C0hen Locker - How to remove

C0hen locker is a ransomware infection for Windows PCs. It was noticed by the security researcher Jack on Twitter. C0hen locker locks your files and asks you to download Discord to add the author of this ransomware (presumably) and ask them for the decryption key.

C0hen locker in short:

Type of threat Ransomware.
Consequences of infection Files are renamed to have “.c0hen” as a second extension,

files don’t open anymore.

How to fix the C0hen files Restore them from a backup,

restore lost files,

get the decryption key.

Remove the malware Use anti-malware tools (like SpyHunter) to get rid of malware,

delete malicious files that caused the infection.

How C0hen locker works

Encryption

C0hen locker takes the files on your computer, runs them through an encryption algorithm, and deletes the originals. Your files are renamed to end with “.c0hen” and their internal content is messed up by the encryption. After all, encryption turns meaningful information into gibberish. So, after C0hen locker is done with your computer, you can’t open your files anymore.

It’s really that simple. There is no way to trick the files or to modify them. Encryption has already made most of them unreadable. Your options to get your files back are these:

  • restore your files from a backup,
  • restore your files from shadow volume copies,
  • recover deleted files,
  • get the decryption key and decrypt the files.

Besides locking your files, C0hen locker also disables your task manager – so even if you notice it mid-encryption, it can be hard to stop the ransomware before harm is done. Best to turn your computer off in that case. If C0hen locker can’t run, it can’t do harm.

Ransom demands

After C0hen locker is done ruining your files, it opens a window with demands and a button called “decrypt”:

Warning: If you turn your PC off you will not get your files back!!!
C0hen locker has infected your PC
Whats happening?
All devices on your network have been infected
All of your computers files have been encrypted with ransomware
Your computer has been infected. You must do as instructed to et your files back.
Donate 0.15 BTC to this wallet
Or:
Download discord and add c0hen#7722 for decryption key discord.com/download

C0hen locker’s makers ask for 0.15 Bitcoin, which is currently worth around one thousand dollars. As an alternative, there’s an offer to contact the person on Discord and ask for the decryption key.

C0hen locker's ransom note gives a bitcoin wallet for ransom payments.

How to avoid ransomware

C0hen locker using symmetric encryption, failing to delete shadow volume copies, and its creators using Discord seem to show that this infection, though genuinely harmful, isn’t made totally seriously. It’s still important to take this chance to learn how to avoid ransomware infections:

  • first, use a good anti-malware program and update it regularly,
  • update your browser, too, so that malware can’t abuse security bugs in it,
  • be careful with pirating because some of those downloads are infected,
  • most importantly – make backups of your files.

Although we mostly hear about ransomware attacking hospitals, businesses, and municipalities, malware like HiddenBeer, Redl, Eris were created to infect individual PCs. That’s why we should be careful and vigilant.

When it comes to individual PC users, infected advertisements and piracy sites are pretty common in distributing ransomware. Infected ads may be stopped by you installing software updates for your browser and OS. But if you download cracks and “free” files a lot, it’s imperative to use your antivirus program to scan every download.

How to fix C0hen files

When it comes to restoring your files, you can just ask for the decryption key. Discord is a safe program and, as long as you’re careful about what links you click and what files you download and run, you will be fine. If you get a working key, that’s great. Just do not use your personal account (create a new one) and do not reveal your personal information.

The person who discovered C0hen locker did that and got this key:

12309482354ab2308597u235fnq30045f

But what if that doesn’t work? There are still a few options.

First, you should get rid of the infection so that C0hen can’t lock your files again. Delete C0hen locker and the file that infected you manually – or, to be safe, scan your computer with an anti-malware program, such as SpyHunter. As you can see on this Hybrid Analysis page, C0hen locker is recognized as malware by most antivirus programs. Not only does C0hen locker need to be removed, but it’s also good to check your computer for other malware. Ransomware spreads the same ways that other malware does, so if you have one infection, you may have a few more. Also, you may want to change your passwords because some ransomware infections double as spyware.

Although C0hen locker does delete your original, unencrypted files, it doesn’t seem to delete your shadow copies or your restore points. You can just take your computer back in time to the last good restore point or fix your files by going to their previous versions.

If you didn’t have backups there, as a last resort, you can use a data recovery program. Just be very careful and follow all the instructions. With that sort of thing, you only have one chance to get it right.

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,


How to recover C0hen Locker encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:


for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode
 

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again.CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before C0hen locker has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3
 

Step 2. Complete removal of C0hen Locker

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Spyhunter and remove all malicious files related to C0hen locker. You can check other tools here.  

Step 3. Restore C0hen Locker affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually C0hen locker tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so. Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer. a) Native Windows Previous Versions Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.
Previous version
b) Shadow Explorer It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover C0hen Locker encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:
  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download a data recovery program.
  • Install and scan for recently deleted files. Data Recovery Pro
Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.
Leave a Reply

Your email address will not be published. Required fields are marked *