Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2021

How to remove Lick ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

Lick virus is a new Kirk ransomware version – get to know how this ransomware operates

Lick virus is a complex computer program that falls into the ransomware category. The appearance of this ransomware simply proves the fact that this illegal industry is booming[1]. When comparing similarities between the ransomware and Kirk virus,[2] it was determined that these two viruses are closely related or even developed by the same ransomware gang[3]. They are both created using Python[4] programming language.

Once installed, malware would encrypt all data, appending .Licked extension to each of the personal files such as documents, videos, pictures, etc. These files would be later listed in a generated stats.txt message; ransom demands would be shown in the ERRORLOG.txt ransom note.

Name Lick ransomware
Type File-locking virus
Programming language Python
Extension .Licked
Ransom note ERRORLOG.txt
Removal Perform a full system scan with SpyHunterCombo Cleaner anti-malware software
System fix Use FortectIntego to remediate Windows system files and repair virus damage

The ransomware is a sneaky virus that displays a pop-up message once executed. The message says:

File Decrypter is initializing for your system. This may take some time. Click ‘Ok’ to close this dialog box and wait for the ‘Finished’ popup.

If this message popped on your screen, shut down your computer and unplug the Internet cable immediately! You will need to remove Lick ransomware in the Safe Mode with Networking, so open this page via your phone or another device and follow the virus removal guidelines given below this text.

Once you boot your PC in the indicated mode, download and install SpyHunterCombo Cleaner or another malware removal tool for a successful ransomware elimination. While personal files might be difficult to return, system files can be easily fixed and restored with the help of FortectIntego repair software.

Lick ransomware version

If the malware manages to corrupt all files, you will notice additional file extensions added to their filenames (after the original file extension, for instance, examplepicture.jpg.Licked). The ransomware creates a file called ERRORLOG.txt, which lists the locations and the names of files that were encrypted.

It also creates a file called RANSOM_NOTE.txt, which is a text version of the message from the cybercriminals. It then launches a program window that contains some ASCII art and a message, which starts with not so uplifting line:

Thanks for your patience! Finished. Malware infection. Read this! Oh no! The Lick ransomware has encrypted your files!

The virus says that the computer has fallen victim to the Lick malware, and all files were encrypted. It shows the number of total encrypted files, a list of targeted extensions, and asks to pay a ransom in Monero[5] currency, which is surprising, considering that viruses typically ask to pay a ransom via the Bitcoin system.

The virus provides the price chart: if the victim pays the ransom within two days, the data decryption costs 50 Monero; if the ransom is paid in 3-7 days, it costs 100 Monero; if between 15 to 30 days – 500 Monero.

The ransomware crooks demand to make the payment, then create an email message to them, including the encrypted file with decryption password in it (pwd file) and victim’s ID, and send it to one of the following email addresses:

  • kirk.payments@scryptmail.com;
  • hanna.harrington@scryptmail.com.

Beware of spam email attachments and links

Rumor has it that this ransomware is distributed via email spam, so we suggest you be extremely careful when checking new emails. Make sure you stay away from all suspicious content that unknown individuals send you. Remember that scammers take advantage of social engineering peculiarities and trick users into opening malicious links or email attachments by adding a short message to spam emails.

Such message is intended to arouse the victim’s curiosity, so, for example, scammers can kindly suggest you view attached contents, which can be obfuscated in the form of an invoice, resume, payment details, or another document that looks safe to open. Once opened, the file drops the ransomware infection. Alternative ransomware distribution methods include exploit kits, malware-laden ads, and others.

Malware elimination and file recovery options

The virus will hold your files secured until you pay a ransom. This extortion tool promises to restore your files as soon as you pay the required amount of money, however, we strongly advise you not to pay the ransom to these cyber crooks.

They might never deliver the decryption guide to you, so do not get your hopes too high. You can restore the majority of your files from a recently created backup, but if you forgot to create it, you could try one of the data recovery methods explained below.

We highly recommend using anti-malware tools for Lick ransomware removal because manual malware removal is a time-consuming task, besides, you might delete only a part of ransomware-related files, which would leave your computer system vulnerable for further malevolent encroachment on your PC.

If you had a data backup, you could use it as soon as the malware removal procedure is finished. If you did not create a data backup in the past, you have two choices – pay the ransom (not recommended) or remove the virus and try to recover your files by yourself.

It is a very hard thing to do, besides, we suggest experimenting on copies of encrypted data(for example, create a copy of encrypted files and move it to an external hard drive – it might come in handy if malware analysts ever create a decryption tool).

Did this guide help?

4 comments

  1. whatheheeell

    i swear, people who create ransomware names are a bit insane.

  2. Bass

    It demands $299 from me. NOT GONNA PAY!

  3. Serane

    This infected our computer network yesterday. I felt so bad because of this. We could not continue work for at least half a day...

  4. Vladivostok

    Thanks for explaining. I removed the virus with reimage, now trying to find that old backup that I created ages ago...

Read in your language

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.