A ransomware infection known by researchers as BTCware ransomware was detected at the beginning of 2017 in multiple variants. The infection demanded somewhere around 0.5 BTC as a ransom payoff to the files encrypted by it which have the .btcware, .cryptobyte, .cryptowin, .theva and .onyon file extensions added to them. Fortunately, now it is possible to decrypt files encrypted with this extension for free. Keep reading this article in order to learn how to remove BTCWare ransomware completely and then decrypt your files for free.
Remove BTCWare from Your Computer
For the effective removal of the BTCWare threat, you must isolate the virus in Safe Mode first. Then, we recommend removing it with the aid of an advanced anti-malware tool, which can be installed in regular Windows mode before hand. Such tool not only will fully, safely and easily remove the BTCWare’s virus files from your computer but will also protect your PC from future attacks.
Manually delete BTCWare from your computer
Note! Substantial notification about the BTCWare threat: Manual removal of BTCWare requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.
Automatically remove BTCWare by downloading an advanced anti-malware program
Decrypt Files Encrypted by BTCWare Ransomware for Free
After removing the threat, all that is left is to decode the encrypted files. To perform this, follow these instructions:
In order to decrypt your files, first you should download the decrypter for BTCWare by Michael Gillespie which containts the master decryption key:
After saving, the decrypter for BTCWare ransomware, disable your antivirus, so It won’t block it. Then copy the decrypter somewhere where it can be easily found and open it.
After extracting the decrypter, start it and click on the “Select Directory” button after which navigate to a directory you wish to decrypt. Then simply decode the files in the directory by clicking on the “Decrypt” button:
Proceed this activity with the other directories as well for their decryption.