in mind that the virus might also be distributed using other techniques such as malvertising[5] or via bogus software updates or downloads. If you want to avoid ransomware, make sure your computer is protected with a strong antivirus program.
However, any program can make you feel 100% safe online. Apart from watching your clicks, you should also make data backups regularly. They will be valuable after a ransomware attack.
Remove Evil ransomware and attempt to recover files without paying
Ransomware elimination requires scanning the infected computer with reliable anti-malware tools. We recommend installing SpyHunterCombo Cleaner or MalwarebytesMalwarebytes because these programs are capable of detecting and eliminating all malicious components that might be hiding deep inside the system.
Keep in mind that trying to complete this task manually might cause even bigger damage. Hence, if you consider removing the Evil ransomware virus manually, get rid of this idea right now. What is more, ransomware might prevent automatic elimination and block access to the security tools. In this case, you will have to reboot your PC to the Safe Mode. Detailed instructions on how to activate malware removal programs and additional data recovery methods are presented below.
Did this guide help?
3 comments
Impressed
Such a vivid name for the ransomware...
encrypted
Please, let us know about the release of the free decryptor.
hate ransomware
Hackers will pay for this dirty job!!!