‘Locky’ is the latest addition to the ransomware family. It has an interesting name and carries the same nastiness. Read more from the post below.
What is the Locky Ransomware?
Locky is a new file-encrypting ransomware malware. It does two things:
And as most of us know, the encrypted files can be decrypted only with a key available with the cyber crook and for a price.
Who all are in the red zone?
Locky ransomware is known to target Windows users.
How does it infect a machine?
The ransomware seems to be using different spam email campaigns to spread and infect its target victims.
In one campaign, it’s been noticed that the email seems to be from a popular organization, and asks the user to download an invoice attachment (MS Word doc).
The document contains text that looks incomprehensible or unreadable. And to make the text readable, the user needs to enable ‘macros’.
If the user falls for this trick and enables the ‘macros’, a series of automatic processes is triggered which finally results in installing the Locky Ransomware on the machine.
Once inside the system, the ransomware begins encrypting whatever files it can find.
What happens next?
Once Locky is done encrypting the files, it displays a message to the user on the desktop. The message informs what has happened, and that decrypting the files is only possible by purchasing a private key from the hacker; the cost could be up to ₹ 26,558/- ($400).
What do we suggest?
How Quick Heal helps?
We have released an update to Quick Heal desktop products that prevents the attack of Locky Ransomware. Besides this, our multilayered defense mechanism helps prevent all types of malware attacks including new ransomware infections.
Email Security blocks emails carrying malicious links and attachments.
Web Security blocks websites containing hidden malware and viruses, and websites designed for phishing attacks.
Advanced DNAScan stops new and unknown malware that can cause the most damage.
Anti-Ransomware stops ransomware from encrypting any data. The feature works in multiple ways to prevent a potential ransomware attack.
We are keeping a track of the Locky Ransomware and its developments. We will keep you posted in case we come across anything important. Stay safe!
46 Comments
Security Alert! is very goods
i like
Many thanks for giving me valuable alertness message.
GD
how is rocky….that is various
this is safe and secure for our system.
thank’s quick heal
hii
Am happy to be using Quick Heal
excelent
LIKE TO QUICKHEAL
Most Useful for us
Thanks
Aman jaiswal
dangerous
Good softwir
good
thanks
Like
SECURITY ALERT
NIC
this is a great
thenks
I love it thanks
Guardian Netsecure
Hi
Thanks. This does help!!
very good
good
nice
I have renewed quick heal total securities on line through credit card payment on 29/03/2016 order no. 100699357 transaction no.60892249709 (ICICI BANK) for 1 year payment Rs.1364/- your thanks for renewal email recd .but on my pc renewal are not shown up till now kindly look in to the matter & talk necessary action in this.
Hi Hiren,
Our renewal team is looking into the matter. They will get in touch with you soon.
Regards,
Start my security
better than all…
It’s Very Nice, Thanks Quick Heal
I am facing problem with quickheal guardinier. Every day machine hangs when opening, starts from safe mode run virus clean then starting in normal mode.
Now a days it is nightmare to me.
Please do the needful at the earliest.
Hi Santanu, Thanks for writing in. Our support engineers would gladly help you with this issue. Please visit https://bit.ly/QHChat to chat with us online. You can also raise a ticket at https://bit.ly/Askus and we will get back to you at the earliest.
Regards,
Happy to get knowledge
MY QUICK HEAL SECURITY NO WORKING PROPERLY
Hi Dinesh,
Thanks for writing in. Our support engineers would gladly help you with this issue. Please visit https://bit.ly/QHChat to chat with us online. You can also raise a ticket at https://bit.ly/Askus and we will get back to you at the earliest.
Regards,
Hi,
I have been using quickheal total security for last more than 7 years. I never had a problem, 2 days ago all of a sudden all my files were renamed with .DECRYPT and i figured out it was a ransomware, i was able to quickly restore my computer to an earlier date with Acronis, now the virus has been removed from my computer and all my C: data has restored, but my entire D: & E: data has .DECRYPT, it cannot be used at all, i need these documents badly. Does Quickheal offer any tool for restoring such encrypted files ?
Thanks,
Asad Khan.
Hi Asad,
Thanks for writing in. We have shared your concern with our team. They will get in touch with you shortly.
Regards,
My system has got attacked by Locky & Word, Excel files have been damaged. Will you be able to help me in recovering the same?
Hi Mukund,
Thanks for writing in. Our support engineers would gladly help you with this issue. Please visit https://bit.ly/QHChat to chat with us online. You can also raise a ticket at https://bit.ly/Askus and we will get back to you at the earliest.
Regards,
hey i install the guardian net secure bt when i update it the virus protection is automatically disable and my net is not supported it plz help
Hi Pratibha,
Thanks for writing in. Our support engineers would gladly help you with this issue. Please visit https://bit.ly/QHChat to chat with us online. You can also raise a ticket at https://bit.ly/Askus and we will get back to you at the earliest.
Regards,
is there any way to restore a file which is infected by locky extension by scanning with quick heal
Hi Franklyn,
Our support engineers would be able to help you better. Please visit https://bit.ly/QHChat to chat with us online. You can also raise a ticket at https://bit.ly/Askus and we will get back to you at the earliest.
Regards,