Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jan 2019

How to remove FilesLocker ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

FilesLocker is a crypto malware that was recently decrypted with the help master RSA key

FilesLocker is a ransomware virus that primarily targets Chinese and English users and was first spotted making rounds in late October 2018. Malware uses AES + RSA cipher to encrypt data and appends .locked or .[fileslocker@pm.me] appendix. While .locked file virus uses the same file extension, researchers did not find any association with all previously encountered ransomware viruses. As described by hackers, FilesL0cker RAN$OMWARE places “解密我的文件.txt” and “#DECRYPT MY FILES#.txt” into each of the affected folder. The ransom note demands 0.18 Bitcoins to be sent to the specified address, and also offers free test decryption. According to cybercriminals, after the payment is processed, victims should contact them via bakfiles@protonmail.com. In early December, hackers came back with FilesLocker ransomware v2.0 which appends [fileslocker@pm.me] file extension. Later that month, a new “Christmas Edition” virus came out and loaded up a Pastebin that contains master RSA key, which consequently led to a decryptor development.[1]

Name FilesLocker ransomware
Also known as FilesL0cker RAN$OMWARE
Type Cryptovirus
Versions FilesLocker ransomware v2.0
File extension .locked, .[fileslocker@pm.me]
Ransom note

#解密我的文件#.txt

#DECRYPT MY FILES#.txt

Targets Chinese and English-speaking users
Contact email bakfiles@protonmail.com, fileslocker@pm.me
Ransom amount 0.18 BTC; 0.15 BTC (v2.0)
Distribution Spam email attachments, exploits, brute-force attacks, etc.
Decryptable? Yes, .[fileslocker@pm.me] variants. Download decrytor from here [WARNING! Direct download link]
Elimination Use FortectIntego and fix virus damage after FilesLocker ransomware removal

FilesLocker ransomware has no difficulty to spread around the world because it has been set to use ransom notes written in English and Chinese languages.[2] The whole file encryption process is fairly quick – it only takes three seconds to complete.[3] 

As a result, the victim cannot use photos, videos, documents, and even the whole network once the attack is finished. The only way to recognize the infection is by looking at the file extension .locked appended at the end of each file name. However, paying the ransom is not the best solution since cybercriminals are not trustworthy.

The best way to release your data is to recover lost files from a backup. If you have your important files stored on cloud services or an external device, you can replace encoded data with the safe copies. However, you need to remove FilesLocker ransomware from the system first because ransomware can encrypt your newly-added files once again.

This virus is also known as FilesL0cker RAN$OMWARE. While its ransom message is typically placed on the system in both languages, we will provide the ransom note written in English: 

FilesL0cker RAN$OMWARE
########################################### 
All your important files(database,documents,images,videos,music,etc.)have been encrypted!and only we can decrypt!
To decrypt your files,follow these steps:
1.Buy 0.18 Bitcoin
2.Send 0.18 Bitcoin to the payment address
3.Email your ID to us,after verification,we will create a decryption tool for you.

Email:bakfiles@protonmail.com
Payment:3EZGS8P439PbBeiWjsGYjSSaRHn9CXKDRQ
Your ID: –

FilesLocker ransomware

You need to get rid of the virus before attempting any data recovery. No matter how little the ransom amount looks, it is worth more than $1100 at the moment of writing. Keep in mind that FilesLocker ransomware is a product of hackers who have one goal – extorting money from their victims. We, like any other cybersecurity expert team,[4] recommend staying away from these dangerous people. 

If you got infected, make sure to perform FilesLocker ransomware removal using reputable anti-malware of your choice and then clean the system with system repair tools like FortectIntego. This is an important step because various intruders may affect the performance of your computer in different ways and programs like these can fix the system damage.

Also, when it comes to encrypted files and data encryption, you have the only solution – restore encoded data. You can find a few file recovery methods and software suggestions down below the article. Remember that ransomware is a dangerous cyber threat that tends to be persistent, so you may need to enter the Safe Mode before scanning the device. Follow our instructions and eliminate FilesLocker ransomware for good. 

Free decryptor for [Fileslocker@pm.me] encrypted files

On 29th of December, security researchers discovered[5] a “Christmas” version of FilesLocker ransomware. Similarly to previous versions, it encrypts files with a strong cipher, drops ransom notes in both, English and Chinese languages, changes the desktop to a Christmas-themed wallpaper and demands 0.3 Bitcoins to be paid to retrieve data. 

However, as soon as file encoding procedure is complete, FilesLocker Christmas Edition does something unexpected: it opens a Pastebin URL which also displays the RSA key inside. This key can be used for both, v1 and v2 viruses.

Upon discovery, independent security researcher Michael Gillespie managed to create a functional decryptor which allows users to retrieve data for free. You can download the tool from [direct link follows] here.

FilesLocker ransomware decryptor

Unfortunately, those who use Microsoft's Defender might find it blocked as it is detected as a trojan.[6] We do not take any responsibility for the decryptor's functionality or any other consequences, so please use it at your own risk. In order to download the decryptor, disable Microsoft anti-virus temporarily.

Indeed, it is surprising that cybercriminals decided to give Christmas present to the victims of their ransomware. Nevertheless, the added a small note at the end of Pastebin message:

The end is just the beginning

Hackers might have been feeling festive, but somehow the message hints on more malware variants in the future.

Ransomware payload is hidden on spam email file attachments

The most common distribution technique used by malware creators is spam email campaigns. It is an easy way to spread viruses around the web and infect target devices without spending much time on social engineering. 

The email filled with ransomware may look legitimate and safe because it tries to pretend to belong to a known company or service. However, this is the method hackers use for tricking people. Users tend to believe the legitimacy of MS Word or Excel file received thru an email with the subject line “Financial information.” 

Pay more attention to what is said in the message and stay away from it if you spot these signs:

  • many typos or grammar mistakes;
  • not matching company names on the email and file attachment;
  • a sender is a service you are not using;
  • you cannot answer the email back;
  • file attachment is called “Order information” or “Invoice.”

Clean your email box more often, keep your anti-malware tools up-to-date and make sure that you are not installing any suspicious software on the device during installation processes. 

Terminate FilesLocker ransomware or any other malicious programs

When it comes to products from crypto extortionists, the main danger is the loss of all your data saved on the system. Because of this fact, you need to remove FilesLocker ransomware without wasting your time and postponing this procedure. Run a full system scan with your reputable anti-malware and get rid of infected files. If you haven't employed such a tool to keep your system safe, feel free to use one of our suggestions. 

Use FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes after FilesLocker ransomware removal and fix remaining virus damage or get rid of any malicious files or programs that may still affect the system of your computer and interfere with data recovery. After the double-checking, you can attempt file restoring using the method of your choice. Follow our methods step-by-step and get rid of the threat completely.

Be the first to comment

Read in your language

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.