Check out our video library AppCheck defending against newest ransomware, automatic recovery and real-time backup.

FilesLocker Ransomware (.locked)

  • Distribution Method : Unknown
  • MD5 : d1c2f79125818f1e7ea16784acf63712
  • Major Detection Name : Generic.Ransom.WCryG.B6E79C46 (BitDefender), Ransom:MSIL/BlackHeart!MTB (Microsoft)
  • Encrypted File Pattern : .locked
  • Payment Instruction File : #解密我的文件#.txt / #DECRYPT MY FILES#.txt
  • Major Characteristics :
     - Offline Encryption
     - The Chinese and English users targeted
     - Disable system restore (vssadmin.exe delete shadows /all /quiet)
     - After encryption, connects to website ( and displays message with image (5b88484028ab1.png)