Desktop is locked with a message about How to pay to unlock your system. Files named such as ‘README_LOCK.TXT’, ‘#_README_#’, ‘_DECRYPT_’ or ‘recover’ in each folder with at least one encrypted file.
When you try to open your file, Windows notifies that you do not have permission to open this file. Of course, decryption of single file cannot guarantee that, after paying the ransom, the victim will be able to recover files affected with the ransomware.Ĭrypto malware, File locker, Crypto virus, Ransomware, Filecoder Attackers offer to decrypt single file for free. The ransomware authors demand a ransom in exchange for a key and a decryptor. The ransom demand message said that the victim’s files are encrypted. You can ask SUPPORT for the TEST-decryption for ONE file!Ĭriminals use the “README_LOCK.TXT” file to demand ransom from the Corona-lock ransomware victims. HOW to understand that we are NOT scammers? To get RSA private key you have to contact us via email to: If you want to decrypt your files, you have to get RSA private key. They will just contact us, buy the key and sell it to you at a higher price. These tools can damage your data, making recover IMPOSSIBLE.Īlso we recommend you not to contact data recovery companies. WE STRONGLY RECOMMEND you NOT to use any Decryption Tools.
The full text of this file is:ĭON’T WORRY! YOUR FILES ARE SAFE! ONLY MODIFIED :: ChaCha + AES This file contains a message from the ransomware authors. The CovidWorldCry (corona-lock) ransomware creates a file with the name “README_LOCK.TXT” on the infected computer. The associated program will not be able to read its contents.ĬovidWorldCry (corona-lock) ransom demand message Removing the extension or renaming the file will not help access the contents of the file. For example, if a file had the name ‘document.doc’, then after this file is encrypted by this ransomware, it will have a name similar to the following ‘-lock’. Each file that has been encrypted is marked, the ransomware appends the ‘.corona-lock’ extension to its name. The Corona-lock ransomware encrypts the contents of all disks file by file. itlĪll documents, photos, archives located on local disks, system disks and connected network drives will be encrypted. The following common file types can be encrypted: Upon execution, the Corona-lock ransomware collects information about the computer and then proceeds to encrypt the files located on it. As other ransomware, it can use the same distribution methods (spam emails, adware, cracks, key generators and so on). It appends the ‘.corona-lock’ extension to each file that it encrypts using a complex encryption mechanism.
corona-lock extension What is CovidWorldCry (corona-lock) ransomwareĬovidWorldCry (corona-lock) ransomware is a new malware that belongs to the category of ransomware.