FacebookTwitterLinkedIn

TorLocker Virus

Also Known As: TorLocker ransomware
Damage level: Severe

What is TorLocker?

The TorLocker ransomware virus infiltrates operating systems via infected email messages (spam), exploit kits, botnets (commonly Andromeda), and fake software updates.

After successful infiltration, this malicious program encrypts files (*.3gp, *.avi, *.doc, *.docx, *.jpg, *.mov, *.mp3, *.mp4, *.pdf, *.png, *.psd, *.rar, *.wma, *.zip, etc.) stored on computers and demands payment of a US$300 ransom (using BitCoins, UKash, or PaySafeCard) to decrypt them. Cyber criminals responsible for releasing this rogue program ensure that it executes on all Windows versions (Windows XP, Windows Vista, Windows 7, and Windows 8).

torlocker ransomware

The developers of this malware use the Tor network (Tor is free software that prevents people from obtaining your location or browsing habits) to hide their identities. To encourage victims to pay the ransom, TorLocker threatens to delete the private key required to decrypt the files unless the user makes a ransom payment within 72 hours.

PC users should beware that recent security research by Kaspersky resulted in the introduction of a free decrypt tool to regain control of files compromised by this ransomware.

According to Kaspersky Lab, the ScraperDecryptor utility is effective in over 70% of cases (the compromised files can be decrypted, since Cyber criminals made several mistakes during implementation of cryptography algorithms).

Screenshot of TorLocker ransomware targeted at PC users who speak Japanese:

torlocker ransomware targeted at japan users

Ransomware infections such as TorLocker (including CryptoWall, CryptoDefense, CryptorBit, and Cryptolocker) present a strong case for users to maintain regular backups of their stored data.

Note that paying the ransom as demanded by this ransomware is equivalent to sending your money to cyber criminals - you will support their malicious business model and there is no guarantee that your files will ever be decrypted.

To avoid computer infection with ransomware infections such as this, express caution when opening email messages, since cyber criminals use various catchy titles to trick PC users into opening infected email attachments (for example, 'UPS Exception Notification').

At time of writing, a file decryption tool was available, however, Cyber criminals are able update this malware at any time, and therefore, this tool may become useless. To protect your computer from file encrypting ransomware infections, use reliable security programs and make regular backups of your stored data.

After successful infiltration, TorLocker ransomware changes victims' desktop wallpaper:

torlocker ransomware wallpaper

Messages presented by TorLocker ransomware:

TorLocker - Your important files produced in this computer and network shares: photos, videos, documents, pdf, music, auto cad, spreadsheets, etc., were encrypted. If you see this text but do not see the “TorLocker” window, then your antivirus removed “TorLocker” from your computer. If you need your files back, you have to recover “TorLocker” from the antivirus quarantine, or find a copy of “TorLocker” in the Internet and start it again. Please disable any Firewall or Antivirus permanently if the Payment address don’t show to you. You can download “TorLocker: from the link given below, using the tool “Tor Browser Bundle”.
Your personal files are encrypted! Your important files are encrypted produced on this computer: photos, videos, documents, etc. Click to see a complete list of encrypted files, and you can verify this. Encryption was produced using a unique public key RSA-2048 generated for this computer. To decrypt files your need to obtain private key. The single copy of the private key, which will allow you to decrypt the files, is located on a secret server on the Internet, the server will destroy the key after a time specified in this window. After that, nobody will never be able to restore your files… To obtain the private key for this computer, which will automatically decrypt your files, you need to pay 300 USD/ 300 EUR/ 300 CAD / similar to amount in another currency. Any attempt to remove or damage this software will lead to the immediate destruction of the private key by the server.

At time of writing, there was a tool capable of decrypting files encrypted by TorLocker without paying the ransom. By following this removal guide, you will be able to remove TorLocker ransomware from your computer. In addition, this guide will enable you to regain control of your compromised data.

TorLocker ransomware removal:

Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.

Quick menu:

Step 1

Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, then select Safe Mode with Networking from the list.

Safe Mode with Networking

Video showing how to start Windows 7 in "Safe Mode with Networking":

Windows 8 users: Go to the Windows 8 Start Screen, type Advanced, in the search results select Settings. Click on Advanced Startup options, in the opened "General PC Settings" window select Advanced Startup. Click on the "Restart now" button. Your computer will now restart into "Advanced Startup options menu".

Click on the "Troubleshoot" button, then click on "Advanced options" button. In the advanced option screen click on "Startup settings". Click on the "Restart" button. Your PC will restart into the Startup Settings screen. Press "5" to boot in Safe Mode with Networking.

Windows 8 Safe Mode with networking

Video showing how to start Windows 8 in "Safe Mode with Networking":

Step 2

Log in to the account infected with the TorLocker virus. Start your Internet browser and download a legitimate anti-spyware program. Update the anti-spyware software and start a full system scan. Remove all entries detected.


If you cannot start your computer in Safe Mode with Networking, try performing a System Restore.

Video showing how to remove ransomware virus using "Safe Mode with Command Prompt" and "System Restore":

1. During your computer start process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When Command Prompt mode loads, enter the following line: cd restore and press ENTER.

system restore using command prompt type cd restore

3. Next, type this line: rstrui.exe and press ENTER.

system restore using command prompt rstrui.exe

4. In the opened window, click "Next".

restore system files and settings

5. Select one of the available Restore Points and click "Next" (this will restore your computer system to an earlier time and date, prior to the TorLocker ransomware virus infiltrating your PC).

select a restore point

6. In the opened window, click "Yes".

run system restore

7. After restoring your computer to a previous date, download and scan your PC with recommended malware removal software to eliminate any remaining TorLocker files.

If you were not able to decrypt your files using ScraperDecryptor utility developed by Kaspersky Lab, try using Windows Previous Versions and Shadow Explorer:

To restore individual files encrypted by this ransomware, try using the Windows Previous Versions feature. This method is only effective if the System Restore function was enabled on an infected operating system. Note that some variants of TorLocker are known to remove Shadow Volume Copies of the files, so this method may not work on all computers.

To restore a file, right-click on it, go into Properties, and select the Previous Versions tab. If the relevant file has a Restore Point, select it and click the "Restore" button.

Restoring files encrypted by CryptoDefense

If you cannot start your computer in Safe Mode with Networking (or with Command Prompt), boot your computer using a rescue disk. Some variants of ransomware disable Safe Mode, thus making its removal complicated. For this step, you require access to another computer.

To regain control of the files encrypted by TorLocker you can also try using a program called Shadow Explorer. More information on how to use this program is available here.

shadow explorer screenshot

To protect your computer from such file encrypting ransomware, you should use reputable antivirus and anti-spyware programs.

cryptoprevent screenshot

Other tools known to remove TorLocker ransomware:

▼ Show Discussion

About the author:

Tomas Meskauskas

Tomas Meskauskas - expert security researcher, professional malware analyst.

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats. Contact Tomas Meskauskas.

PCrisk security portal is brought by a company RCS LT. Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Removal Instructions in other languages
Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

QR Code
TorLocker ransomware QR code
Scan this QR code to have an easy access removal guide of TorLocker ransomware on your mobile device.
We Recommend:

Get rid of Windows malware infections today:

▼ REMOVE IT NOW
Download Combo Cleaner

Platform: Windows

Editors' Rating for Combo Cleaner:
Editors ratingOutstanding!

[Back to Top]

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.