.gocr File Virus Remove and Restore Files

.gocr File Virus Remove and Restore Files


with SpyHunter

Scan Your System for Malicious Files
Note! Your computer might be affected by .gocr file virus and other threats.
Threats such as .gocr file virus may be persistent on your system. They tend to re-appear if not fully deleted. A malware removal tool like SpyHunter will help you to remove malicious programs, saving you the time and the struggle of tracking down numerous malicious files.
SpyHunter’s scanner is free but the paid version is needed to remove the malware threats. Read SpyHunter’s EULA and Privacy Policy

HOW_TO_GET_MY_FILES txt .gocr virus dcry ransomware sensorstechforum

The .gocr file virus is yet another DCry ransomware strain that has been suspected by security researchers. It is a crypto virus that blocks access to valuable files by encrypting them with strong cipher algorithm. Files remain unusable until the victim pays the attacker a ransom for the unique decryption key. After file encryption, the ransomware drops a file named HOW_TO_GET_MY_FILES.txt that contains a ransom message by attackers.

This article includes thorough information about .gocr file virus and detailed guide for its removal from the infected system.

Threat Summary

Name.gocr file virus
TypeRansomware, Cryptovirus
Short DescriptionEncrypts the files on the infected computer. Demands ransom payoff in BitCoin. The ransom varies.
SymptomsThe files are encrypted with the .gocr file extension added to them. The virus drops a ransom note, named HOW_TO_GET_MY_FILES.txt.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by .gocr file virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .gocr file virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Distribution of .gocr File Virus

The threat payload may be distributed via several ways. As preferred one are considered to be spam emails with malicious attachments or compromised links. Such emails usually impersonate well-known business organizations or even governmental institutions aiming to mislead the receiver and make him quite willing to act according to the text message. The email attachment may be documented with embedded malicious macros that contain the ransomware payload. When the document is opened, the user is asked to enable macros. If he does, an executable file triggers the ransomware infection. The links may be destined to mirrored web pages of popular websites. Usually corrupted web pages are designed to download and start the ransomware payload on the computer automatically. Other methods of distribution are fake software notifications, fake setups of free programs, and malicious adverts.

Overview of .gocr Virus Attack

Once the malicious .gocr ransomware payload is running on the system, the attack begins. The .gocr file virus also known as DCry ransomware performs a sequence of malicious activities starting with downloading additional malware files that support the successful infection. These files may be situated in Windows directories like:

  • %AppData%
  • %Temp%
  • %Roaming%
  • %Common%
  • %UserProfile%
  • %System32%

After all malicious files are obtained the ransomware can execute various functionalities. One of the most common actions carried out by crypto viruses like .gocr is shadow volume copies wipe. By acquiring administrator privileges, the threat can execute the following command in Windows Command Prompt:

→ vssadmin.exe delete shadows /all /quiet

This will delete all backed up files on the computer called shadow volume copies and prevent one of the possible ways for .gocr files recovery. In addition .gocr file virus is believed to create registry entries within the following Windows Registry sub-keys:


Those keys are targeted as they are behind all automatically executed processes on every Windows start up. When .gocr file virus adds its malicious values, it is able to load each time the user starts the PC. The ransomware uses the functionalities of Run and RunOnce keys to display its ransom note at the end of the attack. The message is stored in a text file with the name HOW_TO_GET_MY_FILES.txt. Once it is opened the victim can see the following text:

Hello my friend, first sorry for this.
Your files have been crypted with the AES-256 method.
Don’t try decrypt files use third-party software, otherwise you may loss all files permanently.
If you want to decrypt your data, write to e-mail: [email protected]
If you want to test the decrypt, go to https://s7c4wrcmzgbtldbs.onion (use tor browser)

Your ID: STGO_[redacted base64]

It is advisable to restrict any negotiations with cyber criminals. Even though they are likely to promise victims that after ransom payment all .gocr files will be decrypted, there is no guarantee that they will keep the promise. For the sake of your security, we recommend following the step-by-step instructions to remove .gocr file virus and restore corrupted data.

Encryption Means of .gocr File Virus

For the encoding process, the .gocr ransomware is considered to use the AES 256 cipher algorithm. It can modify original code of target files in such a way that they become completely unusable. Each encrypted file is marked with the specific file extension .gocr. Тhe .gocr virus may encrypt files with the following extensions:


.gocr file virus dcry ransomware encrypted file sensorstechforum

After locking files, the ransomware demands payment for their decryption which should be in Bitcoins.

Remove .gocr File Ransomware and Restore Files

To completely get rid of the .gocr file virus, carefully follow the step-by-step removal instructions provided below. After ransomware removal follows .gocr data recovery step.

Note! Your computer system may be affected by .gocr file virus and other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of threats such as .gocr file virus.
Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter’s malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

To remove .gocr file virus follow these steps:

1. Boot Your PC In Safe Mode to isolate and remove .gocr file virus files and objects
2. Find files created by .gocr file virus on your PC

Before starting the Automatic Removal below, please boot back into Normal mode, in case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.

Use SpyHunter to scan for malware and unwanted programs

3. Scan for malware and unwanted programs with SpyHunter Anti-Malware Tool
4. Try to Restore files encrypted by .gocr file virus
Gergana Ivanova

Gergana Ivanova

Gergana has completed a bachelor degree in Marketing from the University of National and World Economy. She has been with the STF team for three years, researching malware and reporting on the latest infections. She believes that in times of constantly evolving dependency of network connected technologies, people should spread the word not the war.

More Posts

Follow Me:
Google Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share