Locker virus (can also be found as Locker v1.7, Locker V2.16, Locker v2.60, Locker v3.5.3, Locker v.3.49 and Locker V5.52) is a truly dangerous cyber threat that operates according to by its name. As soon as specified application penetrates the target computer, it searches for certain files in the system and “closes” access to them. Additionally, if you try to open any of these files, you may see a message asking you to make a payment in exchange for the decryption key. This is usually needed to unlock the files you need and restore access to them. Locker falls into the category of 'ransomware' or 'crypto-ransomware', which means that it tries to force users to pay a ransom. This trick is very likely to succeed, because before demanding a ransom of 0.1 BTC (bitcoins), Locker re-encrypts all the most frequently used files:

3fr, .accdb, .ai, .arw, .bay, .cdr, .cer, .cr2, .crt, .crw, .dbf, .dcr, .der, .dng, .doc, .docm, .docx, .dwg, .dxf, .dxg, .eps, .erf, .indd, .jpe, .jpg, .kdc, .mdb, .mdf, .mef, .mrw, .nef, .nrw, .odb, .odm , .odp, .ods, .odt, .orf, .p12, .p7b, .p7c, .pdd, .pef, .pem, .pfx, .ppt, .pptm, .pptx, .psd, .pst, . ptx, .r3d, .raf, .raw, .rtf, .rw2, .rwl, .srf, .srw, .wb2, .wpd, .wps, .xlk, .xls, .xlsb, .xlsm, .xlsx

As you can see, this cyber threat can easily lead you to the loss of all photos, music files, files with the results of your creative activity, as well as other documents. To be able to decrypt files, you will be required to make a payment within 72 hours. If the victim agrees to pay the first minimum ransom, the Locker ransomware increases the demand to 1.0 BTC.

What can be done in such a situation? First of all, you need to remove Locker virus from the system before it can re-encrypt too many files. In addition, you should look for copies of the locked files. If you still don’t know how to backup important files, then you should read this post: ? If you have not made a backup, you can try to use the following tools: R-Studio, Photorec. Even if specified programs could not help you, this means that the encrypted files, unfortunately, are lost forever.

To remove Locker virus, we highly recommend the program, as it has shown excellent results in solving the problem in question.

How could Locker virus infect my computer?

Nowadays, many similar ransomware programs are being distributed, for example, the well-known CTB locker, Cryptobot, Cryptographic Locker, etc. They all use the same distribution technique used by many other viruses, such as fake anti-spyware, Trojan horses, etc. If you want to stay away from them, you should first remember this: such software is actively promoted through spam. Spam is annoying messages Email, accompanied by infected attachments or malicious links. In an effort to trick users into clicking on such links or downloading malicious attachments, the messages notify about intriguing things such as missing payments, warnings from government agencies and similar nonsense that usually leave people indifferent. Please DO NOT believe such messages and always be critical of the stated sender and body of the message. If they are filled with typos or grammatical errors, then there is a huge chance that the message itself is false. In addition, Locker virus can also enter your PC after you click on misleading pop-up advertisements that can interfere with your browser usage. Please stay away from any notifications reporting missing updates, including Java, Flash Player and so on.

How to remove Locker virus?

If you are one of the victims of the Locker ransomware, then you should immediately remove it from your computer. To do this, you can use the following applications: , , .

If you want to restore access to your files, you can use their backup copies or, if you don't have such copies, try one of the file recovery tools such as R-Studio or Photorec. Besides, Kaspersky Lab also introduced a tool for decrypting re-encrypted files, so you should also try . Please DO NOT pay the ransom because payment does not guarantee that you will receive the key to decrypt your files.

We strongly recommend that you think about preventing infections like Locker. To do this, you can use the above-mentioned programs. Also, be sure to keep your files safe and back them up. You can use an external USB drive, CD/DVD drives, or just an online backup, for example, Google services Drive, Dropbox, Flickr, etc. More information about backup can be obtained from this post: Why do I need backup and what options do I have for that?

