Active THT Locker Virus infections can be recovered using our in-depth guide on restoring your computer and data, read our article to learn more.
Manual Removal Guide
Recover THT Locker Virus Files
Skip all steps and download anti-malware tool that will safely scan and clean your PC.
SpyHunter anti-malware tool will diagnose all current threats on the computer. By purchasing the full version, you will be able to remove all malware threats instantly. Additional information about SpyHunter / Help to uninstall SpyHunter
How Does THT Locker Virus Infiltrate the System?
The THT Locker virus can be delivered using different methods, the most prominent way is by coordinating spam email attacks. They are generated using predefined algorithms and are made to send bulk messages to the intended victims. In their most popular form social engineering tricks are employed to male the victims infect themselves with the THT Locker virus. There are several different kinds of strategies that are employed using this approach:
- Body Contents Links ‒ The hackers can embed links that lead to the malware sample via hyperlinks in the body contents of the messages.
- File Attachments ‒ THT Locker virus files can be delivered directly to the victims as file attachments either directly or as a bundle software installer or an infected document.
The two special cases outlined above are related to the way criminals embed malware scripts ordinary looking files. A popular tactic is to use software installers taken from their official sources and modify them to include the malware code. Documents on the other hand integrate the scripts in rich text documents, spreadsheets or databases.
Browser hijackers are another popular method. They aim to redirect the users to malicious sites and change important settings: default home page, search engine and new tabs page. In most cases all popular web browsers are affected: Mozilla Firefox, Google Chrome, Opera, Safari, Internet Explorer and Microsoft Edge. Once this is done the hacker-controlled page spreads the virus or the THT Locker virus is imposed during the infection phase.
Infection Flow of THT Locker Virus
The THT Locker virus is a new ransomware strainn that institutes a lockscreen instance on the compromised computers. At the moment the initial security analysis reveals that part of the code is similar to that of the Hidden Tear malware family, especially the recent samples. This likely means that the criminals behind the threat have taken the source code from the hacker underground forums where it is available.
The collected samples associated with the current wave of THT locker virus shows that only a basic lockscreen is imposed. It prohibits ordinary user interaction until it is completely eliminated by the user. The users get infected by it via a contaminated file called cryptolocker.exe which bears the same name of another threat. The security audit however did not find a correlation between the two.
The security researchers unvovered that unlike other viruses, the THT Locker does not encrypt the user files. In contrast with them the displayed warning message serves only as a blackmail tool. It reads the following:
важно Ваши важньие файль собрань!!!!!!!!!!
Important!!! Your PC Has Been Locked!!!
You Dont Acess Your Computer…
THT Locker
The first lines are written in Russian and translate to “Important, your important files have been locked”. Normally threats like this one are customized with elaborate descriptions feature contact information which the victims can use to communicate with the hackers. We may see such updates in the near future when newer malware samples can be created.
Furthermore new modules can be added to the THT Locker virus to make it more dangerous. Some of the options that criminals can consider are the following:
- Trojan Module ‒Such additions allow the criminal operators to overtake complete control of the compromised machines. It is traditionally used for spying purposes.
- Data Theft ‒ Advanced viruses can include mechanisms that give hackers the ability to overtake private files.
- Additional Malware Delivery ‒ The THT Locker virus can be used to deliver additional malware to the victim computers.
Remove THT Locker Virus and Restore Data
WARNING! Manual removal of THT Locker Virus requires being familiar with system files and registries. Removing important data accidentally can lead to permanent system damage. If you don’t feel comfortable with manual instructions, download a powerful anti-malware tool that will scan your system for malware and clean it safely for you.
SpyHunter anti-malware tool will diagnose all current threats on the computer. By purchasing the full version, you will be able to remove all malware threats instantly. Additional information about SpyHunter / Help to uninstall SpyHunter
THT Locker Virus – Manual Removal Steps
Start the PC in Safe Mode with Network
This will isolate all files and objects created by the ransomware so they will be removed efficiently. The steps bellow are applicable to all Windows versions.
1. Hit the WIN Key + R
2. A Run window will appear. In it, write msconfig and then press Enter
3. A Configuration box shall appear. In it Choose the tab named Boot
4. Mark Safe Boot option and then go to Network under it to tick it too
5. Apply -> OK
Show Hidden Files
Some ransomware threats are designed to hide their malicious files in the Windows so all files stored on the system should be visible.
1. Open My Computer/This PC
2. Windows 7
-
– Click on Organize button
– Select Folder and search options
– Select the View tab
– Go under Hidden files and folders and mark Show hidden files and folders option
3. Windows 8/ 10
-
– Open View tab
– Mark Hidden items option
4. Click Apply and then OK button
Enter Windows Task Manager and Stop Malicious Processes
1. Hit the following key combination: CTRL+SHIFT+ESC
2. Get over to Processes
3. When you find suspicious process right click on it and select Open File Location
4. Go back to Task Manager and end the malicious process. Right click on it again and choose End Process
5. Next, you should go folder where the malicious file is located and delete it
Repair Windows Registry
1. Again type simultaneously the WIN Key + R key combination
2. In the box, write regedit and hit Enter
3. Type the CTRL+ F and then write the malicious name in the search type field to locate the malicious executable
4. In case you have discovered registry keys and values related to the name, you should delete them, but be careful not to delete legitimate keys
Click for more information about Windows Registry and further repair help
Recover THT Locker Virus Files
WARNING! All files and objects associated with THT Locker Virus should be removed from the infected PC before any data recovery attempts. Otherwise the virus may encrypt restored files. Furthermore, a backup of all encrypted files stored on external media is highly recommendable.
DOWNLOAD THT Locker Virus Removal ToolSpyHunter anti-malware tool will diagnose all current threats on the computer. By purchasing the full version, you will be able to remove all malware threats instantly. Additional information about SpyHunter / Help to uninstall SpyHunter
1. Use present backups
2. Use professional data recovery software
Stellar Phoenix Data Recovery – a specialist tool that can restore partitions, data, documents, photos, and 300 more file types lost during various types of incidents and corruption.
3. Using System Restore Point
-
– Hit WIN Key
– Select “Open System Restore” and follow the steps
4. Restore your personal files using File History
-
– Hit WIN Key
– Type restore your files in the search box
– Select Restore your files with File History
– Choose a folder or type the name of the file in the search bar
– Hit the “Restore” button