File-Locker ransomware demands 50 000 Won from Korean victims

File-Locker is a ransomware-type virus which is categorized as a new variant of the infamous HiddenTear. It uses AES ciphers to encrypt the most widely used data and appends .locked or .razy extension afterward[1]. However, according to the latest researches, it has nothing in common with Razy ransomware.
According to the IT specialists, it reaches the system as File-Locker Ransomware.exe file which is the executable of the file-encrypting virus. Once the malware is inside, it starts corrupting data and drops Warning!!!!!!.txt file to inform a computer user about the attack. Currently, it mainly targets people from Korea since it demands to pay 50K Won as a ransom.
File-Locker ransom note is written in both, Korean and English, languages. The latter version states the following:
English: Warning!!! All your documents, photos, databases and other important personal files were
encrypted!!You have to pay for it.
Send fifty thousand won to fasfry2323@naver.com Bitcoin payment code:
1BoatSLRHtKNngkdXEeobR76b53LETtpyT Payment site: http://www.localbitcoins.com/

You can easily remove File-Locker with the help of the powerful security software. This automatic elimination procedure only requires you to download the antivirus software and let it scan your system thoroughly. If you want more detailed guidelines, head straight to the instructions below.
Note that File-Locker removal is a challenging process and you should not try to get rid of the malicious program yourself. Ransomware-type viruses are able to infiltrate other high-risk computer infections, and you might end up only harming your computer even more.
The most widely used ransomware distribution techniques
While it is currently not enough information to state which distribution method ransomware developers have employed, BedyNet.ru[2] experts believe that they have combined several ones to increase the rate of infections:
- Malicious email attachments;
- Obfuscate application files on P2P networks;
- Fake software updates.
Ransomware can reach the targeted systems as a spam emails holding the executable file. Usually, crooks try to convince gullible people to open the malicious attachment by imitating well-known companies. People are informed about the specific problem and urged to check the attachment for further details.
Unfortunately, once it is opened, the ransomware infiltrates on the system and starts data encryption. Furthermore, obfuscate software files might be placed on peer-to-peer networks which might look extremely genuine[3]. Therefore, the users are advised to closely monitor their online activity and avoid any illegal downloads which may put their security at risk.
Note that a vast of people get tricked to manually install malware once the fake pop-up window or ad appears threatening their privacy. However, be aware that it is merely an attempt to intimidate you and infect your computer by making unthoughtful decisions.
Learn the best way to get rid of File-Locker virus
Once again, we kindly ask you to get help from the professionals in case of File-Locker virus attack. This is a highly dangerous program which might trick you to delete legitimate Windows processes once you try to get rid of it. Also, it may let other computer threats in without your knowledge.
Therefore, we do not recommend trying to remove File-Locker Razy ransomware alone for a regular computer user. Instead, we suggest you two options — either install a powerful security software now or follow the instructions below. Both of these methods will help you to eliminate this computer hazard safely.
If you decide to perform automatic File-Locker removal we suggest using FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. These antivirus tools are tested by our security experts and highly advised to use in case of ransomware.
Did this guide help?
Be the first to comment