Threat Database Ransomware [decryptyourdata@qq.com].bat Ransomware

[decryptyourdata@qq.com].bat Ransomware

By GoldSparrow in Ransomware

The [decryptyourdata@qq.com].bat Ransomware enters its victims' computers with the objective of encrypting their files, which prevent the victims from accessing them. The [decryptyourdata@qq.com].bat Ransomware uses this tactic so that it can convince unprotected users to pay a determined amount, usually in Bitcoins, to recover their data and the access to the infected machine. To make the files unusable. The [decryptyourdata@qq.com].bat Ransomware adds the files extension .bat to their names and then generates a text file named 'RETURN FILES.txt, which contains the [decryptyourdata@qq.com].bat Ransomware's ransom note. Below, you can read the written text of the ransom note presented by [decryptyourdata@qq.com].bat Ransomware to its victims:

'All FILES ENCRYPTED "RSA1024"
All YOUR FILES HAVE BEEN ENCRYPTED!!! IF YOU WANT TO RESTORE THEM, WRITE US TO THE E-MAIL decryptyourdata@qq.com
IN THE LETTER WRITE YOUR ID, YOUR ID 1E857D00
IF YOU ARE NOT ANSWERED, WRITE TO EMAIL:decryptyourdata@qq.com
YOUR SECRET KEY WILL BE STORED ON A SERVER 7 DAYS, AFTER 7 DAYS IT MAY BE OVERWRITTEN BY OTHER KEYS, DON'T PULL TIME, WAITING YOUR EMAIL
FREE DECRYPTION FOR PROOF
You can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
DECRYPTION PROCESS:
When you make sure of decryption possibility transfer the money to our bitcoin wallet. As soon as we receive the money we will send you:
1. Decryption program.
2. Detailed instruction for decryption.
3. And individual keys for decrypting your files.
!WARNING!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.'

The ransom note provides one email address, decryptyourdata@qq.com, which should be used to contact its perpetrators, as well as the victims' ID. The response supported by security researches to a [decryptyourdata@qq.com].bat Ransomware infection is to ignore the criminals' instructions and use a backup of your files to recover the data you lost. However, in the first place, you need to remove the [decryptyourdata@qq.com].bat Ransomware by using a dependable anti-malware program.

Trending

Most Viewed

Loading...