.gocr File Virus Remove and Restore Files

.gocr File Virus Remove and Restore Files

HOW_TO_GET_MY_FILES txt .gocr virus dcry ransomware sensorstechforum

The .gocr file virus is yet another DCry ransomware strain that has been suspected by security researchers. It is a crypto virus that blocks access to valuable files by encrypting them with strong cipher algorithm. Files remain unusable until the victim pays the attacker a ransom for the unique decryption key. After file encryption, the ransomware drops a file named HOW_TO_GET_MY_FILES.txt that contains a ransom message by attackers.

This article includes thorough information about .gocr file virus and detailed guide for its removal from the infected system.

Threat Summary

Name.gocr file virus
TypeRansomware, Cryptovirus
Short DescriptionEncrypts the files on the infected computer. Demands ransom payoff in BitCoin. The ransom varies.
SymptomsThe files are encrypted with the .gocr file extension added to them. The virus drops a ransom note, named HOW_TO_GET_MY_FILES.txt.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by .gocr file virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .gocr file virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Distribution of .gocr File Virus

The threat payload may be distributed via several ways. As preferred one are considered to be spam emails with malicious attachments or compromised links. Such emails usually impersonate well-known business organizations or even governmental institutions aiming to mislead the receiver and make him quite willing to act according to the text message. The email attachment may be documented with embedded malicious macros that contain the ransomware payload. When the document is opened, the user is asked to enable macros. If he does, an executable file triggers the ransomware infection. The links may be destined to mirrored web pages of popular websites. Usually corrupted web pages are designed to download and start the ransomware payload on the computer automatically. Other methods of distribution are fake software notifications, fake setups of free programs, and malicious adverts.

Overview of .gocr Virus Attack

Once the malicious .gocr ransomware payload is running on the system, the attack begins. The .gocr file virus also known as DCry ransomware performs a sequence of malicious activities starting with downloading additional malware files that support the successful infection. These files may be situated in Windows directories like:

  • %AppData%
  • %Temp%
  • %Roaming%
  • %Common%
  • %UserProfile%
  • %System32%

After all malicious files are obtained the ransomware can execute various functionalities. One of the most common actions carried out by crypto viruses like .gocr is shadow volume copies wipe. By acquiring administrator privileges, the threat can execute the following command in Windows Command Prompt:

→ vssadmin.exe delete shadows /all /quiet

This will delete all backed up files on the computer called shadow volume copies and prevent one of the possible ways for .gocr files recovery. In addition .gocr file virus is believed to create registry entries within the following Windows Registry sub-keys:


Those keys are targeted as they are behind all automatically executed processes on every Windows start up. When .gocr file virus adds its malicious values, it is able to load each time the user starts the PC. The ransomware uses the functionalities of Run and RunOnce keys to display its ransom note at the end of the attack. The message is stored in a text file with the name HOW_TO_GET_MY_FILES.txt. Once it is opened the victim can see the following text:

Hello my friend, first sorry for this.
Your files have been crypted with the AES-256 method.
Don’t try decrypt files use third-party software, otherwise you may loss all files permanently.
If you want to decrypt your data, write to e-mail: lnq@protonmail.com.
If you want to test the decrypt, go to https://s7c4wrcmzgbtldbs.onion (use tor browser)

Your ID: STGO_[redacted base64]

It is advisable to restrict any negotiations with cyber criminals. Even though they are likely to promise victims that after ransom payment all .gocr files will be decrypted, there is no guarantee that they will keep the promise. For the sake of your security, we recommend following the step-by-step instructions to remove .gocr file virus and restore corrupted data.

Encryption Means of .gocr File Virus

For the encoding process, the .gocr ransomware is considered to use the AES 256 cipher algorithm. It can modify original code of target files in such a way that they become completely unusable. Each encrypted file is marked with the specific file extension .gocr. Тhe .gocr virus may encrypt files with the following extensions:


.gocr file virus dcry ransomware encrypted file sensorstechforum

After locking files, the ransomware demands payment for their decryption which should be in Bitcoins.

Remove .gocr File Ransomware and Restore Files

To completely get rid of the .gocr file virus, carefully follow the step-by-step removal instructions provided below. After ransomware removal follows .gocr data recovery step.

Gergana Ivanova

Gergana Ivanova

Gergana has completed a bachelor degree in Marketing from the University of National and World Economy. She has been with the STF team for four years, researching malware and reporting on the latest infections.

More Posts

Follow Me:
Google Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share