What is DEcovid19 Ransomware

A new ransomware infection known as DEcovid19 has come to the web and caused a lot of attacks on unprotected PCs. The virus was reported on 11th January by desperate victims with data encrypted. Based on current information, it is clear that DEcovid19 blocks access to data by changing file extensions to .covid19 or .locked. An example of the original 1.mp4 impacted by ransomware may appear in two ways: either as 1.mp4.locked or 1.mp4.covid19. Once the encryption process gets to a close, the malicious program creates a text note (!DECRYPT_FILES.txt or ATTENTION!!!.txt) meant to explain decryption instructions.

DEcovid19 Ransomware (.covid19 extensions)DEcovid19 Ransomware (.locked extensions)

I am the second wave of COVID19, now we infect even PCs. But unlike the human virus, there is a vaccine, but you have to buy it! =)
*
Attention!
Please read these important instructions.
All your content, files, photos, documents, databases, and other important files are encrypted.
All encrypted files have the extension: .covid19.
This is all very sad.
The only way to recover files is to buy a unique private key.
Only we can give you this key and only we can restore your files.
*
!!!!! For decryption, please contact us at Telegram messadger operator contact, follow the instructions below:
*
[1] - Install Telegram.
[2] - Telegram browser download link - > https://telegram.org/
[3] - send operator contact https://t.me/decovid19bot
[4] - enter your (Covid version) and (ID) in the subject line. And how many computers need to be decrypted. (Covid version) and (ID) at the bottom of the message.Attach 1-2 infected files that do not contain important information (less than 2 MB) necessary for generating the decoder and restoring the test file.
[5] - hurry up.Time is limited.Attention. (72 hours).
[6] - if you do not pay within 72 hours, the ransom for decryption will be doubled.
[7] - we don't bite. We are waiting for your emails.
*
[**] Covid Version : 700001
!!!If you contact a file decryption company, they usually trick you, they just write to us and negotiate a ransom. And you only pay them for what they wrote to us. Remember, only we can decrypt the files, and no one can help you! Don't waste your time trying to decipher it, it's impossible without our help. And in 72 hours, the ransom will become even more expensive.
The police won't help you either!
[ * ] Is the ID = .
{redacted}


You are unlucky. The terrible virus has captured your files.
For decryption, please contact us at
Telegram messadger operator contact http://t.me/decovid19bot ,
Enter your ID in the subject line. And how many computers need to be decrypted.
Attach 1-2 infected files that do not contain importent information (less thet 2mb)
are required to generate the decoder and restore the test file.
Hurry up.Time is limited.Attention. (72 hours)
At the end of this time,the private key for generating
the decoder will de destroyed. Files will not be restored.
Your id: {redacted}

Inside, users can see a quick skim through the virus information. The next part of the text is dedicated to restoring your data. Users are said to contact the telegram bot attaching personal ID in the subject line and writing how many PCs need to be decrypted. It is also necessary to send 1-2 encrypted files that do not contain important information (less than 2MB) so that cybercriminals could match up the right decoder for your data. The last, but not least said by swindlers is time boundaries – you have 72 hours to make a decision and pay for the decryption key. Unless you fit in the timeline, the chance to recover your data will no longer exist. Although meeting the requirements of cybercriminals is usually the only way to bring your files back, trusting such fraudulent figures is quite a huge risk. They might fool you and refuse to provide any decryption tools even after committing the payment. Our advice, in this case, is to delete DEcovid19 Ransomware and try to restore files using third-party utilities. Instructions on how to do this will be presented below.

decovid19 ransomware

How DEcovid19 Ransomware infected your computer

The most likely ways of how DEcovid19 could infect your system are via unprotected RDP configuration, trojans, e-mail spam, fake software cracking tools, backdoors, keyloggers, and many other vectors. However, the most abused out of this list is e-mail messages sent with malicious attachments. Cybercriminals do exploit this method because it is easy to use and covers millions of people that use e-mail services on a regular basis. To make victims curious enough to open the attached files, extortionists set up messages with highlighted titles prompting to act. Usually, it is done by disguising messages as something “legitimate” or “urgent”, which generates interest. As a consequence, in case you decide to open the files (MS Office documents, PDFs, executable, JavaScript files), the result will be clear – malware infection like DEcovid19 Ransomware. It is also necessary to mention that the above-mentioned files are totally legitimate, however, some frauds use them as a veil to hide malicious content. In order to grant full protection against such threats in the future, we advise you to follow our instructions below.

