.b29 Files Virus (Paradise) – Remove It and Restore Data

.b29 Files Virus (Paradise) – Remove It and Restore Data

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)

This article has been created with the purpose to explain to you what is the .b29 files virus and how to remove it from your computer and try restoring files, encrypted by it.

A new version of the previously detected Paradise ransomware has been released. The virus now uses the .b29 file extension and It also appends base64 in XML to the end of the encrypted files with a number in it. In addition to this, the ransomware virus also drops a #DECRYPT MY FILES#.html ransom note which asks victims to contact the crooks via their e-mail yourencypter@protonmail.com and likely pay hefty ransom in order to ge the encrypted files recovered back to their normal, working state. If your computer has been infected by this version of Paradise Ransomware, we advise that you read this article thorughly as it aims to help you remove it and try restoring .b29 encrypted files.

Threat Summary

NameParadise .b29 Virus
TypeRansomware, Cryptovirus
Short DescriptionAimed at encrypting the files on the computers infected by it.
SymptomsThe .b29 file extension is added to the victim’s computer. A ransom note, called
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by Paradise .b29 Virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss Paradise .b29 Virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Paradise .b29 Ransomware – How Does It Infect

The primary method of infection that is used In association with Paradise ransomware is believed to be conducted via spammed e-mail messages, whose primary purpose is to get victims to download and run the malicious files of Paradise ransomware. These e-mails may pose as legitimate type of messages, like the following:

The e-mails often carry e-mail attachments that only seem like they are important documents. In reality however, these types of files are either malicious .exe files or may infect your computer with the aid of malicious macros by pretending to be legitimate Microsoft Word or PDF files.

Besides via e-mail, the Paradise ransomware virus may also infect your computer as a result of pretending to be a legitimate file that you may have downloaded as a result of looking for it for free online. In this category of files, very often the following types of programs are imitated by hackers:

  • Setups of programs.
  • Online game patches.
  • Online cracks.
  • Software license activators.

Paradise Ransomware – More Information

Once installed on the victim’s computer, the Paradise ransomware virus may begin to perform various types of unwanted activities. These activities may begin with the ransomware virus dropping it’s malicious payload on the victim’s computer. The payload of the malware may consist of more than one file and the malicious files could reside in the following Windows directories:

  • %AppData%
  • %Local%
  • %LocalLow%
  • %Roaming%
  • %Temp%
  • %Roaming%

Among the files dropped is a #DECRYPT MY FILES#.html ransom note which may have a ransom message that is very similar to the previous variant of Paradise ransomware below:

[WHAT HAPPENED] Your important files produced on this computer have been encrypted due a security problem
If you want to restore them, write us to the e-mail: info@decrypt.ws
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us.
After payment we will send you the decryption tool that will decrypt all your files.

[FREE DECRYPTION AS GUARANTEE] Before paying you can send to us up to 3 files for free decryption.
Please note that files must NOT contain valuable information and their total size must be less than 1Mb
[HOW TO OBTAIN BITCOINS] The easiest way to buy bitcoin is LocalBitcoins site.
You have to register, click Buy bitcoins and select the seller by payment method and price

[ATTENTION] Do not rename encrypted files
Do not try to decrypt your data using third party software, it may cause permanent data loss
If you not write on e-mail in 36 hours – your key has been deleted and you cant decrypt your files

Besides the ransom note, the .b29 version of Paradise ransomware may also set custom registry entries in the Windows Registry Editor of the affected computer. These types of registry entries may be set in the Run and RunOnce registry sub-keys so that the virus file of Paradise ransomware runs automatically on Windows boot:

→ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Furthermore, the .b29 variant of Paradise ransomware is also created to perform other activities on the victim’s computer, such as delete the backed up files. These are basically Windows’s shadow volume copies which may be deleted if the ransomware executes the following command as an administrator on the victim PC:

→ vssadmin.exe delete shadows /all /Quiet

.b29 Paradise Ransomware – Encryption Process

In order to encrypt the files on the computer infected by it, the .b29 variant of Paradise ransomware may first scan for the files it wants to encrypt. The ransomware virus looks for the files that are used often and it may exclude scanning for files in the system directories of Windows. The files that may be encrypted by Paradise ransomware are likely of the following types:

  • Images.
  • Videos.
  • Audio files.
  • Archives.
  • Virtual Drives.
  • Documents.

As soon as the files are detected, Paradise ransomware encrypts them and modifies their core structure on copies of these files, while the virus may delete the original files. The encrypted copies may appear like the image below shows:

Remove Paradise Ransomware and Restore .b29 Encrypted Files

In case your computer has been infected by the .b29 variant of Paradise ransomware, we recommend that you read the removal instructions below. They have been divided in manual and automatic removal instructions so that they can help you to remove this ransomware virus either manually or automatically from your computer. If manual removal is not something you feel comfortable in doing, we recommend that you remove .b29 Paradise ransomware automatically, prefferably by downloading and installing an advanced anti-malware software, as security experts suggest is the best way of removing this threat.

If your files have been encrypted by this version of Paradise ransomware, we recommend that you check out the alternative methods for file recover in step “2. Restore files, encrypted by Paradise .b29 Virus” below. They are not a 100% guarantee that you will be able to restore all of your encrypted files, but with their aid you might be able to recover most of the files.


Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share