If your files have been renamed with the text [email protected], you are most likely the victim of a ransomware. A ransomware is a kind of malware (malicious software) installed by cyber-criminals without your consent. A ransomware allows them to crypt your files remotely. Afterwards it will show you a message saying that you need to pay a ransom to have access to them again. Ransomware like the one installed by [email protected] are usually installed when you download some malicious attachment you got by e-mail, or by clicking on an infected link you got on an instant message or social network. It could have also been installed if you visit some malicious website…
In the particular case of this ransomware, files crypted by [email protected] are renamed with the extension: id-[idcode][email protected].
If you try to contact the ransomware’s creators by writing them using the address, [email protected] you’ll get the following answer:
If you wish to get all your files back, you need to pay 4 BTC.
How to get bitcoins?
1. Bitcoin ATMs www.coinatmradar.com
2. www.localbitcoins.com
3. google: buy bitcoins
This is the only way to get your files back.
There’s no way to decrypt them without the original key.
The price is non-negotiable.
After paying 4 BTC and emailing the confirmation of payment you will be provided with a decoder.
If you don’t trust me, you can email one of your files, I will decode it and send it back to you.
However, if the file you’re requesting to decode is valuable, I will send you either a quote from it or a screenshot.
I apologise for any inconvenience caused.
Let me know if you want to proceed.
As you can see you’re asked to pay 4 bitcoins to free your files, that’s roughly 900 € ! Of course we recommend not to fall into this trap and pay them nothing at all, you have no warranty that they will keep their promise to help you once you’ve paid them.
Use the following guide to remove the ransomware with the recommended free software. In the last part of the guide you’ll find some steps to try to recover your files.
How to remove [email protected] ?
Remove [email protected] with MalwareBytes Anti-Malware
Malwarebytes Anti-Malware dis a light-weight anti-malware program that is excellent at removing the latest detections.
- Download Malwarebytes Anti-Malware to your desktop.
Premium Version Free Version (without Real-time protection) - Install MalwareBytes Anti-Malware using the installation wizard.
- Once installed, Malwarebytes Anti-Malware will automatically start and you will see a message stating that you should update the program, and that a scan has never been run on your system. To start a system scan you can click on the Fix Now button.
- If an update is found, you will be prompted to download and install the latest version.
- Malwarebytes Anti-Malware will now start scanning your computer for [email protected].
- When the scan is complete, make sure that everything is set to Quarantine, and click Apply Actions.
- When removing the files, Malwarebytes Anti-Malware may require a reboot in order to remove some of them. If it displays a message stating that it needs to reboot your computer, please allow it to do so.
Remove [email protected] with HitmanPro
HitmanPro is a second opinion scanner designed to rescue computers that have become infected with viruses, spyware, Trojans, rootkits and other malware, despite continuous protection from up-to-date antivirus software.
- You can download HitmanPro from the below link:
Download HitmanPro - Double-click on the file named HitmanPro.exe (for 32-bit versions of Windows) or HitmanPro_x64.exe (for 64-bit versions of Windows).
- Click on the Next button, to install HitmanPro on your computer.
- HitmanPro will now begin to scan your computer for [email protected] malicious files.
- When it has finished it will display a list of all the malware that the program found as shown in the image below. Click on the Next button, to remove [email protected] virus.
Click here to go to our support page.