CryPy spin-off SintaLocker demands 100 dollars for data decryption
SintaLocker is a newly discovered ransomware virus [1] which originates from the CryPy virus family. The virus code is written in Python and is specifically designed to execute AES encryption [2] on the infected computer’s files. You can notice the Sinta Locker infection right away — the desktop of the infected device will be replaced with an image called mood-ravishing-hd-wallpaper-142943312215_en.jpg which is taken from a free website called wallpaperrs.com. The parasite does not seem to add any extensions to mark the affected files, nevertheless, after the encryption process is over, the affected documents, archives, media files, images, and other data will be inaccessible. Unfortunately, they are likely to stay that way after SintaLocker removal as well. Their recovery may be possible by applying some alternative techniques, nevertheless, you will most likely have to wait for the security experts to come up with a free decrypter in order to decrypt your entire system. Of course, the extortionists will provide their own instructions how to decrypt files. These guidelines are set forward in the ransom note called README_FOR_DECRYPT.txt. This note contains the following message:
All your files are encrypted by with strong chiphers.
Decrypting of your files is only possible with the decryption program, which is on our secret server.
All encrypted files are moved to st directory and renamed to unique random name.
To receive your decryption program send $100 USD Bitcoin to address:
17ynRL2FPW3V7xknUW59vNd7HP5RXJGss9
Contact us after you send the money:
oxo.foxo@yandex.com
Just inform your identification ID and we will give you next instruction.
Your personal identification ID: ***
—
__SINTA I LOVE YOU__

The ransom payment in virtual currency, especially Bitcoins, ensures privacy for the extortionists and protects them from being tracked down and prosecuted. This means that the criminals have no responsibility towards the victims and could simply vanish with their money without issuing the promised decryption tool. So, there is no point contacting them via oxo.foxo@yandex.com or any other email address that may be indicated in the ransom note. To guarantee the success of the attack, SintaLocker will disable the Windows Restore function and mess with the Windows registry, but that does not mean you will not be able to remove SintaLocker from your computer. With a little help from a professional antivirus software such as FortectIntego, the virus will be gone from your PC in no time. So, download the tool and get started!

The best ransomware prevention technique
SintaLocker is currently in quite a lethargic state of distribution — there are only a couple of reports about its attacks. This is good news because it means we have more time to prepare for the ransomware prevention. It is much easier to protect your data rather than recover it after encryption. Thus, we highly recommend creating backup copies of your important files and regularly updating them. This way you will don’t have to worry in case your PC gets unexpectedly corrupted. What you will have to do is remove the virus and restore your files from backup. An important thing to remember is that you must keep the storage devices on which you backup your data UNPLUGGED from the PC when not in use. If these devices are plugged in during the ransomware attack, SintaLocker will easily encrypt files on them.
Recommendations for SintaLocker removal
Most security experts will agree that the safest and quickest way to remove SintaLocker virus from the corrupted device is automatic system scan with a trusted antivirus. This essentially means that the program you are using for the virus elimination should be legal, capable of sophisticated malware detection and elimination as well as compatible with your device. If you already own such a utility, don’t forget to update it to the latest version as well. If you don’t own one yet, we recommend checking out the Software section of our site where you will find comparisons of today’s most popular and acknowledged security utilities. We hope this guide will help you pick a reputable malware removal tool and perform a thorough SintaLocker removal.
Did this guide help?
Be the first to comment