Relock ransomware virus urges to contact the criminals for a decryption tool

Relock ransomware is a file-encrypting virus that blocks the access to your data and demands a ransom. Analysts believe that it might be a new variant of an infamous Matrix ransomware. After the infiltration, victims receive a !OoopsYourFilesLocked!.rtf ransom note and are urged to pay a ransom since it states that the amount of payment increases every 12 hours. Criminals provide relock001@tuta.io and relock001@yahoo.com e-mail addresses for contact purposes.
Hackers warn people not to use alternative decryption tools as it will only lead to permanent damage of the data. To gain victim’s trust, they offer a free decryption of 3 files. They must not be bigger than 5 MB and shouldn’t contain valuable information.
However, we neither encourage you to trust the criminals nor purchase useless decryptors online. Malevolent people aim for quick profits and usually do not keep their promises[1]. Instead, start a Relock removal immediately and try to recover your files using alternative methods.
ZonderVirus.nl[2] experts discovered that the malware only encrypts documents and archive files. However, they use sophisticated algorithmic methods and leave the data completely corrupted. Relock virus blocks the access to your files by appending _[RELOCK001@TUTA.IO].* file extension. Therefore, we always suggest keeping backup copies in case of ransomware. If you store them in the cloud or another external device, you should be able to quickly retrieve them and avoid financial losses.
According to the VirusTotal.com analysis, Relock virus is recognized as VJdbqn9n.exe_ and successfully detected by anti-malware software. Therefore, we strongly recommend not to try to remove Relock ransomware by yourself. You should employ a professional security system such as FortectIntego and get rid of the file-encrypting virus automatically.

Crooks use malspam campaigns to distribute ransomware
One of the most popular methods used by cybercriminals to distribute malware — send spam e-mail messages containing a malicious attachment[3]. It is set to download an executable file of the malware as soon as the victim opens it.
Developers often design those letter to look extremely genuine and gullible people are tricked to install ransomware unconsciously. Spam e-mails may be sent from reputable institutions or campaigns that provide useful services. You can encounter virus sent as a fake invoice or another document.
Thus, we encourage you to be extremely careful when opening messages from unknown senders. Be aware that crooks may also hack into social networking accounts and spread the infected links. In case of a suspicious letter, do not click on it and always contact your friend in person and make sure that his or her account is safe.
Get rid of the Relock ransomware with the help of an anti-malware program
You can remove Relock virus by employing a trustworthy security software. However, ransomware developers may set it to block the installation of the anti-virus system. Therefore, you should reboot your computer to Safe Mode and then run a full system scan.
If you want to start a manual Relock removal, follow the guide provided below. This way you will safely eliminate the virus and do not cause more damage to your files. Shortly after, you will be able to try to recover your data. There are several alternative methods which can help to bet back the access to your files, and you can check them at the end of this article.
Was this guide helpful?
Be the first to comment