Youfileslock Ransomware (. Youfileslock File) — Removal Guide
What Is Youfileslock Virus? Youfileslock Adds Its Extra. Youfileslock Extension to Every File’s Name. for Instance, a File Named “Photo. Jpg” Will Be Renamed...
What is Youfileslock virus?
Youfileslock adds its extra .youfileslock extension to every file’s name. For instance, a file named “photo.jpg” will be renamed to “photo.jpg.youfileslock”. In the same manner, the Excel sheet with the name “table.xlsx” will end up as “table.xlsx.youfileslock”, and so forth.
In each folder that contains the encrypted files, a HOW_TO_RECOVER_DATA.html text file will appear. It is a ransom money memo. Therein you can find information about the ways of paying the ransom and some other remarks. The ransom note most probably contains a description of how to purchase the decryption tool from the tamperers. That is how they do it.
| Name | Youfileslock Virus |
| Ransomware family1 | MedusaLocker ransomware |
| Extension | .youfileslock |
| Ransomware note | HOW_TO_RECOVER_DATA.html |
| Detection2 | Trojan:Win32/RedLineStealer.PS!MTB, Ransom:Win32/Ciluf, MSIL/Agent.VIF |
| Symptoms | Your files (photos, videos, documents) get a .youfileslock extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Youfileslock virus |
In the picture below, you can see what a directory with files encrypted by the Youfileslock looks like. Each filename has the “.youfileslock” extension added to it.
Must Read
How did my machine catch Youfileslock ransomware?
There are currently three most exploited ways for malefactors to have ransomware planted in your system. These are email spam, Trojan infiltration and peer networks.
If you open your inbox and see letters that look just like notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose mailer is unknown to you, beware of opening those letters. They are most likely to have a malicious file attached to them. Therefore, it is even riskier to download any attachments that come with letters like these.
Another thing the hackers might try is a Trojan virus scheme3. A Trojan is an object that infiltrates into your computer pretending to be something legal. For example, you download an installer for some program you need or an update for some program. But what is unpacked turns out to be a harmful program that compromises your data. As the installation package can have any title and any icon, you’d better be sure that you can trust the resource of the things you’re downloading. The optimal way is to use the software developers’ official websites.
As for the peer-to-peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is reasonable to scan the directory containing the downloaded items with the antivirus as soon as the downloading is done.