The Dextop screenlocker ransomware is a threat that not only locks the screen of the computers it infects and displays a threatening message, but also performs numerous other activities among which are modifying system files, deleting backups and modifying the Windows Registry Editor. In case you have become an unfortunate victim of the Dextop ransomware virus, we recommend reading this article and learning how to remove it and restore files that have been encrypted with the .locked file extension added.
|Short Description||The malware encrypts users files using an encryption algorithm and locks the screen, making direct decryption possible only via a unique decryption key available to the cyber-criminals.|
|Symptoms||The user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension .locked has been used.|
|Detection Tool|| See If Your System Has Been Affected by Dextop |
Malware Removal Tool
|User Experience||Join our forum to Discuss Dextop.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
Dextop Ransomware – More Information
This threat, in proximity to other ransomware viruses may cause an infection in proximity to many other ransomware viruses out there – via spam e-mail. The threat may be downloaded via third-party infection file that is executed on the victim’s computer. Such files may come in different forms – as executable files as well as files that are documents with malicious macros that activate a script upon enabling. Such may also be in the form of fake installers or drive-by download links caused by malvertising campaigns that target unsuspecting users.
Dextop Ransomware – Infection Process
This screenlocker type of ransomware has not been so far related to any other malware threat out there, however the people who are behind it may have some experience in cyber-crime, more specifically ransomware viruses.
When the virus infects a given computer, it begins to execute malicious scripts. One of those may modify the Windows Registry Editor and hence create values with data in the Run and RunOnce sub-keys. These may allow the execution of this ransomware on the victim’s computer when Windows boots up.
After infecting a system, Dextop rasnsomware may also download it’s malicious payload, which is usually located in critical Windows folders.
Then, the virus may begin to encrypt files of the following type:
→ “PNG .PSD .PSPIMAGE .TGA .THM .TIF .TIFF .YUV .AI .EPS .PS .SVG .INDD .PCT .PDF .XLR .XLS .XLSX .ACCDB .DB .DBF .MDB .PDB .SQL .APK .APP .BAT .CGI .COM .EXE .GADGET .JAR .PIF .WSF .DEM .GAM .NES .ROM .SAV CAD Files .DWG .DXF GIS Files .GPX .KML .KMZ .ASP .ASPX .CER .CFM .CSR .CSS .HTM .HTML .JS .JSP .PHP .RSS .XHTML. DOC .DOCX .LOG .MSG .ODT .PAGES .RTF .TEX .TXT .WPD .WPS .CSV .DAT .GED .KEY .KEYCHAIN .PPS .PPT .PPTX ..INI .PRF Encoded Files .HQX .MIM .UUE .7Z .CBR .DEB .GZ .PKG .RAR .RPM .SITX .TAR.GZ .ZIP .ZIPX .BIN .CUE .DMG .ISO .MDF .TOAST .VCD SDF .TAR .TAX2014 .TAX2015 .VCF .XML Audio Files .AIF .IFF .M3U .M4A .MID .MP3 .MPA .WAV .WMA Video Files .3G2 .3GP .ASF .AVI .FLV .M4V .MOV .MP4 .MPG .RM .SRT .SWF .VOB .WMV 3D .3DM .3DS .MAX .OBJ R.BMP .DDS .GIF .JPG ..CRX .PLUGIN .FNT .FON .OTF .TTF .CAB .CPL .CUR .DESKTHEMEPACK .DLL .DMP .DRV .ICNS .ICO .LNK .SYS .CFG”Source:fileinfo.com
The files may or may not be encrypted and could have the .locked. They may appear like the following:
After locking the files on the computer, the virus displays a ransom note, that is similar to the police type of ransomware viruses, convicting innocent victims of committing online crimes:
THE DEXTOP IS LOCKED
Dear GB citizen, your dextop computer has been locked for commiting multiple crimes that violate GB law.
-Pornography of a disturbing nature
-Breaking copyright law
These broken laws are serious offenses. As a result, all files will be ceased when the designated time is over unless you gain an appeal licence key from the Metropolitan Police.
Do not attempt to close or remove the locking software from your PC. Only the authors and the Metropolitan Police hold the rights to do so. Removing the software manually will not only corrupt your personal data, but will make you criminally responsable for a vandalism of police equipment.
Time Until Removal:
1. Visit the appeal website. click to appeal
2. Enter the unlock key in the text field below
3. Click “Unlock” to recover your files
Remove Dextop Ransomware and Restore .locked Files
For the removal of Dextop ransomware, we advise you to follow our removal instructions below. They will help you to successfully get rid of the malware from your system by isolating it first. You can choose to follow the manual removal option, but experts strongly advise using and advanced anti-malware program to perform the removal of Dextop ransomware automatically and more efficient.
In case you have removed Dextop ransomware and are looking for methods to restore your files, we have several suggestions, mentioned in step “2. Restore files encrypted by Dextop” below. They are in no way fully efficient against this ransomware, but they may get some of your files back. Also, make sure to make copies of the encrypted files first and then test those copies with the methods, instead of the original encrypted files.