Hey you,
BE IN THE KNOW!

35,000 ransomware infections per month and you still believe you are protected?

Sign up to receive:

  • alerts
  • news
  • free how-to-remove guides

of the newest online threats - directly to your inbox:


DotRansomware RaaS Remove and Restore Files


This article aims to help you remove the iterations of DotRansomware and restore your files (.locked file extension) if they have been encrypted by it.

A ransomware-as-a-service virus, calling itself DotRansomware has appeared on the deep web. The virus has been created in English and is highly modifiable. It also uses AES encryption algorithm to encode the files on the victims’ computers. This encryption is sophisticated and generates a unique decryption key. The virus comes with it’s custom sales page which is oriented primarily towards selling it to people who want to infect users with it. The ransomware virus uses the TOR networking system to infect various users and hence remain untraceable. In case you have been infected by DotRansomware, recommendations are to read the following material and learn what DotRansomware exactly performs and how to neutralize it and try getting back the data.

Threat Summary

Name

DotRansomware

Type Ransomware
Short Description The malware is offered online as a part of a scheme to distribute it in a final variant for 50% of the ransom the victims pay for their files encrypted by the virus.
Symptoms The user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension .locked has been used but may be changed with different versions.
Distribution Method Via an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner. Depends on who is part of the RaaS scheme and spreads it.
Detection Tool See If Your System Has Been Affected by DotRansomware

Download

Malware Removal Tool

User Experience Join our forum to Discuss DotRansomware.
Data Recovery Tool Data Recovery Pro by ParetoLogic Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

How Does DotRansomware Spread

This particular virus is advertised online to absolutely everyone who has access to some particular areas of the deep web. This means that DotRansomware may spread depending on what the cyber-criminal decides. Typically most cyber-criminals choose e-mail spam messages with deceitful content, like the example picture below shows:

Such e-mails aim to get the user to open malicious e-mail attachment which is the infection malware that downloads the payload of DotRansomware, in this hypothetical scenario.

However, there are many other methods by which this ransomware infection could infect users:

  • Via fake installers or updates downloaded from shady websites.
  • If the user activates a fake patch for cracking unlicensed software, usually downloaded from torrent websites.
  • Via other malware that has previously infected a computer.
  • Via potentially unwanted program (PUP) that aims to perform an infection via multiple different advertisements, redirects or pop-ups.

DotRansomware – Further Analysis

The virus has been uploaded on a TOR-based web page and as soon as you open it, the terms of the developers immediately become evident:

The cyber-criminals offer as much as half of the extorted money paid by the victim to the one who distributes their own version of DotRansomware. The registration process of the virus is also quite simple. All one needs to begin infecting is a BitCoin address. As tempting as it sounds, this is quite the risk and at the end, trusting cyber-criminals is never a good idea at all.

During the infection process, DotRansomware may drop multiple malicious files on the computers it compromises. The files may have different names and may be located in different Windows folders, for example:

The official file extension of the DotRansomware virus is .locked, but the ransomware may undergo some changes, it really depends on how it is configured:

Image Source: id-ransomware.blogspot.bg

Amongst the files types this virus encrypts are around 400 different files that are connected with various programs that are used on a daily basis:

→.001, .1dc, .3ds, .3fr, .7z, .a3s, .acb, .acbl, .accdb, .act, .ai, .ai3, .ai4, .ai5, .ai6, .ai7, .ai8, .aia, .aif, .aiff, .aip, .ait, .anim, .apk, .arch00, .ari, .art, .arw, .asc, .ase, .asef, .asp, .aspx, .asset, .avi, .bak, .bar, .bay, .bc6, .bc7, .bgeo, .big, .bik, .bkf, .bkp, .blob, .bmp, .bsa, .c, .c4d, .cap, .cas, .catpart, .catproduct, .cdr, .cef, .cer, .cfr, .cgm, .cha, .chr, .cld, .clx, .cpp, .cr2, .crt, .crw, .cs, .css, .csv, .cxx, .d3dbsp, .das, .dat, .dayzprofile, .dazip, .db, .db0, .dbf, .dbfv, .dcr, .dcs, .der, .desc, .dib, .dlc, .dle, .dlv, .dlv3, .dlv4, .dmp, .dng, .doc, .docm, .docx, .drf, .dvi, .dvr, .dwf, .dwg, .dxf, .dxg, .eip, .emf, .emz, .epf, .epk, .eps, .eps2, .eps3, .epsf, .epsp, .erf, .esm, .fbx, .ff, .fff, .fh10, .fh11, .fh7, .fh8, .fh9, .fig, .flt, .flv, .fmod, .forge, .fos, .fpk, .fsh, .ft8, .fxg, .gdb, .ge2, .geo, .gho, .gz, .h, .hip, .hipnc, .hkdb, .hkx, .hplg, .hpp, .hvpl, .hxx, .iam, .ibank, .icb, .icxs, .idea, .iff, .iiq, .indd, .ipt, .iros, .irs, .itdb, .itl, .itm, .iwd, .iwi, .j2k, .java, .jp2, .jpe, .jpeg, .jpf, .jpg, .jpx, .js, .k25, .kdb, .kdc, .kf, .kys, .layout, .lbf, .lex, .litemod, .lrf, .ltx, .lvl, .m, .m2, .m2t, .m2ts, .m3u, .m4a, .m4v, .ma, .map, .mat, .max, .mb, .mcfi, .mcfp, .mcgame, .mcmeta, .mdb, .mdbackup, .mdc, .mddata, .mdf, .mdl, .mdlp, .mef, .mel, .menu, .mkv, .mll, .mlx, .mn, .model, .mos, .mp, .mp4, .mpqge, .mrw, .mrwref, .mts, .mu, .mxf, .nb, .ncf, .nef, .nrw, .ntl, .obm, .ocdc, .odb, .odc, .odm, .odp, .ods, .odt, .omeg, .orf, .ott, .p12, .p7b, .p7c, .pak, .pct, .pcx, .pdd, .pdf, .pef, .pem, .pfx, .php, .php4, .php5, .pic, .picnc, .pkpass, .png, .ppd, .ppt, .pptm, .pptx, .prj, .prt, .prtl, .ps, .psb, .psd, .psf, .psid, .psk, .psq, .pst, .ptl, .ptx, .pwl, .pxn, .pxr, .py, .py, .qdf, .qic, .r3d, .raa, .raf, .rar, .raw, .rb, .rb, .re4, .rgss3a, .rim, .rofl, .rtf, .rtg, .rvt, .rw2, .rwl, .rwz, .sav, .sb, .sbx, .sc2save, .sdf, .shp, .sid, .sidd, .sidn, .sie, .sis, .skl, .skp, .sldasm, .sldprt, .slm, .slx, .slxp, .snx, .soft, .sqlite, .sqlite3, .sr2, .srf, .srw, .step, .stl, .stp, .sum, .svg, .svgz, .swatch, .syncdb, .t12, .t13, .tar, .tax, .tex, .tga, .tif, .tiff, .tor, .txt, .unity3d, .uof, .uos, .upk, .vda, .vdf, .vfl, .vfs0, .vpk, .vpp_pc, .vst, .vtf, .w3x, .wallet, .wav, .wb2, .wdx, .wma, .wmo, .wmv, .wotreplay, .wpd, .wps, .x3f, .xf, .xl, .xlk, .xls, .xlsb, .xlsm, .xlsx, .xvc, .xvz, .xxx, .ycbcra, .yuv, .zdct, .zip, .ztmp

