Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2017

How to remove Ykcol ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

Locky is currently distributed as Ykcol ransomware virus – protect your computer now!

Ykcol ransomware virus

Ykcol ransomware is the latest strain of the infamous Locky ransomware. It follows previously released Lukitus and Diablo6[1] versions and uses a combination of RSA-2048 and AES-128 ciphers to lock victim’s files. The virus appends .ykcol file extension to every encrypted file and drops ykcol.bmp and ykcol.htm files on the desktop.

Locky’s developers chose the new name for the ransomware by simply reversing the name of the initial virus backward. The malicious software is currently being pushed via malicious spam[2] that delivers a compromised attachment containing a script that downloads and executes Ykcol virus on the system.

After hijacking the system, the malicious virus drops to aforementioned files that function as ransom notes. The BMP file will be set as desktop’s wallpaper while the HTM file opens via web browser and provides links leading to user’s personal payment page (accessible via Tor browser only). In order to view contents of the personal payment page, the victim has to download the aforementioned browser and enter the .onion website via it.

The payment page on Tor network presents “Locky decryptor” which is the decryption tool offered by the ransomware authors. While previous versions of the virus used to demand half a Bitcoin to set all files free, Ykcol malware asks for 0.25 Bitcoin.

However, since the Bitcoin’s value has been increasing, this amount is now approximately equal to more than 1000 US dollars, which is a high price for data decryption.

Cybersecurity experts recommend ignoring criminals’ demands and using available data recovery methods instead of paying cybercriminals. Currently, there is no news regarding successful data recovery attempts, so at the moment the only efficient data restoration method is to use a backup.

Locky virus is now calling itself Ykcol

NoVirus.uk[3] strongly recommends you to remove Ykcol virus from your computer as soon as possible. The recovery after a ransomware attack requires time, and in order to use your PC safely again, you must get rid of the malware before doing anything else. Use a trustworthy program like FortectIntego or MalwarebytesMalwarebytes to clean your PC. In addition, you will need to reboot your PC in Safe Mode with Networking to eliminate the new Locky version.

Start Ykcol removal by reading the directions provided below the article. Once you learn how to prepare your PC for this task, you should do it immediately. Once your PC is in a safe mode for malware removal, run anti-malware software to find the malicious files and delete them. Also, we would like to remind you to update your security software before scanning your PC for malware.

Currently used distribution methods that spread Locky ransomware

All variants of Locky are typically distributed via mail spam, and Ykcol virus is no different. The latest variant of ransomware is being pushed via malspam campaign that delivers fake 7Zip attachments with a .vbs file inside of them. The malicious emails are again based on the fake invoice theme. The emails with malicious attachments will kindly ask the victim to review “attached invoice” and let the sender know about the status of it.

The compromised attachment is named with a set of random chars and contains a VBS file that, once opened, connects to one of remote servers and downloads Locky payload from it. Following a successful download of the ransomware, the VBS file runs it. As a consequence, the victim loses all of his files immediately and faces ransom notes left by cybercriminals.

The authors of this virtual extortion tool have been using a variety of different malware distribution techniques, but so far it seems that phishing and malicious spam is their go-to combo that they use to deceive victims. Locky’s developers rarely change the distribution tactics as so far it seems that their methods are working quite well.

Remove Ykcol virus right now

In case the latest Locky’s version attacked your PC and compromised your files, the first thing you need to do is to remove Ykcol virus from the system. Unfortunately, the malicious software can refuse to enter your computer so easily, so you will need to use programs developed by IT experts to identify and kill it.

Ykcol removal might be complicated because this malicious software aims to avoid detection using professional obfuscation techniques. However, if your security software did not manage to stop it from encrypting your files, you must update it and remove remains of Locky malware right now. This will secure and protect your computer from illegal activities that the virus might be trying to implement.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.