Minotaur ransomware – malicious cryptovirus that uses .lock file extension to mark its encrypted files

Minotaur ransomware — a cryptovirus that appends a well-known extension to the encrypted data called .lock. Ransomware threats like Lock virus or .Locked files virus have already been using this extension for some time now. Once Minotaur encrypts its target files with the AES algorithm, it starts displaying a ransom note called How To Decrypt files.txt. The ransom warning reveals more details about the particular attack and identifies the 0.125 BTC amount which is required to pay to recover files encrypted by the virus. The main virus executable is called Minotaur.exe. The minute it gets on the system, it checks the location and the state of a device. Then, the file-locking process starts.
| Name | Minotaur ransomware |
|---|---|
| Type | Cryptovirus |
| File extension | .lock |
| Ransom note | How To Decrypt files.txt |
| Ransom amount | 0.125 BTC |
| Main file | Minotaur.exe |
| Distribution | Spam email attachments |
| Elimination | Install and use FortectIntego for virus damage repair after Minotaur ransomware removal using your antivirus |
Once Minotaur ransomware virus gets on the system, it starts running in the background of the system. However, the main malicious behavior stays unnoticed until your data becomes useless and ransomware marks locked files with the help of the .lock file extension.
After the fast encryption[1] process is finished, ransomware forms a message for its victim which is saved in the file called How To Decrypt files.txt. Minotaur virus focuses on English-speakers and displays only a few details in this note, including the ransom amount (0.125 BTC) and the email address provided for contacting its developers (called minotaur@420blaze.it).
Minotaur ransomware ransom note reads the following:
—————————————————————————————-
(KEY): J3oLtCrE14E****
(EMAIL): minotaur0428blaze.it
—————————————————————————————-
ALL YOUR FILES ARE ENCRYPTED BY (MINOTAUR) RANSOMWARE!
—————————————————————————————-
FOR YOUR FILES DECRYPT NEED TO PAY US A (0.125 BTC )!
—————————————————————————————-
SEND YOUR (KEY) TO OUR E-MAIL FOR SUPPORT!—————————————————————————————-
You need to remove Minotaur ransomware immediately after receiving such note on your desktop. Do not think about paying the ransom or contacting these criminals at all because this is a straight way to the money loss. Even though the ransom amount looks not a big deal to you, there is no guarantee that your locked data will be decrypted after you send your payment to cybercriminals. Also, researchers[2] claim that they have no information about the existing decryptor from the developers of this ransomware.
Minotaur ransomware removal is a procedure that needs to be done before trying to recover your locked files. If you tried to replace your encrypted data from backup, beware that ransomware on your computer could try to affect your files once again. Make sure you use a reputable anti-malware program in the elimination of this virus. Try FortectIntego as an alternative scanner to repair the damage after virus termination.
Remember that there is no decryption tool developed for Minotaur ransomware encrypted files yet, so your best option is to employ data recovery steps provided by our experts or replace files with safe copies from a backup. If you have no backups, try software selected by our experts for file recovery.

Ransomware distribution methods are similar to widely-used practices
The malicious payload of these crypto-extortionists can be loaded on the device directly or with the help from other malware. However, most of these intruders come from safe-looking documents as spam email attachments which are infected with macros[3].
A malicious virus can land on the system immediately after the file is downloaded and opened on the infected machine. If you do not pay enough attention to emails, you recently opened you may be in danger. Trojans, malware, ransomware itself affect the system without your content or knowledge.
You can avoid cyber infections if you choose wisely which emails to open freely without thinking and which not. If your email box gets filled on a daily make sure to look out for these details:
- subject line says “invoice” or “financial information”, “order”;
- the email contains MS Word or Excel file;
- there are typos or grammar mistakes in the main message;
- here is no clear connection between the sender and the file attachment;
- you have never used the service or company the email is sent from.
Minotaur ransomware elimination tips
The most important thing you need to know about Minotaur ransomware removal is a need for professional anti-malware software. Do NOT try to get rid of the cryptovirus manually because it affects different components on the system as soon as it infiltrates it. To find all these components, you should employ programs designed to fight against such threats.
Once you get rid of malicious files, check if the ransomware didn't affect your computer's registry. Run FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to make sure that the malware is fully eliminated. Programs like these will also indicate if there is any additional malware hiding in your PC system.
Once you remove Minotaur ransomware, try data recovery options provided below. Double-check if the system is clear and then try file recovery methods from down below. Creating file backups on various platforms can be helpful to prevent such losses in the future.
Did this guide help?
Be the first to comment