These important files are rendered no longer openable and the virus also has a ransom note which can be customized. Malware researchers believe that it may be somehow connected to Unlock26 ransomware – a relatively new virus that hit the wild recently.

Remove DotRansomware and Try Getting Back the Files

In case you have been infected by an instance of this ransomware infection on your computer, the first deal of business is to immediately back up the encrypted files.

Then, experts recommend removing this ransomware infection from your computer with the one and only purpose of creating a safe environment to try the methods In step “2. Restore files encrypted by DotRansomware” below. In case you have difficulties in manually removing this ransomware infection from your computer, reccomendations are to focus on scanning your computer with an advanced anti-malware software. It will fully remove all files associated with this threat and make sure to protect your computer in the future as well.

Manually delete DotRansomware from your computer

Note! Substantial notification about the DotRansomware threat: Manual removal of DotRansomware requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove DotRansomware files and objects
2.Find malicious files created by DotRansomware on your PC

Automatically remove DotRansomware by downloading an advanced anti-malware program

1. Remove DotRansomware with SpyHunter Anti-Malware Tool and back up your data

Globe2 Ransomware Decryption Instructions

In order to successfully decrypt files enciphered by globe ransomware you are going to need several details to begin with. First, you will need an original file and an encrypted file.

encrypted-file-original-file-globe-ransomware-sensorstechforum

In case you cannot find one, make sure to browse through the default wallpaper folder of the same version of your Windows OS. Here is an example of the location of the default folders for wallpapers for different Windows versions:

C:\Windows\Web\Wallpaper
C:\Users\UserProfile\Pictures
C:\Users\UserProfile\Sample Pictures

After having located an original and an encrypted file, make sure to download the decrypter by clicking on the download button below:

Download

Globe2 Decrypter

Make sure to save the decrypter somewhere easy to find and open it. Then follow the steps below:

Step 1: Drag and drop the encrypted file and the original file together into the decrypter, like the animated image below demonstrates:

globe2-ransomware-drag-drop-filess

Step 2: The decrypter will begin a brute forcing sequence. Simply wait until your key has been discovered:

decrypt-globe2-instructions-bruteforcing-key-sensorstechforum

2-i-1-nemucod-key-found-globe2-sensorstechforum

Step 3: After this, click on OK and the main interface of the decrypter should appear. From it, choose Add Files to add all the files that you wish to be deciphered.

3-globe2-main-ninterface-sensorstechforum-1

Step 4: After you have added your files, click on the Decrypt button so that the decrypter can begin the deciphering operation.

6-globe2-decrypt-files-sensorstechforum

At this point you will begin to see on the live feed at the middle of the decrypter’s interface which files were successfully decoded:

4-decrypted-files-globe2-sensorstechfrum

Globe2 Ransomware – The Bottom Line

As a summary of this virus, it is nothing special since malware researchers have managed to almost immediately decode it. But bear in mind that there are many other dangerous ransomware viruses out there that exist for couple of years now and no decryption solution has been released yet. This is why it is always a benefit to know how to protect yourself from malware of the file encryption type.

We have prepared several simple tips that you can follow and stay safe in the future:

Tip 1: Make sure to read our general protection tips and try to make them your habit and educate others to do so as well.
Tip 2: Install an advanced anti-malware program that has an often updated real-time shield definitions and ransomware protection.

Tip 3: Seek out and download specific anti-ransomware software which is reliable.

Tip 4: Backup your files using one of the methods in this article.

Tip 5: : Make sure to use a secure web browser while surfing the world wide web.

Vencislav Krustev

A network administrator and malware researcher at SensorsTechForum with passion for discovery of new shifts and innovations in cyber security. Strong believer in basic education of every user towards online safety.

More Posts - Website

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.