FLKR ransomware is a crypto malware that is seeking to make victims' files useless

FLKR ransomware – a malicious cryptovirus which has been targeting victims from all around the world. It is designed to encrypt files with Blowfish symmetric-key block cipher[1] and make them inaccessible. Additionally, all encrypted files are marked with the following extensions:
- ._morf56@meta.ua_
- .+jabber-theone@safetyjabber.com
- .__murzik@jabber.mipt.ru
Victims who want to get their files back are urged to reach the hackers via morf56@meta.ua or fhmjfjf@default.rs email addresses. However, if you don't want to get scammed, use anti-malware software to remove the virus and then recover your files from backup.
| Name | FLKR |
|---|---|
| Type | Ransomware |
| Extension |
|
| Ransom Note | INSTRUCT.txt; INSTRUCTIONS.txt |
| Email address | morf56@meta.ua; fhmjfjf@default.rs; murzik@jabber.mipt.ru |
| Decryptable | No |
| Distribution | Malspam campaigns, rogue websites |
| Elimination | FortectIntego is the best tool to uninstall FLKR virus |
Unlike other viruses, FLKR doesn’t pay much attention to .txt, .mp3, and .avi files, as it doesn’t consider them valuable. However, it can encrypt documents, databases, programs and other data. Once the main programs’ component – flkr.exe file finishes its dirty job, an INSTRUCT.txt file is created.
This file stores the short message from authors of the virus, which state that all information on the compromised computer is encrypted “with a strong” password, and those who want FLKR decryptor should get in touch with the criminals via indicated email addresses and be prepared to pay the ransom.

In case the victim doesn’t get a response from criminals after writing to the given email, one can use an alternative communication channel and get in touch with culprits via Jabber, also known as an IM service which is based on XMPP[2]. Here is the extract of the ransom note by FLKR virus:
Information is encrypted with a strong password.
To decrypt it e-mail: morf56@meta.ua for instructions.
Reserve communication channel – this jabber: fhmjfjf@default.rs
Use jabber only when conversation via email is not possible
However, we can save you some time and inform you about what is going to happen next. Criminals will ask you to buy digital currency, usually, Bitcoins, and send them to them as a ransom. The ransom price is likely to be high (starting with $500 or so and up), but chances to recover files will be low.
First of all, criminals rarely decide to help victims and do anything to restore their files. Besides, by paying the ransom, you would encourage them to spread the virus further — so please, do not do that! Victims already are getting aware of ransomware menace and paying less ransom than before, so it would be great if you would join this fight against ransomware as well.

Therefore, instead of wasting your hard-earned money on criminals, consider removing the virus with a proper anti-malware tool. For FLKR removal, use a good anti-malware program, for instance, FortectIntego. This is the safest method to get rid of this dangerous cyber threat as it is sophisticated and designed to corrupt Windows Registry. This results in more complicated elimination procedure.
We do not recommend you remove FLKR virus manually since it will most likely result in computer damage. However, if you are unable to download security software, immediately check the instructions below showing how to deactivate the ransomware. Additionally, there are ways how you can get back the access to your files without paying the ransom.
The new version of the ransomware targets Russian-speaking computer users
Cybersecurity researchers have recently noticed a new version of FLKR ransomware which is designed to infect computers in Russia particularly. According to the analysis, it appends .__murzik@jabber.mipt.ru extension after the data is encrypted and drops INSTRUCTIONS.txt ransom note.
The message is written in Russian language as the following:
Хотите расшифровать Ваши файлы? Пишите на джаббер (xmpp): murzik@jabber.mipt.ru (можете писать в оффлайн если нас нет в онлайне) Ваш PIN: [redacted 2 numbers]
Once again, the hackers encourage their victims to reach them via murzik@jabber.mipt.ru on Jabber. Although, now people can also get in touch with them offline, by using the indicated PIN. Despite the fact that it is currently unknown how much money the attackers demand to pay, we want to warn you not to pay the ransom!
Ransomware distribution techniques explained
Even though there are numerous information sources, saying how to protect against ransomware attacks, people continue to stay inattentive and infect their computers with this dangerous threat. Likewise, we want to explain you one of the most common ways how ransomware spreads. Here are some of the distribution techniques:
- Exploit kits;
- Malicious online ads;
- Malspam campaigns;
- Infected software-bundles.
Most of the cyber threats are distributed via malicious spam emails. Therefore, computer users should be extremely cautious when opening and clicking on the content of the letter. There is a high risk that it might hold an innocent looking file which is, in fact, the payload of the ransomware.
Also, BedyNet.ru[3] experts encourage you to stay away from shady-looking websites that aggressively suggest you play a particular game, fill out a survey, or install specific plug-ins or applications. If you feel that a particular Internet site desperately wants you to do something or add something to your computer, better be careful. You risk installing untrustworthy programs and infecting your computer with useless apps!
Learn how to uninstall FLKR virus safely
If you believe that you can remove FLKR on your own, we would like to warn you about the potential threats and encourage to choose a more reliable way — automatic elimination. Unfortunately, this dangerous malware can be programmed to infiltrate the system with other malicious programs that you will not be able to identify.
Therefore, complete FLKR removal requires not only specific IT skills and knowledge but also time. For this reason, we suggest you save your precious time and ensure the malware elimination to professional security software. These products are designed to help novice computer users and protect their systems at all times.
You can uninstall FLKR virus with FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. However, if you cannot install the antivirus, the malware might be still active. Learn how to deactivate the ransomware by following the instructions below and later you will be able to recover the encrypted data without paying the ransom.
Did this guide help?
4 comments
Lora
This is so frustrating... where the decryption tool... I saw some hiddentear based viruses can be decrypted... whats up with this one???
Garrix
HiddenTear is open-source. It is possible to decrypt files that are locked by amateur-level viruses. This one is not based on HD... So here we are here, with those useless encrypted files.
freddo
I am so angry. I have emptied my hard drive and gave it to a friend to transfer some data. I dont have a backup, and I am more than nervous!!
Norw190
Thanks... Removed the virus but still strugglin with the decryption