VHDLocker ransomware is a bit different from other threats of this type. It exhibits a strange behavior for an encrypting program. It still targets valuable files of most popular types on your computer, but instead of typical adding of abnormal extension to them, VHDLocker transfers the data to a Virtual Hard Disk.
Other than this expect to see nothing new – just a standard procedure of «Pay us if you want your files back!». The hackers demand to pay 0.5 Bitcoin following the instructions in the PLEASE READ.txt which is created after VHDLocker finishes its job.
Furthermore, this ransomware is also capable of altering Windows Registry which allows launching the virus whenever Windows OS starts. In addition to that, Shadow Volume Copies of the corrupted files can be deleted by this malware using Delete Shadows command (vssadmin.exe Delete Shadows /All /Quiet). So we advise having backups for most important files on your computer. VHDLocker will most likely target files with the following extensions: .jpg, .jpeg, .docx, .doc, .xlsx, .xls, .ppt, .pdf, .png, .odt, .pptx, .msg, .rar, .mdb, .zip.
We still don’t have a full list of the main spreading techniques for this ransomware, but it is safe to safe that most common strategies are in use. We’re talking about typical stuff like:
Please, follow the instructions below if you need additional information to remove VHDLocker. Usually, this kind of malware can be deleted automatically – using an advanced anti-malware program such as Plumbytes Anti-Malware – or manually. Though, we do not recommend the second option because might accidentally harm your system even more. File-encrypting programs like this one are often disguised as safe-looking files. Deleting wrong files might cause additional problems with your OS. If you need more information, please continue to read the paragraph below.
Symptoms of VHDLocker Ransomware infection on your computer can be: computer crashes, unusual homepage or search engine on your browser, unwanted pop-up ads and advertising banners. We recommend to download our automatic removal tool. This removal tool has been tested for VHDLocker Ransomware threat removal and it is easy to use.
After performing all of the steps above you should have all of your web browsers clean of the VHDLOCKER RANSOMWARE and other suspicious add-ons and extensions. However to complete the removal procedure we strongly advise to scan your computer with antivirus and anti-malware tools like SpyHunter, HitmanPro 32-bit, HitmanPro 64-bit or Malwarebytes Anti-Malware. Those programs might help to you find registry entries of malware and remove them safely.