What is ZeroFucks ransomware? And how does it carry out its attack?

ZeroFucks ransomware is a data-encrypting virus that has been spotted recently. It is created to encrypt important data in a targeted machine and adds the “.zerofucks” extension to each one of the files it encrypt. As soon as it enters a targeted computer, it starts to execute a sequence of attack. First, it employs a data gathering module used to collect information from the system. The information collected is classified into two, namely personal information and anonymous metric. After that, it uses the second module called stealth protection to bypass certain applications and services like antivirus programs, firewalls, and sandbox environments. Once these two modules are completed, ZeroFucks ransomware will start to modify system setting specifically the Windows Registry where it messes with some registry keys and sub-keys, allowing it to automatically run on every system boot. After that, it encrypts files that are mostly user-generated using the AES 256 cipher and opens a ransom note named Bitcoin_Address.txt which contains the following message:
“All your files are locked!
[Unlock]
All your important files have been encrypted.
If you want your files back, you need to pay €400 in Bitcoins.
After the payment is received, we will give you access to unlock your files.
Click on the Payment button to get more info.
If you don’t pay within 48 hours, the price will be doubled.
After another 24 hours, the price will be doubled again.
If you don’t pay within 96 hours your files will be destroyed.

User-ID: 28NNL272XC
Important
Payment

If you close me or shutdown your pc without paying, you won’t be able to unlock your files again!
We guarantee that you will get your files back if you pay!
You can find more info about paying by clicking on the payment button.

You can create a Bitcoin wallet on site’s like:
{www.blockchain.com} or {www.coinbase.com}
You can also buy Bitcoins on these websites.
There are plenty of site to buy bitcoins from.
After you’ve bought €400 worth of Bitcoins, send it to the address wich you can copy below.
Put your user-ID in the description of the transaction!
If we have received your payment, we will give you access to unlock your files.
Click on the Unlock button and follow the instruction there.
If you don’t put your user-ID in the description of the transaction, we don’t know if you have payed! (you can see your User-ID under the time left)

If you have payed, click on the Check button to see if we received your payment.
If we do, we will give you access to unlock your files.
It can take some time to decrypt all your files.
Restart your pc after the program is done with decrpyting.
After restarting your pc, you can use all your files again.”
How does ZeroFucks ransomware proliferate?
It isn’t clear how exactly the ZeroFucks ransomware proliferates but it could use malicious spam email campaigns – a distribution method utilized by many perpetrators. These kinds of emails contain an infected attachment which may look legitimate and safe as crooks tend to disguise them to lure users into downloading and opening the attachment. Thus, the next time you download or open any attachment or link, make sure that you’ve done a thorough check first.
To successfully Kill ZeroFucks ransomware from your infected computer, follow the removal guide laid out below as well as the advanced steps that comes next.
Step 1: First, restart your PC and boot into Safe Mode with Command Prompt by tapping F8 a couple of times until the Advanced Options menu appears.

Step 2: Next, navigate to Safe Mode with Command Prompt using the arrow keys on your keyboard. After selecting Safe Mode with Command Prompt, hit Enter.
Step 3: After loading the Command Prompt type cd restore and hit Enter.

Step 4: After cd restore, type in rstrui.exe and hit Enter.

Step 5: A new window will appear, and then click Next.

Step 6: Select any of the Restore Points on the list and click Next. This will restore your computer to its previous state before being infected with the ZeroFucks Ransomware. A dialog box will appear, and then click Yes.

Step 7: After System Restore has been completed, try to enable the disabled Windows services.

  1. Press Win + R keys to launch Run.
  2. Type in msc in the box and press Enter to open Group Policy.
  3. Under Group Policy, navigate to:
    1. User Configuration\Administrative Templates\System
  4. After that, open Prevent access to the command prompt.
  5. Select Disable to enable cmd
  6. Click the OK button
  7. After that, go to:
    1. Configuration\Administrative Templates\System
  8. Double click on the Prevent Access to registry editing tools.
  9. Choose Disabled and click OK.
  10. Navigate to :
    1. User Configuration\Administrative Templates\System>Ctrl+Alt+Del Options
  11. Double click on Remove Task Manager.
  12. And then set its value to Disabled.

Step 8: Next, tap Ctrl + Shift + Esc to open the Task Manager and then go to the Processes tab and look for the malicious processes of ZeroFucks Ransomware and end them all.
Step 9: Open Control Panel by pressing Start key + R to launch Run and type appwiz.cpl in the search box and click OK to open the list of installed programs. From there, look for ZeroFucks ransomware or any malicious program and then Uninstall it.

Step 10: Tap Windows + E keys to open the File explorer then navigate to the following directories and delete the malicious files created by ZeroFucks ransomware such as “Bitcoin_Address.txt” and “[random].exe”.

  • %UserProfile%\AppData
  • %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
  • %TEMP%.
  • %USERPROFILE%\Downloads
  • %USERPROFILE%\Desktop

Step 11: Close the File Explorer.
Before you proceed to the next steps below, make sure that you are tech savvy enough to the point where you know exactly how to use and navigate your computer’s Registry. Keep in mind that any changes you make will highly impact your computer. To save you the trouble and time, you can just use [product-name], this system tool is proven to be safe and excellent enough that hackers won’t be able to hack into it. But if you can manage Windows Registry well, then by all means go on to the next steps.
Step 12: Tap Win + R to open Run and then type in regedit in the field and tap enter to pull up Windows Registry.

Step 13: Navigate to the paths listed below and delete all the registry values added by ZeroFucks ransomware.

  • HKEY_CURRENT_USER\Control Panel\Desktop\
  • HKEY_USERS\.DEFAULT\Control Panel\Desktop\
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

Step 14: Close the Registry Editor and empty your Recycle Bin.
After you’re done with the steps given above, you can recover your files by downloading this free decrypter from Emisoft. Once you’re done recovering your encrypted files, you need to continue the ZeroFucks ransomware removal process using a reliable program like [product-name]. How? Follow the advanced removal steps below.
Perform a full system scan using [product-code]. To do so, follow these steps:

  1. Turn on your computer. If it’s already on, you have to reboot it.
  2. After that, the BIOS screen will be displayed, but if Windows pops up instead, reboot your computer and try again. Once you’re on the BIOS screen, repeat pressing F8, by doing so the Advanced Option shows up.

  1. To navigate the Advanced Option use the arrow keys and select Safe Mode with Networking then hit
  2. Windows will now load the Safe Mode with Networking.
  3. Press and hold both R key and Windows key.

  1. If done correctly, the Windows Run Box will show up.
  2. Type in the URL address, [product-url] in the Run dialog box and then tap Enter or click OK.
  3. After that, it will download the program. Wait for the download to finish and then open the launcher to install the program.
  4. Once the installation process is completed, run [product-code] to perform a full system scan.

  1. After the scan is completed click the “Fix, Clean & Optimize Now” button.

logo main menu

Copyright © 2024, FixMyPcFree. All Rights Reserved Trademarks: Microsoft Windows logos are registered trademarks of Microsoft. Disclaimer: FixMyPcFree.com is not affiliated with Microsoft, nor claim direct affiliation. The information on this page is provided for information purposes only.

DMCA.com Protection Status

Log in with your credentials

Forgot your details?