Hi all! Today we will talk about the Super Locker application, whose advertising and constant loading prevent you from using your phone normally. You will learn how to completely remove Super Locker from Android.

Recently, users of Android smartphones have encountered another adware application. This time this application was Super Locker. In general, such promotions have become very popular recently - Apus Launcher, 9 Store and other programs are often installed on smartphones without notice.

Is Super Locker a virus or not?

First, let's figure out what this program is.

Super Locker is an application for stylishly locking your phone and speeding up battery charging. The lock screen displays weather information, news, and the device's charge level.

Here are the main features of the application:

  1. Speeds up the phone charging process (by 20% on average);
  2. Setting a PIN code or pattern lock for entry;
  3. Current and detailed weather forecast (humidity, wind strength and direction, showing sunrise and sunset), based on receiving phone geodata;
  4. Quick transition to the main functions of the smartphone - calculator, flashlight, Wi-Fi, Bluetooth, screen brightness, etc.

If we talk about the usefulness of the application, then I cannot say anything. Such a standard set of functions has many more popular applications (Clean Master, For example).

If we talk about the application itself as a virus, then I would not say that it is such. Constant automatic installation is an advertising campaign (action) that many developers often order from distributors. One thing is certain, spontaneous installation is viral problem, which you need to get rid of.

How to remove Super Locker from Android

If you are faced with this problem and constantly receive advertisements for Super Locker and its installation, then you need to find specific file, which activates the viral process of downloading this program to the phone and launching banners.

First, remove in a standard way Locker itself: go to the application manager - clear the cache - clear the data - stop and delete.

  1. Go to Application Manager and view All tab.
  2. Find and remove the application android communication sync. In most cases, it is this that is the source of trouble. Also view availability com.android.comp.download …(the endings are different) and delete if there are any.
  3. If suddenly this does not help you, install Kaspersky mobile anti-virus. Very often he finds such applications.
  4. You can also view all active applications and close them one by one. As soon as after the next closed process, advertising will stop, then delete it. Long - but also effective.

I hope these methods will help you and you will remove Super Locker from Android and no longer download illegal programs :). If it helped, please write in the comments.

IN Google Play you can find many applications that change the lock screen. But most often they have very poor functionality. The style of showing time changes, but it appears new picture- that's all they can please. Fortunately, there are exceptions. Try downloading Super Locker. This blocker differs from many others in that it somehow reduces recharging time.

Interface

The application can be downloaded for free. All functionality of the blocker opens immediately after installation - there are no paid functions here. The product is intended for Android - primarily for smartphones. Suitable version operating system 4.0.3 or later. Unfortunately, on the oldies from the second Android version the application will not be launched. This is logical, because in such old version The operating system does not provide the ability to change the lock screen.

Installing Super Locker is incredibly easy. The process is no different from installing any other screen locker. When this process is complete, you will be able to admire the changed lock screen. In particular, a widget will appear here that displays the time and weather. In the settings you can select the degree of its load. For example, it can display not only a thumbnail view of cloudiness and precipitation, but also humidity levels, wind strength, and sunrise and sunset times. Weather data is taken from the Weather Channel service; nothing can be changed in this regard.

You will also find the Camera app icon on the lock screen. As you might guess, this allows you to go to it without visiting the desktop. In the settings, you can enable the display of some other blocks on the lock screen. The most useful of them is the “News” item. So you will be aware of the most important news even before unlocking the smartphone. But don’t count on any detailed notes - only news headlines are displayed on the lockscreen.

As already said, this program distributed free of charge. But at the same time, it has such functionality that many paid blockers would envy. Most main feature Super Locker is a smartphone optimization. It turns out that you simultaneously have both an optimizer and a blocker at your disposal! The application will try to kill the so-called idle background utilities, which completely waste RAM, and therefore energy. As a result, the device begins to work noticeably faster.

The optimization function will be useful to owners budget smartphones equipped with an older version of the operating system.

Unfortunately, there is no point in optimization if you are using a flagship or even some mid-range smartphone price category. Samsung and many other companies have already learned to provide their creations with a similar feature, where applications are completely unloaded from memory if you haven’t launched them for three or four days.

