Maktub Ransomware

What is Maktub Ransomware?

Maktub Locker is a malicious program that encrypts your files and forces you to pay a ransom. Although it promises that you will receive your decryption key after paying a certain amount of bitcoins, there are no guarantees that you will get it for sure. Do not start panicking as there are a few ways you can get rid of this malware. However, without the decryption key, the files on your computer will be lost, since it is impossible to decrypt them on your own. Under these circumstances, you should think about all the important files on your computer, and if you have made some copies, then you can delete Maktub Locker with no worries. You could use the removal instructions provided below, but when it comes to such serious infections like this ransomware, it is always better to leave this job for reliable security tools.testtesttest

How does Maktub Locker work?

It is possible that you launched a malicious file that looked like a Notepad or Word document, but it was an executable file with a random name. After 20-60 seconds the infection will open a Rich text document that should have the same name as the executable file, but its extension should be “.rtf”. The text inside of it says about some software’s Privacy Policy changes, and it will not make any sense to you. Our researchers at Anti-spyware-101.com think that it is only a distraction because at the same time the ransomware will encrypt your files.

After a couple of minutes, Maktub Ransomware creates a folder on the desktop that is named as backup but has a random ending, e.g. “backup_elijxri” and places its files there. The random part of the folder filename (e.g. “elijxri”) will also appear on all of the encrypted data as their extension, e.g. picture1.jpg.elijxri. At this point, you can no longer use your data. You will also notice a pop-up that appears on your screen; it has a black skull, and the letters should say “Maktub Locker”. It will state that “your documents, photos, databases and other important files have been encrypted with strongest encryption and unique key, generated for this computer.” Besides, you should see a clock that is set for 12 hours; this is how much time you are given to pay the ransom. If you do not put up with their demands they threaten to delete the decryption key after the time runs out. Apparently, the pop-up is not only there to scare you, but it also has the instructions that tell you how to pay the ransom or reach the secret servers with your private key for the decryption process. As we mentioned before, there is no reassurance that these cyber criminals will keep up to their word, so if you have copies of your most important files somewhere else, do not hesitate and get rid of the ransomware.

How to remove Maktub Ransomware?

If you want to delete this malware manually, there are a few tasks you should do. For starters, you will have to find the malicious file process through the task manager and end it. Unfortunately, this file should have a random name, and it might be different for each user. Therefore, you will have to identify it on your own. You should look for any files that do not make any sense to you on your desktop, the downloads folder, temporarily files folders, etc., as these are the main locations where infections like this one place their files. When you locate it, you should end the malicious file’s process and then delete it from your computer too. Also, you should erase the folder that was created on your desktop, and it should have a file that could look like this one “_DECRYPT_INFO_elijxri.html”. For more instructions you could check the provided removal steps below the text. As you realize, manual deletion is not an easy task to do, especially for inexperienced users. That is why it would be more advisable to get rid of Maktub Locker with a legitimate antimalware tool that will find all its files on your system and delete it in a few moments.

Delete Maktub Ransomware

  1. Press Ctrl+Alt+Delete to open the Task Manager.
  2. Choose the Processes tab.
  3. Find the malicious file process and click End Task button.
  4. Locate the malicious file in your system, right-click it and select Delete.
  5. Find the folder on your desktop, e.g. “backup_elijxri”
  6. Locate .html file in the folder, e.g. “_DECRYPT_INFO_elijxri.html” and right-click to delete it.
  7. Remove the folder from your desktop.
  8. Empty your Recycle bin.
100% FREE spyware scan and
tested removal of Maktub Ransomware*
Disclaimer
Disclaimer

Leave a Comment

Enter the numbers in the box to the right *