ExecutionerPlus is designed to attack computer users from Turkey and English-speaking countries

ExecutionerPlus is a ransomware virus that is based on CryptoJoker’s source code. Malware uses AES encryption[1] and appends either .pluss.executioner or .destroy.executioner file extensions to the targeted data. Following data encryption, it delivers and opens a ransom note in Readme.html file.
The ransom-demanding message is short and does not provide any detailed information about data recovery. However, judging from the ransom note, ExecutionerPlus aims at English and Turkish[2] computer users. The original text provided in the ransom note:
HEYKLOG-LOSTHAT
HEYKLOG & CRYPTONIC the My the Friend the Best
Turkish Underground World ~
Guvenlik bir bir urun degil surectir.
ExecutionerPlus virus is executed from CryptoJoker_dump.exe.bin file which might be installed on the system as a fake software, update or email attachment. Once it infiltrates the system, it immediately alter’s Windows settings and Registry, and start data encryption procedure.
Crypto-virus is designed to corrupt the most popular and widely used file types in order to cause a bigger damage to the victims. Thus, after the ExecutionerPlus attack, users will not be able to open Microsoft Office, OpenOffice or other documents, text files, PDFs, archives, databases, various types of audio, video and image files.
The current version of the virus might be decryptable. Thus, victims are advised to focus on ExecutionerPlus removal. Ransomware might cause numerous changes to the system and inject malicious codes to legit system processes. For this reason, you should not try to terminate file-encrypting virus manually.
In order to remove ExecutionerPlus correctly and safely, you have to use reputable security software, such as FortectIntego or MalwarebytesMalwarebytes. However, if you cannot download or run malware removal tool, you should check our prepared instructions at the end of the article.

Distribution methods of the crypto-malware
Currently, malware hasn’t started active distribution campaign. However, security experts note the importance of learning about ransomware distribution strategies to avoid the cyber attack. Therefore, you should pay attention to these security tips:
- Do not open spam emails and their attachments. Malspam is the main ransomware distribution method that relies on social engineering tactics. Thus, users can easily get tricked by fake invoice, statement or other safe looking documents.
- Eye-catching and aggressive pop-ups often contain malicious content. Ads that promote unknown security software, warn about detected viruses or report about missing updates often are the ones that spread malware. Thus, you should never click them.
- Install all available updates. Outdated operating system and software might include security vulnerabilities that might help malware to get inside the system.
- Protect your PC with antivirus to minimize the risk of cyber attack.[3]
- Create and regularly update data backups. In case of the ransomware attack, they will be extremely important.
Removal of the ExecutionerPlus ransomware virus
Trying to locate and eliminate ransomware-related entries from the computer manually is a risky task. Thus, if you are thinking about this ExecutionerPlus removal method, we want to discourage you from that. You might accidentally delete wrong files and damage the system even more.
In order to remove ExecutionerPlus safely, you have to use reputable malware removal software and run a full system scan with it. We suggest using FortectIntego or MalwarebytesMalwarebytes, but feel free to choose your preferred tool as well. If you need additional help, please follow the guide below.
Did this guide help?
Be the first to comment