Other useful feature Super Locker is a charging acceleration. If you have performed optimization, charging will then proceed at an accelerated pace. But here, too, everything depends on the smartphone used. On some devices, charging time is reduced by about 20%, while on others the increase is only 5-6%.

But owners of absolutely all smartphones will have access to the control center. If previously you could only go to this center from the desktop, now you can get the corresponding access on the lock screen. Here you can disable data transfer via mobile networks, adjust the brightness of the screen backlight, enable Wi-Fi or airplane mode, and perform other useful actions.

Interestingly, this center even contains a flashlight and a calculator. Need I say that it is precisely to search for these functions that you most often do not want to waste time on unlocking?

Summarizing

This concludes our story about the Super Locker application. This is the full functionality of this blocker. He doesn’t have enough stars from the sky and he doesn’t send spaceships there either. But useful “tricks” like optimizing the device and speeding up charging will definitely find a response in the hearts of owners of the simplest smartphones. We must not forget about the control center, thanks to which you can turn on the flashlight or disable the search for Wi-Fi networks without unlocking the device.

New mobile threat, DoubleLocker malware. The malware, like many other malware, exploits the legitimate functionality of the Accessibility service and is reactivated every time you press the Home button.

DoubleLocker is built on the code of the famous banker Svpeng. However, for now it has disabled functions designed specifically for collecting users’ banking data. Instead, DoubleLocker is equipped with two extortion tools at once: it can change the device PIN to an arbitrary one, and it also encrypts the data it finds. According to ESET experts, this is the first time such a combination of functions has been observed in the Android ecosystem.

DoubleLocker is distributed in the “classic” way: mainly under the guise Adobe Flash Player via compromised sites. After running the malware on the user’s device, the application prompts you to activate the service special features(Accessibility service). Having received the necessary permissions to operate, DoubleLocker gains administrator rights and sets itself as the default launcher.

“Self-installation as the default launcher improves the safety of malware on the device,” said Lukas Stefanko, the ESET virus analyst who discovered DoubleLocker. “Every time the user presses the Home button, the ransomware is activated and locks the screen of the tablet or smartphone again.”

Once executed on a device, DoubleLocker uses two compelling arguments to convince the user to pay the ransom.

First, it changes the PIN code of the tablet or smartphone, which prevents the device from being used. The new PIN is set to a random value, the code is not stored on the device and is not sent anywhere outside, so neither the user nor the security specialist will be able to recover it.

Secondly, DoubleLocker is one of the few mobile malware that actually encrypts all files in the device’s main storage. To do this, the malware uses the AES encryption algorithm and adds the .cryeye extension to the files. Unfortunately, it is not yet possible to decrypt the affected data.

The ransom amount is 0.0130 bitcoin (about 4,000 rubles), and the attackers’ message emphasizes that payment must be made within 24 hours. If the ransom is not transferred, the data will remain encrypted.

To get rid of DoubleLocker, ESET experts recommend taking the following measures:

  • Unrooted device, which does not have a management solution installed mobile device, capable of resetting the PIN: the only way to get rid of the lock screen is to reset it to factory settings.
  • Rooted device: The user can connect to the device via ADB and delete the file where the PIN is stored. To do this, you need to enable device debugging (Settings – Developer options – USB debugging). The lock screen will be removed and the user will regain access to the device. Then, working in safe mode, the user will be able to deactivate the device administrator rights for the malware and delete it. In some cases, the device may need to be rebooted.

However, all this, unfortunately, will not help decrypt the affected data, as mentioned above.

Threat name

Executable file name:

Threat type:

Affected OS:

(randomname).dll

Ransomware

Win32 (Windows XP, Windows Vista, Windows Seven, Windows 8)




Locker Virus infection method

Locker Virus copies its file(s) to your HDD. Typical file name (randomname).dll. Then it creates a startup key in the registry with a name and value (randomname).dll. You can also find it in the process list with the name (randomname).dll or .

if you have additional questions regarding Locker Virus, please fill out and we will contact you shortly.


