Ransom.LockerGoga is Malwarebytes’ detection name for aransomwarethat is primarily used in targeted, and very disruptive attacks.
Ransom.LockerGoga encrypts files on the affected system and adds the .locked extension to the encrypted files.
Ransom.LockerGoga shows a ransom note called README_LOCKED.txt
Users of affected systems may also find themselves locked out because their login credentials were changed.
Ransomware is a form of malware that locks you out of your device and/or encrypts your files, then forces you to pay a ransom to get them back.
Ransom.LockerGoga is typically delivered by a targeted attack using login credentials that the threat actor somehow got hold of.
Besides the encrypted files of the filetypes:
.doc, .dot, .docx, .docb, .dotx, .wkb, .xlm, .xml, .xls, .xlsx, .xlt, .xltx, .xlsb, .xlw, .ppt, .pps, .pot, .ppsx, .pptx, .posx, .potx, .sldx, .pdf, .db, .sql, .cs, .ts, .js, and .py
users my find that they have been locked out of their systems because their credentials were changed by the threat actor.
必威平台APP伪安全保护用户免受赎金。LockerGogaby using real-time protection.
Malwarebytes can detect and remove Ransom.LockerGoga on business machines without further user interaction.
To remove Ransom.LockerGoga using Malwarebytes business products, follow the instructions below.
If you have infected machines that are not registered endpoints in Malwarebytes Endpoint Protection, you can remove Ransom.LockerGoga with our Breach Remediation tool (MBBR).
If the ransomware has encrypted some files before the behavioral detection kicked in, you can use the rollback feature (if available) to retrieve the files.
Malwarebytes can detect and remove Ransom.LockerGoga without further user interaction.
但是注意,删除这ransomwaredoes not decrypt your files. You can only get your files back from backups you made before the infection happened.
Mutex:
MX-tgytutrc
Files:
%APPDATA%\Local\Temp\tgytutrc8.exe
%APPDATA%\Local\Temp\tgytutrc{4 Random Numbers}.exe
E-mail addresses used:
AbbsChevis@protonmail.com
AperywsQaroci@o2.pl
AsuxidOruraep1999@o2.pl
CottleAkela@protonmail.com
CouwetIzotofo@o2.pl
DharmaParrack@protonmail.com
DutyuEnugev89@o2.pl
IjuqodiSunovib98@o2.pl
MayarChenot@protonmail.com
PhanthavongsaNeveyah@protonmail.com
QicifomuEjijika@o2.pl
QyavauZehyco1994@o2.pl
RezawyreEdipi1998@o2.pl
RomanchukEyla@protonmail.com
SayanWalsworth96@protonmail.com
SchreiberEleonora@protonmail.com
SuzuMcpherson@protonmail.com
wyattpettigrew8922555@mail.com
Select your language