Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2017

How to remove Anubis ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Anubis ransomware now appends .anubi file extension

Anubis ransomware asks for money

Anubis ransomware is a file-encrypting virus[1] which is based on EDA2 ransomware. Malware has been spotted on October 2016, encoding files with .coded file extension. However, almost one year later, in 2017, researchers discovered a brand new variant of ransomware. This August Anubi NotBTCWare has been noticed appending [].anubi extension to targeted data.

The original version of Anubis virus is also known as Coded ransomware or .coded file extension virus due to the suffix appended to targeted audio, video, image or text files. Then the malicious program also changes desktop wallpaper with a picture of the Egyptian god and short message, which includes the following information:

HELLO

Time is the most valuable thing you can have.
At the moment all files on computer encrypted.
Do you want to understand how to get your data and save time,
Whrite to this address:

Then the virus asks to contact ransomware developers via email:

Email to me: support.code@aol.com or support.code@india.com

The victim is asked to write a message to the first email address, and in case no one replies within 48 hours, try to get in touch with crooks via the second listed email. Anubis malware says that the victim should read the information provided by “Decrypt instructions” file, which the virus generates and saves on the desktop.

This malevolent computer program is designed to be destructive, and it is nearly impossible to sort out what the decryption key (essential for data recovery) is. If you have been infected with this harmful virus, please do not listen to criminals’ commands and do not pay the ransom.[2] There is no guarantee that you will get your files back even if you pay the ransom.

Us, like any other malware researchers, recommend you to remove Anubis virus as soon as possible, and if you do not have an anti-malware[3] program, we recommend FortectIntego program. Please do not try to eliminate this ransomware manually because it is not as easy as you think. Ransomware is not a regular program, and it does not provide an uninstaller.

The revival of ransomware: Anubi NotBTCWare virus emerges on August 2017

The new version of Anubis ransomware seemed to be related to BTCWare. However, after the investigation, it was named as Anubi NotBTCWare virus. This crypto-malware adds [].anubi file extension to the targeted files and provides data recovery instructions in __READ_ME_.txt.

The ransom note asks to contact criminals via anubi@cock.lt email address to learn how much they have to pay for the data recovery. According, to the message, the size of the ransom is set based on how fast victims write to hackers. The final deadline – 36 hours. Later the decryption key is said to be deleted. However, you should still not trust developers and remove Anubi NotBTCWare with an antivirus program.

The picture of Anubis ransomware virus

Infiltration methods of the ransomware viruses

Ransomware viruses are distributed in the form of safe-looking files, and that is why we say that the discussed virus spreads and acts as a Trojan horse. Typically, crooks create a safe looking file, for example, Word document, and insert malicious scripts into it.

Then they add such file to an email message and send it to thousands of victims. In most cases, criminals target employees of large enterprises and send such deceptive emails[4] to their work emails, because they expect to infect the entire computer network with the help of one inattentive employee. Experts from No Virus[5] remind to be careful and stay away from emails that come from unknown individuals.

However, you can also get infected with ransomware after visiting a malicious website that contains an exploit kit. You can get redirected to such site by clicking on a malware-laden ad, so please be attentive and think before clicking on links, banners, or pop-up ads, no matter what they offer to you.

Elimination guide for Anubis ransomware

To safely remove Anubis virus from the system, we recommend using removal instructions provided below. You can try to start your anti-virus tool right away, but we highly suggest you start the PC in a Safe Mode with Networking first to prevent the virus from deleting your files or damaging your computer even more.

Keep in mind that Anubis removal has to be performed with reputable antivirus or malware removal program. For this ask, we recommend one of these tools: FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Don’t forget to update security software before running a full system scan.

3 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.