This article will aid you to remove May ransomware fully. Follow the ransomware removal instructions at the bottom of the article.
May is a ransomware cryptovirus that displays a window with a ransom note. The message is written in English and you are being extorted to pay 1 Bitcoin in exchange of getting your files back to normal. This ransomware seeks to encrypt files while putting the extension .locked after the encryption process is done. Keep on reading below to see how you could try to potentially restore some of your files.
|Short Description||The ransomware encrypts files on your computer and creates a ransom note afterward.|
|Symptoms||The ransomware will encrypt your files and put the extension .locked to them after it finishes with the encryption process.|
|Distribution Method||Spam Emails, Email Attachments|
|Detection Tool|| See If Your System Has Been Affected by May |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss May.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
May Ransomware – Update
The virus has a new version, with a fe changes. The most noticeable difference is the ransom message, which will appear as a .html document called Restore_maysomware_files.html. You can see it below:
That ransom message reads the following:
All your files have been encrypted with May Ransomware. For encrypt we use AES256+RSA4096. You have 5 days for decrypt your files. Don`t try recover your files.
1) Make your bitcoin wallet on block.io or blockchain.info and buy 1,5 bitcoins on BTC Exchange Sites (https://goo.gl/1PE96T)
2) Send 1,5 bitcoin to adress 3Gw6b57A3E34nAph3mzGbKAj8sTSgD8GP9
3) Write to us on email email@example.com. In subject write this identificator [ID] 4) After receive bitcoins and your email, we contact with you.
— YOU MIGHT DECRYPT 2 FILES FOR FREE. Send it to email firstname.lastname@example.org. In Subject, write your UNIQUE Identificator.
Another thing which is worth to note is that the extension placed to encrypted files now is .maysomware.
May Ransomware – Infection
May ransomware might spread its infection with various methods. A payload dropper which initiates the malicious script for this ransomware is being spread around the world, and researchers have gotten their hands on a malware sample. If that file lands on your computer system and you somehow execute it – your computer will become infected. You can see the detections of such a file, called May_ransomware.exe, on the VirusTotal service right here:
May ransomware might also deliver its payload file on social media and file-sharing services. Freeware which is found on the Web can be presented as helpful also be hiding the malicious script for the cryptovirus. Refrain from opening files right after you have downloaded them. You should first scan them with a security tool, while also checking their size and signatures for anything that seems out of the ordinary. You should read the tips for preventing ransomware found in our forums.
May Ransomware – Description
May is a virus that will encrypt your files and try to extort you to pay a ransom to get them restored. Malware researchers have found it a few days ago in the middle of month May, so its name is appropriate.
May ransomware could make entries in the Windows Registry to achieve persistence, and probably launch or repress processes in a Windows environment. Such entries are typically designed in a way to launch the virus automatically with each start of the Windows operating system.
The note is written in English, and it will be inside a file called Restore_your_files.txt. You can view the ransom message that loads after the encryption process in this picture:
That ransom note stored in the Restore_your_files.txt file reads the following:
You have 5 days for decrypt your files.
All your files have been encrypted with May Ransomware.
For encrypt we use AES256+RSA4096.
Don`t try recover your files.
1) Make your bitcoin wallet on block.io or blockchain.info and buy 1 bitcoins on BTC Exchange Sites (https://goo.gl/1PE96T)
2) Send 1 bitcoin to address 3Gw6b57A3E34nAph3mzGbKAj8sTSgD8GP9
3) Write to us on email email@example.com . In subject write this identificator “81ff05bf2ab1406d8f11b866e804af37”
4) After receive bitcoins and your email , we contact with you.
YOU MIGHT DECRYPT 2 FILES FOR FREE. Send it to email firstname.lastname@example.org .In Subject ,write your UNIQUE Identificator.
The ransomware gives you a period of 5 days to make the demanded payment of 1 Bitcoin. That amount equals to nearly 1.833 US dollars, at the moment of writing of this article.
You should NOT under any circumstances pay the ransom. Your files may not get restored, and nobody could give you any real guarantee. Moreover, giving money to cybercriminals will likely motivate them to create more ransomware viruses or even do different criminal activities.
May Ransomware – Encryption Process
Currently, the ransomware is still being researched, and some experts say that it might be a HiddenTear variant, while others don’t say such a thing. If that proves to be true, then the encryption algorithm will probably be AES. Although, the ransom note states that the encryption algorithms which are used are AES 256-bit and RSA 4096-bit ones. For now, there is no information about what extensions the cryptovirus seeks to encrypt. However, most probably extensions for the following file types are being encrypted:
Those file types are still the most commonly-used ones today for nearly all Windows users, making the list quite viable. All of the files that get encrypted will receive the same extension appended to them, and that is the .locked extension.
The May cryptovirus might be tweaked to erase all the Shadow Volume Copies from the Windows operating system with the help of the following command:
→vssadmin.exe delete shadows /all /Quiet
In case the command stated above is executed that would make the encryption process more efficient as it will eliminate one of the ways for restoring your files. If your computer is infected with this ransomware, read on through to find out how you could potentially recover your files.
Remove May Ransomware and Restore .locked Files
If your computer got infected with the May ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.