  1. Download DEcovid19 Ransomware Removal Tool
  2. Get decryption tool for .covid19 or .locked files
  3. Recover encrypted files with Stellar Data Recovery Professional
  4. Restore encrypted files with Windows Previous Versions
  5. Restore files with Shadow Explorer
  6. How to protect from threats like DEcovid19 Ransomware

Download Removal Tool

Download Removal Tool

To remove DEcovid19 Ransomware completely, we recommend you to use WiperSoft AntiSpyware from WiperSoft. It detects and removes all files, folders, and registry keys of DEcovid19 Ransomware and prevents future infections by similar viruses.

Alternative Removal Tool

Download SpyHunter 5

To remove DEcovid19 Ransomware completely, we recommend you to use SpyHunter 5 from EnigmaSoft Limited. It detects and removes all files, folders, and registry keys of DEcovid19 Ransomware. The trial version of SpyHunter 5 offers virus scan and 1-time removal for FREE.

DEcovid19 Ransomware files:


!DECRYPT_FILES.txt
ATTENTION!!!.txt
FTS.exe
svchost.com
local_enc_private_key
local_public_key_len
{randomfilename}.exe

DEcovid19 Ransomware registry keys:

no information

How to decrypt and restore .covid19 or .locked files

Use automated decryptors

Download Kaspersky RakhniDecryptor

kaspersky dharma ransomware decryptor

Use following tool from Kaspersky called Rakhni Decryptor, that can decrypt .covid19 or .locked files. Download it here:

Download RakhniDecryptor

There is no purpose to pay the ransom because there is no guarantee you will receive the key, but you will put your bank credentials at risk.

Dr.Web Rescue Pack

Famous antivirus vendor Dr. Web provides free decryption service for the owners of its products: Dr.Web Security Space or Dr.Web Enterprise Security Suite. Other users can ask for help in the decryption of .covid19 or .locked files by uploading samples to Dr. Web Ransomware Decryption Service. Analyzing of files will be performed free of charge and if files are decryptable, all you need to do is purchase a 2-year license of Dr.Web Security Space worth $120 or less. Otherwise, you don’t have to pay.

If you are infected with DEcovid19 Ransomware and removed it from your computer you can try to decrypt your files. Antivirus vendors and individuals create free decryptors for some crypto-lockers. To attempt to decrypt them manually you can do the following:

Use Stellar Data Recovery Professional to restore .covid19 or .locked files

stellar data recovery professional

  1. Download Stellar Data Recovery Professional.
  2. Click Recover Data button.
  3. Select type of files you want to restore and click Next button.
  4. Choose location where you would like to restore files from and click Scan button.
  5. Preview found files, choose ones you will restore and click Recover.
Download Stellar Data Recovery Professional

Using Windows Previous Versions option:

  1. Right-click on infected file and choose Properties.
  2. Select Previous Versions tab.
  3. Choose particular version of the file and click Copy.
  4. To restore the selected file and replace the existing one, click on the Restore button.
  5. In case there is no items in the list choose alternative method.

Using Shadow Explorer:

  1. Download Shadow Explorer program.
  2. Run it and you will see screen listing of all the drives and the dates that shadow copy was created.
  3. Select the drive and date that you want to restore from.
  4. Right-click on a folder name and select Export.
  5. In case there are no other dates in the list, choose alternative method.

If you are using Dropbox:

  1. Login to the DropBox website and go to the folder that contains encrypted files.
  2. Right-click on the encrypted file and select Previous Versions.
  3. Select the version of the file you wish to restore and click on the Restore button.

How to protect computer from viruses, like DEcovid19 Ransomware, in future

1. Get special anti-ransomware software

Use BitDefender Anti-Ransomware

bitdefender anti-ransomware

Famous antivirus vendor BitDefender released a free tool, that will help you with active anti-ransomware protection, as an additional shield to your current protection. It will not conflict with bigger security applications. If you are searching complete internet security solution consider upgrading to full version of BitDefender Internet Security 2018.

Download BitDefender Anti-Ransomware

2. Back up your files

idrive backup

As an additional way to save your files, we recommend online backup. Local storages, such as hard drives, SSDs, flash drives, or remote network storages can be instantly infected by the virus once plugged in or connected to. DEcovid19 Ransomware uses some techniques to exploit this. One of the best services and programs for easy automatic online backup is iDrive. It has the most profitable terms and a simple interface. You can read more about iDrive cloud backup and storage here.

3. Do not open spam e-mails and protect your mailbox

mailwasher pro

Malicious attachments to spam or phishing e-mails are the most popular method of ransomware distribution. Using spam filters and creating anti-spam rules is good practice. One of the world leaders in anti-spam protection is MailWasher Pro. It works with various desktop applications and provides a very high level of anti-spam protection.

Download MailWasher Pro