{
	"id": "dcbc1030-5cab-4ab1-96b3-c15c72f1611f",
	"created_at": "2026-04-06T00:15:49.779682Z",
	"updated_at": "2026-04-10T03:21:27.96272Z",
	"deleted_at": null,
	"sha1_hash": "3810c8806ea0dfe58ce071b836f03589732e5b4b",
	"title": "InfinityLock Ransomware",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 54053,
	"plain_text": "InfinityLock Ransomware\r\nArchived: 2026-04-05 19:34:05 UTC\r\nPosted by Max Lehmann on September 21, 2017\r\nWhat is InfinityLock Ransomware?\r\nWe want to inform you about a newly found ransomware-type computer malware called InfinityLock\r\nRansomware. This program is dangerous because it masquerades as a crack for Adobe Premier, so it can infect\r\nyour PC secretly and then encrypt many of your files. Its creators want you to pay for a decryption key that is not\r\ncheap. However, do not recommend you just to jump right in and pay the ransom because it is possible that the\r\ncybercriminals behind this ransomware will not decrypt your files. If you want to find out more about this highly\r\ndangerous, we suggest you read this short description.\r\nWhat does InfinityLock Ransomware do?\r\nAs a ransomware-type program, InfinityLock Ransomware is dedicated to encrypting your files which it does with\r\na combination of the RSA an AES encryption methods. As a result, the files are subject to a strong encryption and\r\ndecrypting them using a third-party tool is unlikely but then again, there is no free decryptor tailored for this\r\nparticular ransomware.\r\nThis ransomware was configured to encrypt files only in predetermined locations, so many of your files can avoid\r\nencryption. According to our malware analysts, this ransomware can encrypt files located in the following\r\nlocations.\r\n%PUBLIC%\r\n%USERPROFILE%\\Documents\r\n%USERPROFILE%\\Pictures\r\n%USERPROFILE%\\Videos\r\n%USERPROFILE%\\OneDrive\r\n%USERPROFILE%\\Music\r\n%USERPROFILE%\\Downloads\r\n%USERPROFILE%\\Desktop\r\n%PROGRAMFILES%\r\n%PROGRAMFILES(X86)%\r\n%COMMONPROGRAMFILES%\r\n%COMMONPROGRAMFILES(X86)%\r\nInfinityLock Ransomware encrypts a wide variety of file types that include pictures, videos, audios, documents,\r\ndatabases, file archives, executable files, and so on. It appends all encrypted files with a “.HWID” file extension\r\nthat acts as a file marker. Basically, the cybercriminals behind this ransomware want to encrypt as many of your\r\nfiles as possible to compel you to pay a 0.17 BTC (Bitcoins) ransom that translates to almost 650 USD.\r\nhttps://anti-spyware-101.com/remove-infinitylock-ransomware\r\nPage 1 of 3\n\nAfter it has encrypted your files, InfinityLock Ransomware drops a ransom note named\r\nnfinityLock_Recover_Instructions.txt on the desktop. The note says how much you have to pay and how to buy\r\nBitcoins to do that. Furthermore, it drops a text file named InfinityLock_UniqeID.txt that features a unique ID that\r\nyou can send together with the ransom. However, we urge you to refrain from paying the ransom because there is\r\nno telling whether the cybercriminals will pay the ransom.\r\nWhere does InfinityLock Ransomware come from?\r\nWhile most ransomware is distributed using email spam and security exploits, InfinityLock Ransomware is\r\ndifferent. Our cyber security experts have received information that this new ransomware is distributed disguised\r\nas a crack for Adobe Premier. If you launch this file, it will start encrypting your files immediately. This crack is\r\nprobably featured on some website that distributes cracks. Nevertheless, this crack might also be included along\r\nwith the software itself and distributed via torrent websites. Unfortunately, no concrete information has surfaced\r\non what websites host this fake crack.\r\nHow do I remove InfinityLock Ransomware?\r\nSince there is no guarantee that your files will be decrypted and the fact that your files might not be worth the\r\nmoney, we recommend that you remove InfinityLock Ransomware program from your PC as soon as the\r\nopportunity arises. We suggest using our manual removal guide that includes the most likely places this\r\nransomware might reside. Nevertheless, you can also get an antimalware program such as SpyHunter to do the\r\nfinding and the deleting for you.\r\nRemoval Guide\r\n1. Press Windows+E keys to open File Explorer.\r\n2. In the address box, enter the following locations and locate the malicious executable.\r\n%WINDIR%\\Syswow64\r\n%WINDIR%\\System32\r\n%ALLUSERSPROFILE%\\Start Menu\\Programs\\Startup\r\n%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\r\n%USERPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\r\n%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\r\n%ALLUSERSPROFILE%\\Application Data\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\r\n%USERPROFILE%\\Desktop\r\n%USERPROFILE%\\Downloads\r\n%TEMP%\r\n3. Find and right-click the executable and click Delete.\r\n4. Then, go to the desktop and delete InfinityLock_UniqeID.txt and InfinityLock_Recover_Instructions.txt\r\n5. Right-click the Recycle Bin and click Empty Recycle Bin. Download Removal Tool100% FREE spyware\r\nscan and\r\ntested removal of InfinityLock Ransomware*\r\nhttps://anti-spyware-101.com/remove-infinitylock-ransomware\r\nPage 2 of 3\n\nSource: https://anti-spyware-101.com/remove-infinitylock-ransomware\r\nhttps://anti-spyware-101.com/remove-infinitylock-ransomware\r\nPage 3 of 3",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"Malpedia"
	],
	"references": [
		"https://anti-spyware-101.com/remove-infinitylock-ransomware"
	],
	"report_names": [
		"remove-infinitylock-ransomware"
	],
	"threat_actors": [],
	"ts_created_at": 1775434549,
	"ts_updated_at": 1775791287,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/3810c8806ea0dfe58ce071b836f03589732e5b4b.pdf",
		"text": "https://archive.orkl.eu/3810c8806ea0dfe58ce071b836f03589732e5b4b.txt",
		"img": "https://archive.orkl.eu/3810c8806ea0dfe58ce071b836f03589732e5b4b.jpg"
	}
}