Download the removal utility

Download this program and remove Locker Virus and (randomname).dll (download will start automatically):

* SpyHunter was developed by the American company EnigmaSoftware and is capable of removing Locker Virus from automatic mode. The program was tested on Windows XP, Windows Vista, Windows 7 and Windows 8.

Functions

The program is able to protect files and settings from malicious code.

The program can fix browser problems and protects browser settings.

Removal is guaranteed - if SpyHunter fails, free support is provided.

24/7 anti-virus support is included in the package.


Download the Locker Virus removal utility from the Russian company Security Stronghold

If you are not sure which files to delete, use our program Locker Virus removal utility.. The Locker Virus removal utility will find and completely remove all problems associated with the Locker Virus virus. Fast, easy-to-use Locker Virus Removal Tool will protect your computer from the Locker Virus threat that harms your computer and violates your privacy. Locker Virus removal tool scans your hard disks and registry and removes any manifestation of Locker Virus. Regular antivirus software is powerless against malicious programs such as Locker Virus. Download this simplified removal tool specially designed to solve problems with Locker Virus and (randomname).dll (download will start automatically):

Functions

Removes all files created by Locker Virus.

Removes all registry entries created by Locker Virus.

The program can fix browser problems.

Immunizes the system.

Removal is guaranteed - if the Utility fails, free support is provided.

24/7 antivirus support via GoToAssist is included in the package.

Our support team is ready to solve your problem with Locker Virus and remove Locker Virus right now!

Leave detailed description your problem with Locker Virus in the section. Our support team will contact you and provide you with step by step solution Problems with Locker Virus. Please describe your problem as accurately as possible. This will help us provide you with the most effective method Locker Virus removal.

How to remove Locker Virus manually

This problem can be resolved manually by deleting the registry keys and files associated with Locker Virus, removing it from the startup list and de-registering all associated DLL files. In addition, missing DLL files must be restored from the OS distribution if they were damaged.

To get rid of it, you need:

1. Terminate the following processes and delete the corresponding files:

Warning: you need to delete only files whose checksums are in the list of malicious ones. Your system may have necessary files with the same names. We recommend using this to solve the problem safely.

2. Delete the following folders:

3. Delete the following registry keys and/or values:

Warning: If registry key values ​​are specified, you should delete only the specified values ​​and leave the keys themselves intact. We recommend using this to solve the problem safely.

4. Reset browser settings

Sometimes it can affect your browser settings, such as replacing search and home page. We recommend that you use the free "Reset Browsers" feature in "Tools" in the program to reset all browsers at once. Please note that before this you need to delete all files, folders and registry keys belonging to Locker Virus. To reset browser settings manually, use these instructions:

For Internet Explorer

    If you are using Windows XP, click Start, And Open. Enter the following in the field Open without quotes and press Enter: "inetcpl.cpl".

    If you are using Windows 7 or Windows Vista, click Start. Enter the following in the field Search without quotes and press Enter: "inetcpl.cpl".

    Select a tab Additionally

    Under Reset settings Internet browser Explorer, click Reset. And press Reset again in the window that opens.

    Select checkbox Remove personal settings to delete history, restore search and home page.

    After Internet Explorer has completed the reset, click Close in the dialog box.

Warning: Reset browser settings V Tools

For Google Chrome

    Find the folder Google installations Chrome at: C:\Users\"username"\AppData\Local\Google\Chrome\Application\User Data.

    In folder User Data, find the file Default and rename it to DefaultBackup.

    Launch Google Chrome and it will be created new file Default.

    Google Chrome settings reset

Warning: In case this doesn't work, use the free option. Reset browser settings V Tools in the Stronghold AntiMalware program.

For Mozilla Firefox

    Open Firefox

    From the menu, select Help > Problem Solving Information.

    Click the button Reset Firefox.

    After Firefox finishes, it will show a window and create a folder on your desktop. Click Complete.

Warning: This way you will lose your passwords! We recommend using the free option Reset browser settings V Tools in the Stronghold AntiMalware program.