What is Firstkill virus?
Firstkill appends its own .FirstKill extension to every fileās name. For instance, an image entitled āphoto.jpgā will be turned into āphoto.jpg.FirstKillā. In the same manner, the Excel sheet with the name ātable.xlsxā will be renamed to ātable.xlsx.FirstKillā, and so on.
In each directory with the encoded files, a CO_SIÄ_STAÅO.html file will appear. It is a ransom money note. It contains information about the ways of paying the ransom and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. That is it.
| Name | Firstkill Virus |
| Extension | .FirstKill |
| Ransomware note | CO_SIÄ_STAÅO.html |
| Detection1 | Troj/GandCrab-A, Trojan:Win32/Glupteba.NI!MTB, Ransom:Win32/StopCrypt.SLH!MTB |
| Symptoms | Your files (photos, videos, documents) get a .FirstKill extension and you canāt open them. |
| Fix Tool | See If Your System Has Been Affected by Firstkill virus |
In the image below, you can see what a folder with files encrypted by the Firstkill looks like. Each filename has the ā.FirstKillā extension added to it.
How did my computer get infected with Firstkill ransomware?
There are currently three most popular methods for hackers to have ransomware acting in your system. These are email spam, Trojan injection and peer-to-peer networks.
If you access your mailbox and see letters that look just like notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is strange to you, be wary of opening those emails. They are most likely to have a harmful item attached to them. Therefore, it is even more dangerous to download any attachments that come with emails like these.
Another option for ransom hunters is a Trojan virus model2. A Trojan is a program that infiltrates into your PC disguised as something different. Imagine, you download an installer for some program you need or an update for some service. But what is unpacked reveals itself a harmful program that encodes your data. Since the installation wizard can have any title and any icon, you have to make sure that you can trust the resource of the things youāre downloading. The best thing is to use the software companiesā official websites.
As for the peer-to-peer file transfer protocols like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded items with the anti-malware utility as soon as the downloading is done.