.aa974(knoocknoo@cock.li) Virus (.aa974 File) Removal Guide

.aa974(knoocknoo@cock.li) Virus (.aa974 File) Removal Guide

What is .aa974(knoocknoo@cock.li) virus? .aa974(knoocknoo@cock.li) virus is also known as Kokoklock ransomware. It encrypts files and demands a ransom for their alleged restoration.


Kokoklock or otherwise known as .aa974(knoocknoo@cock.li) virus is ransomware. It encrypts files by appending the .aa974(knoocknoo@cock.li) extension to them, making them inaccessible. All encrypted files will receive the new extension as a secondary one. Another extension will be added before it that is generated on a random principle. The Kokoklock ransomware drops a ransom note, which gives instructions to victims on how they can allegedly restore their data.

Threat Summary

Name.aa974 virus
TypeRansomware, Cryptovirus
Short DescriptionThe ransomware encrypts files on your computer system and demands a ransom to be paid to allegedly recover them.
SymptomsThe Kokoklock ransomware will encrypt your files by appending the .aa974(knoocknoo@cock.li) extension to them, along with a unique identification number placing the new .aa974(knoocknoo@cock.li) extension as a secondary.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by .aa974 virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .aa974 virus.
Data Recovery ToolWindows Data Recovery by Stellar Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

.aa974(knoocknoo@cock.li) Virus – What Did It Do to My Computer?

The .aa974(knoocknoo@cock.li) virus is a new sample that originates from the Mailto ransomware family. This is a loose collection of viruses which may nor may not commanded from the same hacking collective as the previous versions, at the moment there is no information regarding their identity.

Related: .mailto[kokoklock@cock.li] Files Virus – How to Remove (Update Feb 2020)

It is very possible that the infections are done by using the same approach as previous samples. Most of them relied on the sending of phishing emails or scam sites which are operated by the criminals. They are usually hosted on similar sounding domain names and can include counterfeit or stolen contents from well-known web services or companies with the aim of faking them. The virus infection can also be caused by interacting with malware files which can be of these two types — macro-infected documents and setup bundles. They can be easily uploaded to these hacker-controlled sites and/or file-sharing networks like BitTorrent.

Related: Mailto Virus Ransomware (.mailto Files) – How to Remove and Restore Data

When the .aa974(knoocknoo@cock.li) virus is deployed onto a given system it will start a series of dangerous modules. The most common ones are the following:

  • Information Gathering — The main module can be programmed to harvest sensitive information about the victims and/or their computers. The collected data can be used to identify the users and reveal personal information about their habits and everyday life. The machine information can be processed by a special algorithm which will result in the generation of an unique ID for each host.
  • Persistent Installation — This is the reconfiguration of the virus in a way which will start it every time the computer is powered on.
  • System Changes — The .aa974(knoocknoo@cock.li) virus will modify key system settings. Usually this will act against configuration files and also the Windows Registry. Such modifications will lead to problems such as performance issues, data loss and unexpected errors.
  • Additional Virus Delivery — The active ransomware infections can be used to deploy malware of various kinds. They can be Trojans, cryptocurrency miners and even browser hijackers.

The .aa974(knoocknoo@cock.li) virus will run its own encryption engine when everything has finished running. Like the previous infections this is done by engaging a powerful cipher against target user data. Depending on a list of files that are to be encrypted the victim files may be different: multimedia files, backups, archives, databases and etc. They will be encrypted and renamed with the relevant .a974 extension. This time the ransom note will contain the knoocknoo@cock.li contact email and will bear the AA974-Readme.txt name.

Remove .aa974(knoocknoo@cock.li) Virus

If your computer got infected with the .aa974(knoocknoo@cock.li) Files Virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.


Martin Beltov

Martin graduated with a degree in Publishing from Sofia University. As a cyber security enthusiast he enjoys writing about the latest threats and mechanisms of intrusion.

More Posts - Website

Follow Me:
TwitterGoogle Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share