Security Stronghold security made easy

How to remove KoreanLocker Ransomware and decrypt .locked files


* What is KoreanLocker Ransomware

* Download WiperSoft Antispyware Malware Remediation Tool

* Remove KoreanLocker Ransomware manually

* Decrypt files after KoreanLocker Ransomware infection

* Protect your PC from KoreanLocker Ransomware and other crypto-viruses

* Get Professional Support

* Read Comments


Threat indicator: HIGH

Threat's profile

Name of the threat:

Command or file name:

Threat type:

Affected OS:

KoreanLocker Ransomware

KoreanLocker.exe

Ransomware

Win32/Win64 (Windows XP, Vista/7, 8/8.1, Windows 10)


------------------ koreanLocker Ransomware ------------------
당신의 컴퓨터가 랜섬웨어에 감염되었습니다
당신의 개인적 파일, 예를들어 사진, 문서, 비디오 외 다른 중요한 문서들이 RSA-2048이란 강력한 암호화 알고림즘을 이용하여 암호화 되었습니다
당신의 개인키는 우리의 서버에 생성되어 저장되었습니다
그렇게되면 그 누구도 당신의 파일을 영원히 복호화 할 수 없습니다
그리고 장담하건데 개인키가 없이는 절대 복호화가 이루어지지 않습니다
다시한번 말하지만 비트코인을 지불하는것 외해 복호화 할 수 있는 방법은 존재하지 않습니다
당신에게 할당된 비트코인 주소를 반드시 확인하세요. 한글자라도 틀리게 입력하여 보내시면 복구가 되지 않고 당신의 비트코인은 사라지게됩니다
당신은 '24시간'안에 지불하셔야합니다
당신의 개인ID(personal ID)를 반드시 확인하세요
만약 그 시간안에 지불하지 않으면 당신의 개인키는 자동적으로 우리의 서버에서 지워지게됩니다
명심하세요
비트코인 주소:1HB5XMLmzFVj8ALj6mfBsbifRoD4miY36v
비트코인 지갑을 생성하시고 우리의 비트코인 주소로 1비트코인(1BTC)를 보내주시면 됩니다.
세가지 스텝을 따라 당신의 파일을 복구하세요
시간을 낭비하시지 마세요
암호화된 파일들이 속한 폴더 안의 설명 문서 (.txt)는 바이러스가 아닙니다 설명 문서 (.txt)가 파일들의 암호 해독을 도와드릴 것입니다.
암호화된 파일들이 속한 폴더에서 파일 복원에 관한 설명 문서 (.txt)를 보실 수 있습니다
우리는 착한사람들은 아닙니다. 하지만 이야기한 부분에 있어서는 반드시 지킵니다
최악의 상황은 이미 발생했으며 앞으로 파일들의 운명은 귀하의 판단과 빠른 조치에 달려있음을 명심하시기 바랍니다
추가정보:
1).지불은 비트코인 만으로만 가능합니다. 따라서 1비트코인(1BTC)를 비트코인 거래소를 통하여 구매하세요. 그 후 화면(랜섬노트)비트코인 주소(Bitcoin Address)로 1비트코인(1BTC)를 송금하세요
2).당신의 개인 ID(Personal ID)를 아래의 공식 메일주소로 보내주세요
3).지불을 완료하시고 메일을 보내시주시면 당일의 메일로 복호화툴과 개인키를 보내드립니다
4) 비트코인을 송금하시고 메일로 개인ID(Personal ID)를 코리아 공식메일 주소로 보내주세요
***
개인키(Private Key)는 당신의 파일을 복호화하여 복구하는데 아주 중요한 키 입니다
공개키(Public key)는 당신의 파일을 암호화하는데 사용되었습니다
공식주소: www.bithumb.com
공식주소: www.coinone.com
공식주소: www.localbitcoins.com
암호화된 파일들이 속한 폴더 안의 설명 문서 (.txt)는 바이러스가 아닙니다 설명 문서 (.txt)가 파일들의 암호 해독을 도와드릴 것입니다.
비트코인 주소:1HB5XMLmzFVj8ALj6mfBsbifRoD4miY36v
Officail Mail: powerhacker03@hotmail.com
***
Best Regards
Korean Ransomware Team
------------------ koreanLocker Ransomware ------------------


KoreanLocker Ransomware

KoreanLocker Ransomware intrusion method

KoreanLocker Ransomware copies its file(s) to your hard disk. Its typical file name is KoreanLocker.exe. Then it creates new startup key with name KoreanLocker Ransomware and value KoreanLocker.exe. You can also find it in your processes list with name KoreanLocker.exe or KoreanLocker Ransomware. Also, it can create folder with name KoreanLocker Ransomware under C:\Program Files\ or C:\ProgramData.

If you have further questions about KoreanLocker Ransomware, please, contact our technical support. It is free. Or you can use programs to remove KoreanLocker Ransomware automatically below.


