Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2017

How to remove Flotera ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

The third version in Polski ransomware trilogy – Flotera ransomware virus

Flotera virus is a malicious computer program that we have added to ransomware category. This virus appears to belong to Polski ransomware group. It must be said that Flotera ransomware is almost identical to Vortex ransomware – both ransomware viruses use AES-256[1] to encrypt files on the available drives, and both of them use .aes file extension to mark encrypted files. Following the encryption procedure, Flotera creates !!!-ODZYSKAJ-DANE-!!!.TXT file, which malware researchers identify as the “ransom note.” This text file contains the message that cyber criminals wrote for the victim. Ŧl๏tєгค гคภร๏๓ฬคгє authors say that files on the system were corrupted and that they are the only ones who can help to restore them. Of course, not for free. Cyber criminals[2] demand a ransom, which reportedly ranges from $199 to $299. Flotera developers promise to increase the price by 100% in case the victim fails to collect money for the ransom within four days. Crooks tell the victim to write to one of those emails in case one decides to pay the ransom – flotera@2.pl or flotera@protonmail.ch and wait for further instructions. We do not advise you to pay the ransom – instead, we suggest you remove Flotera virus using anti-malware programs like FortectIntego. A full ransomware Flotera removal guide is provided at the end of this page. Flotera ransomware virus

Flotera ransomware, just like Vortex virus, is based on open-source encryption and decryption software AESxWin, which is published on GitHub. The author of the three Polish ransomware variants had modified the code of the encryption tool before using it for the ransomware project. Therefore, once the ransomware is run on the victim’s computer for the first time, it displays a pop-up “AESxWinAuto” which asks if it should run at startup. If the victim clicks Stop, the ransomware won’t be executed. Otherwise, it begins the encryption routine. The ransomware then connects to a public API[3] and gets an encryption key that consists of 120 characters, then connects to another API to get user’s IP address. Such information immediately gets transmitted to criminals’ servers. If by any chance you use a network traffic tracking program, you could find the encryption/decryption key in the logs and use it for data decryption. Unfortunately, users typically do not install such tracking software on their PC’s.

How did this ransomware infiltrate my computer system?

Unlike the majority of ransomware viruses, Flotera isn’t distributed using same malware propagation means. Instead of attaching it to phishing emails or spreading it alongside pirated software packs, authors of this ransomware tend to install it on computer systems manually. It appears that the virus can be downloaded to the system with the help of vjw0rm Remote Access Trojan (RAT)[4], which is distributed via several spam campaigns targeting Polish computer users. This Trojan gives attackers access to control victim’s system remotely; therefore they can install the ransomware manually.

How can I remove Flotera ransomware from my computer?

In the ransom note, cyber criminals advise the victim not to use antivirus programs because “the virus deletes itself as soon as it encrypts files.” However, you should not trust them and scan the system with anti-malware tool to detect and remove Flotera remains as well as the described vjw0rm Trojan[5]. You can find instructions on how to launch your anti-malware program properly down below. We suggest you not to attempt to remove the malware from the system manually because this way you can create more problems than you can imagine. To clear your PC from malware, follow these steps:

4 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.