.Loveransisgood Files Virus – Remove and Restore Encrypted Files

.Loveransisgood Files Virus – Remove and Restore Encrypted Files

This article aims to help you remove the .loveransisgood ransomware virus from your computer and restore files that have been encrypted by this SamSam variant without having to pay the ransom.

SamSam ransomware viruses have been coming out in new variants every week and .loveransisgood files virus is no exception. The virus is from the file encryption type, meaning that it uses an encryption algorithm to encrypt the files on your computer and then extort you into paying the ransom. Read this article to learn how to remove .loveransisgood ransomware and restore the files that have been encoded by it on your computer.

Threat Summary

Name.loveransisgood Virus
TypeRansomware, Cryptovirus
Short DescriptionPart of the SamSam ransomware family. Encrypts the files on your computer and demands a ransom to be paid in BitCoin to get them back.
SymptomsThe files are appended .loveransisgood file extension and can no longer be opened. A ransom note may appear as an .html file somewhere on your desktop.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by .loveransisgood Virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .loveransisgood Virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

.Loveransisgood Ransomware – Distribution

For this virus to be widespread, it may use different methods which cause the infection itself. The main method used by it is via spammed e-mail messages. Such messages often contain either malicious web links embedded within them or spammed e-mail attachments that pretend to be legitimate types of files. Such messages often pose as:

  • Banking statements of suspicious activity on your bank account.
  • Fake PayPal invoices.
  • Fake receipts from online retailers, like eBay, Amazon, etc.

Besides via spammed e-mails, .Loveransisgood may also be replicated via other methods, like being disguised as a fake program setup, software activator, game patch or crackfix for such.

.Loveransisgood Ransomware – More Information

Once an infection with .loveransisgood ransomware takes place, the virus drops two malicious files on the victim’s computer. They have been reported to be .exe types of files with different names:

  • {random name}{number}.exe
  • {random name}.exe

Besides these files, other files may also be dropped on the victim’s computer, more specifically in the following Windows folders:

  • %AppData%
  • %Local%
  • %Roaming%
  • %LocalLow%
  • %Temp%

After these files have already been dropped on the victim’s computer, the malware may delete the shadow volume copies of the infected computer by executing the vssadmin command as an administrator in Windows Command Prompt:

→ vssadmin delete shadows /for={DrivePartition} [/oldest | /all | /shadow={Identification of the shadow copies}] [/quiet]

After having done this, the .loveransisgood may also modify the Run and RunOnce Windows registry sub-keys, adding values in them with data that points to the location of the malicious files which cause the encryption. The sub-keys have the following location:

→ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\

.Loveransisgood Ransomware – Encryption Process

In order to encrypt files on your computer, this variant of SamSam ransomware scans for them and then uses encryption to alter data from the original files with scrambled data. The .Loveransisgood ransomware does not encrypt the entire files, instead it encrypts the . It looks for specific files to encrypt, while excluding the important Windows files which may damage your OS. The files which SamSam’s .loveransisgood variant may scan for are usually videos, documents, archives, audio files, pictures and other often used types of files. The virus does the scanning process by looking for the files, based on a file extension list of commonly used types of files, for example:


After the encryption process has completed, the files have the following appearance:

Remove SamSam Ransomware and Restore .loveransisgood Encrypted Files

In order to remove this ransomware completely from your computer, we recommend that you follow the removal instructions below. They are created to help remove all the files and objects created by .loveransisgood file virus on your computer. If manual removal is a difficulty for you, it is advisable to remove .loveransisgood files ransomware using an advanced anti-malware scanner, which will fully and automatically take care of the removal for you and protect your PC against future infections as well.

Furthermore, if you want to restore files that have been encrypted by this ransomware on your computer, you can try the alternative methods for file recovery below in step “2. Restore files encrypted by .loveransisgood Virus”. They are specifically created to help restore as many files as possible without paying any ransom.


Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share