The .gocr file virus is yet another DCry ransomware strain that has been suspected by security researchers. It is a crypto virus that blocks access to valuable files by encrypting them with strong cipher algorithm. Files remain unusable until the victim pays the attacker a ransom for the unique decryption key. After file encryption, the ransomware drops a file named HOW_TO_GET_MY_FILES.txt that contains a ransom message by attackers.
This article includes thorough information about .gocr file virus and detailed guide for its removal from the infected system.
|Name||.gocr file virus|
|Short Description||Encrypts the files on the infected computer. Demands ransom payoff in BitCoin. The ransom varies.|
|Symptoms||The files are encrypted with the .gocr file extension added to them. The virus drops a ransom note, named HOW_TO_GET_MY_FILES.txt.|
|Distribution Method||Spam Emails, Email Attachments, Executable files|
|Detection Tool|| See If Your System Has Been Affected by .gocr file virus |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss .gocr file virus.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
Distribution of .gocr File Virus
The threat payload may be distributed via several ways. As preferred one are considered to be spam emails with malicious attachments or compromised links. Such emails usually impersonate well-known business organizations or even governmental institutions aiming to mislead the receiver and make him quite willing to act according to the text message. The email attachment may be documented with embedded malicious macros that contain the ransomware payload. When the document is opened, the user is asked to enable macros. If he does, an executable file triggers the ransomware infection. The links may be destined to mirrored web pages of popular websites. Usually corrupted web pages are designed to download and start the ransomware payload on the computer automatically. Other methods of distribution are fake software notifications, fake setups of free programs, and malicious adverts.
Overview of .gocr Virus Attack
Once the malicious .gocr ransomware payload is running on the system, the attack begins. The .gocr file virus also known as DCry ransomware performs a sequence of malicious activities starting with downloading additional malware files that support the successful infection. These files may be situated in Windows directories like:
After all malicious files are obtained the ransomware can execute various functionalities. One of the most common actions carried out by crypto viruses like .gocr is shadow volume copies wipe. By acquiring administrator privileges, the threat can execute the following command in Windows Command Prompt:
→ vssadmin.exe delete shadows /all /quiet
This will delete all backed up files on the computer called shadow volume copies and prevent one of the possible ways for .gocr files recovery. In addition .gocr file virus is believed to create registry entries within the following Windows Registry sub-keys:
Those keys are targeted as they are behind all automatically executed processes on every Windows start up. When .gocr file virus adds its malicious values, it is able to load each time the user starts the PC. The ransomware uses the functionalities of Run and RunOnce keys to display its ransom note at the end of the attack. The message is stored in a text file with the name HOW_TO_GET_MY_FILES.txt. Once it is opened the victim can see the following text:
Hello my friend, first sorry for this.
Your files have been crypted with the AES-256 method.
Don’t try decrypt files use third-party software, otherwise you may loss all files permanently.
If you want to decrypt your data, write to e-mail: email@example.com.
If you want to test the decrypt, go to https://s7c4wrcmzgbtldbs.onion (use tor browser)
Your ID: STGO_[redacted base64]
It is advisable to restrict any negotiations with cyber criminals. Even though they are likely to promise victims that after ransom payment all .gocr files will be decrypted, there is no guarantee that they will keep the promise. For the sake of your security, we recommend following the step-by-step instructions to remove .gocr file virus and restore corrupted data.
Encryption Means of .gocr File Virus
For the encoding process, the .gocr ransomware is considered to use the AES 256 cipher algorithm. It can modify original code of target files in such a way that they become completely unusable. Each encrypted file is marked with the specific file extension .gocr. Тhe .gocr virus may encrypt files with the following extensions:
→ “PNG .PSD .PSPIMAGE .TGA .THM .TIF .TIFF .YUV .AI .EPS .PS .SVG .INDD .PCT .PDF .XLR .XLS .XLSX .ACCDB .DB .DBF .MDB .PDB .SQL .APK .APP .BAT .CGI .COM .EXE .GADGET .JAR .PIF .WSF .DEM .GAM .NES .ROM .SAV CAD Files .DWG .DXF GIS Files .GPX .KML .KMZ .ASP .ASPX .CER .CFM .CSR .CSS .HTM .HTML .JS .JSP .PHP .RSS .XHTML. DOC .DOCX .LOG .MSG .ODT .PAGES .RTF .TEX .TXT .WPD .WPS .CSV .DAT .GED .KEY .KEYCHAIN .PPS .PPT .PPTX ..INI .PRF Encoded Files .HQX .MIM .UUE .7Z .CBR .DEB .GZ .PKG .RAR .RPM .SITX .TAR.GZ .ZIP .ZIPX .BIN .CUE .DMG .ISO .MDF .TOAST .VCD SDF .TAR .TAX2014 .TAX2015 .VCF .XML Audio Files .AIF .IFF .M3U .M4A .MID .MP3 .MPA .WAV .WMA Video Files .3G2 .3GP .ASF .AVI .FLV .M4V .MOV .MP4 .MPG .RM .SRT .SWF .VOB .WMV 3D .3DM .3DS .MAX .OBJ R.BMP .DDS .GIF .JPG ..CRX .PLUGIN .FNT .FON .OTF .TTF .CAB .CPL .CUR .DESKTHEMEPACK .DLL .DMP .DRV .ICNS .ICO .LNK .SYS .CFG”Source:fileinfo.com
After locking files, the ransomware demands payment for their decryption which should be in Bitcoins.
Remove .gocr File Ransomware and Restore Files
To completely get rid of the .gocr file virus, carefully follow the step-by-step removal instructions provided below. After ransomware removal follows .gocr data recovery step.