Decrypt Files Encrypted by OzozaLocker and Remove It

Decrypt Files Encrypted by OzozaLocker and Remove It

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)

ozoza-locker-ransom-noteA ransomware virus was discovered in late November 2016, going by the name OzozaLocker. The virus’s payload is an executable, called CryptoSolution.exe and it uses a maliciously configured script to encrypt files using the AES encryption algorithm. After encrypting the files on the compromised computer, OzozaLocker asks victims to pay the sum of 1 BTC to restore their files. Fortunately, you do not have to pay this insane ransom, because EmsiSoft researcher Fabian Wosar @fwosar has created a decryptor that can restore your files for free. Keep reading this article to learn how to Remove OzozaLocker properly and decrypt your files without paying a dime to cyber-crooks.

OzozaLocker – Brief Analysis

OzozaLocker is a relatively new ransomware variant that is believed to slither onto victims’ computers via spammed e-mail messages that contain the malicious executable of the virus in an archive. The file may be concealed to resemble a .pdf or Microsoft Office document as well as other legitimate files, but once it’s opened the virus immediately begins to modify the computer.

The first thing OzozaLocker performs is to heavily modify the Windows Registry editor by adding the malicious executable in the Run and RunOnce registry keys so It can encrypt files on Windows startup.

After having done this, the OzozaLocker virus begins encrypting files using the AES (Advanced Encryption Standard). After it enciphers the files on the encrypted computer, the malware adds it’s distinctive locked extension, making the files look like the following:


The OzozaLocker virus then drops a “HOW TO DECRYPT YOUR FILES.txt” file to notify the user. The file has the following contents:

→ “Files has been encrypted.
If you want to decrypt, please, send 1 bitcoin to address 136X2LzDrLyR9EiEDV3zogwW5esq5DyHRB and write me to e-mail:
Your key: {custom key}”

The good news is that there has been a decryptor released specifically to help users with the free restoration of their files. Follow the instructions below to learn how to download and use it after removing OzozaLocker from your computer.

OzozaLocker Removal Manual

Before beginning any type of decryption operation, we urge you to follow either the manual or the automatic instructions below. In case you lack the experience in interfering with registry objects and concealed files, please be advised that recommendations are to download and install an advanced anti-malware program which should be able to take care of your malware problem for you.


Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share