Download Wipersoft Antispyware

Download this advanced removal tool and solve problems with KoreanLocker Ransomware and KoreanLocker.exe (download of fix will start immediately):

Download WiperSoft Antispyware to remove KoreanLocker Ransomware

* WiperSoft Antispyware was developed to remove threats like KoreanLocker Ransomware in automatic mode. Remover has active module to protect PC from hijackers, trojans, ransomware and other viruses. Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.

Features of WiperSoft Antispyware

* Removes all files created by viruses.

* Removes all registry entries created by viruses.

* Removal is guaranteed - if Wipersoft fails ask for FREE support.

* 24/7 Spyware Helpdesk Support included into the package.


Download Spyhunter Remediation Tool by Enigma Software

Download antimalware designed specifically to remove threats like KoreanLocker Ransomware and KoreanLocker.exe (download of fix will start immediately):

Download AntiMalware to remove KoreanLocker Ransomware

Features of Spyhunter Remediation Tool

* Removes all files created by KoreanLocker Ransomware.

* Removes all registry entries created by KoreanLocker Ransomware.

* Removal is guaranteed - if Spyhunter Remediation Tool fails ask for FREE support.

* 24/7 Helpdesk Support and 5 hours of Remote Support via GoToAssist included into the package.


Let our support team solve your problem with KoreanLocker Ransomware and remove KoreanLocker Ransomware right now!

support person

Submit support ticket below and describe your problem with KoreanLocker Ransomware. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove KoreanLocker Ransomware. Trouble-free tech support with over 10 years experience removing malware.


Submit support ticket


Software Industry Professionals Member
Threat's description and solution are developed by Security Stronghold security team.

Here you can also learn:

* Technical details of KoreanLocker Ransomware threat.

* Manual KoreanLocker Ransomware removal.

* Download WiperSoft Antispyware Malware Remediation Tool.


How to remove KoreanLocker Ransomware manually?

This problem can be solved manually by deleting all registry keys and files connected with KoreanLocker Ransomware, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by KoreanLocker Ransomware. However, this threat may not allow you to do htis in some cases, thats why, we recommednd you to use one of the above options.

To get rid of KoreanLocker Ransomware, you should:

file logo

1. Kill the following processes and delete the appropriate files:

  • KoreanLocker.exe
  • README.txt

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.

**Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.

windows folder logo

2. Delete the following malicious folders:

no information

windows registry logo

3. Delete the following malicious registry entries and\or values:

no information

Warning: if value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.


How to decrypt .locked files after KoreanLocker Ransomware infection?

You may attempt to decrypt files infected by different versions of KoreanLocker Ransomware manually. Modern ransomware threats use complex encryption algorithms and try to prevent users from decrypting their files by disabling System Restore option, removing Shadow copies and previous versions of user files. However, in most cases, there is still a chance to restore your files using one of the described metods. There is also special advanced data recovery software, that can revive lost data in several clicks. This is not a guarantee for data restoration, but it is worth giving a try.

Using advanced data recovery software

recuva
  1. Download and run 'Recuva Professional'
  2. Click on the result
  3. Choose the date before the infection appearance
  4. Follow the on-screen instructions

Restore encrypted files using System Restore

System Restore constantly creates copies of files and folders before major changes in the system (windows update, software installation). You can also create restore point manually from time to time. KoreanLocker Ransomware may remove system restore files, but you can check it using following instruction.

windows system restore
  1. Click Start and search for 'system restore'
  2. Click System Restore result (Recovery in Windows 10)
  3. Choose any date before the infection appeared
  4. Follow the wizard instructions

Roll the files back to the previous version

Previous versions are copies of files and folders made by Windows Backup (if Windows Backup option is turned on) or copies of files and folders created by System Restore. You can use this feature to restore files and folders that you accidentally modified or deleted, or that were encypted by KoreanLocker Ransomware. Available only in Windows 7 and later versions.

windows previous versions of files
  1. Right-click on the file and select Properties
  2. Click on the Previous Version tab
  3. Choose the latest version and click Copy
  4. Finally, click Restore

Restore .locked files using shadow copies

shadow explorer
  1. Download Shadow Explorer and run it.
  2. Choose the drive and the folder, where encrypted files are located and date, when they were in normal state.
  3. Right-click on the folder, that you want to restore and choose Export.
  4. Select location folder for export and overview restored files.

Protect your computer from ransomware

Most of modern antivirus solutions have a module to protect from ransomware threats. However, there are also special solutions, that can detect cryptoviral activity and stop it, preventing modification of your files. One of the best is ZoneAlarm Anti-Ransomware utility, that will not use much resources for effective protection against latest ransomware threats.

zonealarm anti-ransomware
  1. Download and run ZoneAlarm Anti-Ransomware.
  2. Install it (works only on Windows).
  3. You are protected from encryption activity.

Information provided by: Aleksei Abalmasov

Next threat: Krypton Ransomware »

« Back to catalog

Home | Partners | Shop | Support | Terms of use | Contact Us | Privacy Policy | Sitemap

Copyright © 2024 Security Stronghold. All Rights Reserved. All content on this website is protected and belongs to Security Stronghold LLC.