.ZWIEBEL Datei Virus - (Entfernen und Wiederherstellen von Dateien Zwiebel)

.ONION File Virus (Restore Files)


with SpyHunter

Scan Your System for Malicious Files
Note! Your computer might be affected by .onion file virus and other threats.
Threats such as .onion file virus may be persistent on your system. They tend to re-appear if not fully deleted. A malware removal tool like SpyHunter will help you to remove malicious programs, saving you the time and the struggle of tracking down numerous malicious files.
SpyHunter’s scanner is free but the paid version is needed to remove the malware threats. Read SpyHunter’s EULA and Privacy Policy

This article is created to help you remove Dharma ransomware’s .onion variant and restore .id-{random}.[[email protected]].onion encrypted files.

A new version of Dharma ransomware has been reported to be spreading, this time using the .onion file extension added to the files it encrypts. The new version of Dharma ransomware is believed to be very similar to the old one and just like it, encrypt files on the compromised computer after which change the wallpaper on the compromised computer and then demand victims to pay a hefty ransom fee to restore their encrypted files. In case your computer has been infected by the .onion Dharma ransomware recommendations are to read this article thoroughly.

Threat Summary


.onion file virus

Short Description.Onion virus, also calling itself Dharma encrypts user files and leaves as contact e-mail addresses to contact the criminals behind it and pay a ransom fee to restore encrypted files.
SymptomsChanges file extension of encrypted files to .onion. Changes wallpaper to one with ransom instructions that have ransom e-mail.
Distribution MethodVia an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner.
Detection Tool See If Your System Has Been Affected by .onion file virus


Malware Removal Tool

User ExperienceJoin our forum to Discuss .onion file virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Update May 2017 – New Data Recovery Method

It has been brought to our attention that victims of the latest Dharma .onion ransomware infection variants have managed to restore a very high percentage (over 90%) of their files using a very unique method – converting files into virtual drives and then using partition recovery option on data recovery programs. This method takes advantage of the converting the files into a .VHD file type which is a virtual drive. Since there are new data recovery programs specifically designed to recover partitions, one approach is to restore files encyrpted by Dharma ransomware is to convert the encrypted files into .VHD files and then try to recover them using partition recovery software. Since the algorithm that encrypts files actually alters only a small portion of the file, you have a much higher chance of recovering the files if you change them into .VHD type.

The methods have been reported to not be a full guarantee to recover all the files, but if you haven’t reinstalled your operating system yet, we advise you to follow them. But first, make sure to remove Dharma’s malicious files from the instructions at the bottom of these article. Here are the instructions:

.onion Recovery Instructions 2017