What is FLAMINGO Ransomware

FLAMINGO is a malicious piece designed to block access to user’s data by running encryption with cryptographic algorithms. Despite the ransomware is relatively new, already known that it uses the .FLAMINGO extension to encrypt data. For example, a file like 1.mp4 will change to 1.mp4.FLAMINGO following successful encryption. After this, users receive decryption steps located in a text note called #READ ME.txt.

FLAMINGO Ransomware
||||||||----[ All your data is encrypted by a strong encryter called FLAMINGO ]----||||||||
============= # Unique ID : -
============= # E-mail : FlamingoRans@tutamail.com
####################################
" PLEASE BE CAREFUL " :
if your data is important to you, And you want to make a payment, be sure
to send us a test file first(3 Mb),And make sure we have the ability to
open your files(Decrypt test files).So first send the test file to prove
that we can decrypt your files, Then make a payment (Buy BTC) and receive the
decryption tool (Send Decrypter).
####################################
If you do not receive a reply after sending us an email,
please send an email to the second email address.
second E-mail : FlamingoRans@protonmail.com
####################################

According to them, victims have to send a test file via e-mail (not more than 3MB) to prove the decryption capabilities of cybercriminals. Then, you will get a reply with instructions to buy (in BTC) a decryption tool. We have to inform you that manipulating files, restarting, or shutting down your PC can be unpredictably dangerous for your data. Usually, ransomware developers create special values that delete data completely if detected attempts to change it. Unfortunately, an effective way to recover data encrypted by FLAMINGO has not been found just yet. You can only uninstall the virus to prevent further encryption. The decryption may be possible but should be tested individually. Sometimes, third-party programs can unlock the assigned cipher and access data eventually. Give it a try using our tutorial and share your feedback in the comments section below.

flamingo ransomware

How FLAMINGO Ransomware infected your computer

Getting infected with malware can look sophisticated. Developers use multiple ways to make their software reach unprotected systems. As an example, the most popular distribution channel is via e-mail spam delivered to many users. The purpose is to cover malicious attachments (MS Office documents, PDFs, executables, JavaScript files) under legitimate-looking messages. Once inexperienced users decide to open or download them, the infection process is launched somewhere in the background passing by users’ consent. This is why it is important to not respond to such messages, even if they look to be innocent. Always think twice before opting for any risk. You can read our guide below to learn more about protection and establish safety against such threats.

  1. Download FLAMINGO Ransomware Removal Tool
  2. Get decryption tool for .FLAMINGO files
  3. Recover encrypted files with Stellar Data Recovery Professional
  4. Restore encrypted files with Windows Previous Versions
  5. Restore files with Shadow Explorer
  6. How to protect from threats like FLAMINGO Ransomware

Download Removal Tool

Download Removal Tool

To remove FLAMINGO Ransomware completely, we recommend you to use WiperSoft AntiSpyware from WiperSoft. It detects and removes all files, folders, and registry keys of FLAMINGO Ransomware and prevents future infections by similar viruses.

Alternative Removal Tool

Download SpyHunter 5

To remove FLAMINGO Ransomware completely, we recommend you to use SpyHunter 5 from EnigmaSoft Limited. It detects and removes all files, folders, and registry keys of FLAMINGO Ransomware. The trial version of SpyHunter 5 offers virus scan and 1-time removal for FREE.

FLAMINGO Ransomware files:


!=HOW_TO_DECRYPT_FILES=!.txt
64RA05.exe
{randomfilename}.exe

FLAMINGO Ransomware registry keys:

no information

How to decrypt and restore .FLAMINGO files

Use automated decryptors

Download Kaspersky RakhniDecryptor

kaspersky dharma ransomware decryptor

Use following tool from Kaspersky called Rakhni Decryptor, that can decrypt .FLAMINGO files. Download it here:

Download RakhniDecryptor

There is no purpose to pay the ransom because there is no guarantee you will receive the key, but you will put your bank credentials at risk.

Dr.Web Rescue Pack

Famous antivirus vendor Dr. Web provides free decryption service for the owners of its products: Dr.Web Security Space or Dr.Web Enterprise Security Suite. Other users can ask for help in the decryption of .FLAMINGO files by uploading samples to Dr. Web Ransomware Decryption Service. Analyzing of files will be performed free of charge and if files are decryptable, all you need to do is purchase a 2-year license of Dr.Web Security Space worth $120 or less. Otherwise, you don’t have to pay.

If you are infected with FLAMINGO Ransomware and removed it from your computer you can try to decrypt your files. Antivirus vendors and individuals create free decryptors for some crypto-lockers. To attempt to decrypt them manually you can do the following:

Use Stellar Data Recovery Professional to restore .FLAMINGO files

stellar data recovery professional

  1. Download Stellar Data Recovery Professional.
  2. Click Recover Data button.
  3. Select type of files you want to restore and click Next button.
  4. Choose location where you would like to restore files from and click Scan button.
  5. Preview found files, choose ones you will restore and click Recover.
Download Stellar Data Recovery Professional

Using Windows Previous Versions option:

  1. Right-click on infected file and choose Properties.
  2. Select Previous Versions tab.
  3. Choose particular version of the file and click Copy.
  4. To restore the selected file and replace the existing one, click on the Restore button.
  5. In case there is no items in the list choose alternative method.

Using Shadow Explorer:

  1. Download Shadow Explorer program.
  2. Run it and you will see screen listing of all the drives and the dates that shadow copy was created.
  3. Select the drive and date that you want to restore from.
  4. Right-click on a folder name and select Export.
  5. In case there are no other dates in the list, choose alternative method.

If you are using Dropbox:

  1. Login to the DropBox website and go to the folder that contains encrypted files.
  2. Right-click on the encrypted file and select Previous Versions.
  3. Select the version of the file you wish to restore and click on the Restore button.

How to protect computer from viruses, like FLAMINGO Ransomware, in future

1. Get special anti-ransomware software

Use BitDefender Anti-Ransomware

bitdefender anti-ransomware

Famous antivirus vendor BitDefender released a free tool, that will help you with active anti-ransomware protection, as an additional shield to your current protection. It will not conflict with bigger security applications. If you are searching complete internet security solution consider upgrading to full version of BitDefender Internet Security 2018.

Download BitDefender Anti-Ransomware

2. Back up your files

idrive backup

As an additional way to save your files, we recommend online backup. Local storages, such as hard drives, SSDs, flash drives, or remote network storages can be instantly infected by the virus once plugged in or connected to. FLAMINGO Ransomware uses some techniques to exploit this. One of the best services and programs for easy automatic online backup is iDrive. It has the most profitable terms and a simple interface. You can read more about iDrive cloud backup and storage here.

3. Do not open spam e-mails and protect your mailbox

mailwasher pro

Malicious attachments to spam or phishing e-mails are the most popular method of ransomware distribution. Using spam filters and creating anti-spam rules is good practice. One of the world leaders in anti-spam protection is MailWasher Pro. It works with various desktop applications and provides a very high level of anti-spam protection.

Download MailWasher Pro