.SUSPENDED File Virus – How to Remove and Restore Files

.SUSPENDED File Virus – How to Remove and Restore Files

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)

remove .SUSPENDED File Virus

This article provides guide how to remove .SUSPENDED file virus as well as alternative ways to restore corrupted files.

The .SUSPENDED file virus is newly discovered threat that plagues computer users systems. It encrypts target files stored on the infected host and marks them with the .SUSPENDED extension. Afterward, the crypto virus drops a ransom note named !!!RestoreProcess!!!.txt. The message states that all corrupted files can be decrypted with the help of a specific decryption key. In order to obtain the key victims should contact hackers at a given email address ( suspendedfiles@bitmessage.ch ) and pay them $600. The good news is that .SUSPENDED files can be restored by utilizing alternative data recovery methods. Check the guide at the end of the article to see some good and reliable alternatives.

Threat Summary

Name.SUSPENDED virus
TypeRansomware, Cryptovirus
Short DescriptionEncrypts target files on the infected computers and asks for a ransom payoff in BitCoins to decrypt the files of victims.
SymptomsFiles that store important information are encrypted and marked with the extension .SUSPENDED. A ranom message appears on the PC screen.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by .SUSPENDED virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .SUSPENDED virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

.SUSPENDED File Virus – Distribution

There are several ways of distribution that may be utilized by hackers behind .SUSPENDED ransomware. The threat is invading systems mainly via email spam messages. Such messages are usually trying to convince you to click a presented link or download attached files. By visiting a compromised web page or opening a file on your PC the ransomware payload is easily triggered as these elements contain the malicious code.

Beware that the email attachments carriers of .SUSPENDED virus payload are usually trusted types of files that you open without hesitation like office documents, text files, images and compressed archives.

A visit to a compromised web page causes an automatic download of the ransomware payload on your computer. Such attacks are called drive-by-download. The technique allows hackers to inject the ransomware payload in various web pages and set them to cause unintended download each time a user lands on the page.

Links to compromised web pages that deliver .SUSPENDED ransomware may be spread on various social media channels and instant messaging services.

.SUSPENDED File Virus – Impact

The .SUSPENDED file virus is designed to compromise computer systems in order to encrypt predefined types of files stored on the drives. That’s why it is classified as data locker ransomware. It is named after the specific extension .SUSPENDED that is appended to each encrypted file.

In order to fulfil the data encryption process, .SUSPENDED crypto virus needs to plague the system. For the purpose once its payload is running on the system it may drop additional malicious files needed for the attack. Then the ransomware is likely to utilize the functionalities of vast number of system registry keys to activate its malicious files and begin the encryption process.

Most of the ransomware infections like .SUSPENDED access the Registry Editor to add specific values under the Run and RunOnce sub-keys as these keys are able to execute all the malicious files associated the threat. So you definitely need to clean the system registry entries in order to remove completely this nasty crypto virus. How to do that is shown in step one of the manual removal below.

Afterward, .SUSPENDED file virus drops a ransom note on the infected host aiming to blackmail victims into paying a ransom for file decryption solution. The message is contained in a text file named !!!RestoreProcess!!!.txt. It reads the following:

All your important files were encrypted on this PC.
All files with .SUSPENDED extension are encrypted.
Encryption was produced using unique private key RSA-1024 generated for this computer.
To decrypt your files, you need to obtain private key + decrypt software.
To retrieve the private key and decrypt software, you need to contact us by email suspendedfiles@bitmessage.ch send us an email your !!!RestoreProcess!!!.txt file and wait for further instructions.
For you to be sure, that we can decrypt your files – you can send us a 1-3 any not very big encrypted files and we will send you back it in a original form FREE.
Price for decryption $600 if you contact us first 72 hours.
Your personal id:
E-mail address to contact us:
Reserve email address to contact us:

As it gets clear, hackers expect to contact them at suspendedfiles@bitmessage.ch and transfer them a ransom of $600 probably in Bitcoin. The price $600 is valid only if the sum is transferred within 72 hours as stated in the ransom. However, do not get tricked for the second time. There is no guarantee that hackers have a working solution for your corrupted files. Chances are that you are only going to lose your money without receiving a decryption key.

.SUSPENDED File Virus – Encryption

The encryption is applied only to target types of files not to all files stored on the drives. For the purpose, the ransomware utilizes strong cipher algorithm that modifies completely the original code of all target files. Afterward, corrupted files receive the extension .SUSPENDED and remain completely unusable until a decryption solution is applied. Usually, crypto viruses aim to corrupt files that store valuable information like:

  • Documents.
  • Videos.
  • Images.
  • Music.
  • Audio files.
  • Archives.

In addition to this ,the .SUSPENDED ransomware virus may delete the backups and the shadow volume copies stored on the infected host. This is possible by executing the following commands as an administrator on the victim PC:

→ process call create “cmd.exe /c vssadmin.exe delete shadows /all /quiet & bcdedit.exe /set {default} recoveryenabled no & bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures

How to Remove .SUSPENDED File Virus and Restore Files

Тo remove .SUSPENDED file virus just follow the step-by-step removal guide below which provides both manual and automatic approaches. Due to the complexity of ransomware code, security researchers recommend the help of advanced anti-malware tool that guarantees maximum efficiency.

Once the removal is complete, alternative data recovery approaches could be also found in the guide. They may be useful for the restore of some encrypted files. Be advised to back up all encrypted files to an external drive before you proceed with the recovery process.

Gergana Ivanova

Gergana Ivanova

Gergana has completed a bachelor degree in Marketing from the University of National and World Economy. She has been with the STF team for three years, researching malware and reporting on the latest infections.

More Posts

Follow Me:
Google Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share