Firstkill Ransomware šŸ” (. Firstkill File) — Removal Guide

Firstkill Ransomware šŸ” (. Firstkill File) — Removal Guide

What is Firstkill virus?

Firstkill appends its own .FirstKill extension to every file’s name. For instance, an image entitled ā€œphoto.jpgā€ will be turned into ā€œphoto.jpg.FirstKillā€. In the same manner, the Excel sheet with the name ā€œtable.xlsxā€ will be renamed to ā€œtable.xlsx.FirstKillā€, and so on.

In each directory with the encoded files, a CO_SIĘ_STAŁO.html file will appear. It is a ransom money note. It contains information about the ways of paying the ransom and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. That is it.

NameFirstkill Virus
Extension.FirstKill
Ransomware noteCO_SIĘ_STAŁO.html
Detection1Troj/GandCrab-A, Trojan:Win32/Glupteba.NI!MTB, Ransom:Win32/StopCrypt.SLH!MTB
SymptomsYour files (photos, videos, documents) get a .FirstKill extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Firstkill virus

In the image below, you can see what a folder with files encrypted by the Firstkill looks like. Each filename has the ā€œ.FirstKillā€ extension added to it.

An example of encrypted .FirstKill files.

How did my computer get infected with Firstkill ransomware?

There are currently three most popular methods for hackers to have ransomware acting in your system. These are email spam, Trojan injection and peer-to-peer networks.

If you access your mailbox and see letters that look just like notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is strange to you, be wary of opening those emails. They are most likely to have a harmful item attached to them. Therefore, it is even more dangerous to download any attachments that come with emails like these.

Another option for ransom hunters is a Trojan virus model2. A Trojan is a program that infiltrates into your PC disguised as something different. Imagine, you download an installer for some program you need or an update for some service. But what is unpacked reveals itself a harmful program that encodes your data. Since the installation wizard can have any title and any icon, you have to make sure that you can trust the resource of the things you’re downloading. The best thing is to use the software companies’ official websites.

As for the peer-to-peer file transfer protocols like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded items with the anti-malware utility as soon as the downloading is done.

Elena Rostova
Author

Elena Rostova

Elena Rostova holds a Master's degree in Public Health Journalism. She covers groundbreaking medical research, holistic wellness trends, mental health awareness, and nutritional science.