Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2021

How to remove RansomPlus ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

RansomPlus ransomware – malware that can result in personal file loss

RansomPlus virus

RansomPlus is a file-encrypting Trojan horse falls into ransomware[1] category, as it wants to extort money from victims by making their personal files useless. As soon as the infection hits the computer system or the entire network, it converts all files into useless pieces of data by locking them and adding the .encrypted extension. It is important to note that they are not corrupted but rather locked and require a unique key that is in the possession of cybercriminals. Malware also drops a ransom note to deliver contact and other relevant information to victims of the virus.

Name RansomPlus
Type Ransomware
File extension .encrypted
Ransom note YOUR FILES ARE ENCRYPTED!!!.txt
Removal Perform a full system scan with anti-malware such as SpyHunterCombo Cleaner
System fix To remediate Windows and repair damaged system files, use FortectIntego

Encryption strength is currently unknown, and although we cannot promise, it is likely that a free decryption tool might be created by malware researchers soon. Until then, victims of the ransomware are advised to remove RansomPlus using anti-malware tools such as SpyHunterCombo Cleaner, and, if possible, recover files from backups.

When ransomware steps into the target system and encrypts files, it also adds .encrypted file extensions to all of them and finally leaves a ransom note on the desktop. It is a short text document called YOUR FILES ARE ENCRYPTED!!!.txt. The virus leaves the following message:

YOUR FILES ARE ENCRYPTED!!!
To restore (decrypt) them you must:
1. Pay 0.25 bitcoin (btc) to address [deleted]
You can get BTC on this site http://localbitcoins.com
2. After payment you must send Bitcoin Transaction ID to E-mail: andresaha82@gmail.com
Then we will send you decryption tool.

This is a typical ransom message when criminals ask the victim to show the transaction ID to prove that the victim made the transaction and paid the ransom.

As you can see, authors of this virus want victims to contact them via andresaha82@gmail.com email address. However, we must remind you that there is no point to trust cybercriminals. They can lie to you, promise you to give you a decryption tool even if they do not have it, or, in the worst case, send you a decryption tool along with some malicious programs such as Trojans[2] or spyware-type viruses.

Therefore, a thorough RansomPlus removal is required in order to protect your computer from additional attacks. As you probably understood, we do not recommend you to pay the ransom!

Ransomware distribution techniques

Ransomware viruses are made to look trustworthy at first sight. For example, Locky virus[3] was probably the first one to use an obfuscation technique based on Microsoft Word. Authors of this infamous ransomware managed to insert malicious scripts into Word documents, which only needed to be activated via Macros to start carrying out malicious procedures on the target system.

Nowadays, this ransomware distribution method is still one of the most efficient ones. Remember that scammers tend to deliver viruses via email, so we advise you to stay away from all shady-looking emails, and in case you receive an unexpected letter from Amazon or PayPal, do not rush to open it. It might be a phishing email[4], professionally designed by malevolent individuals. Have data backups and protect the system with anti-malware software for multi-layer protection[5].

Eliminate malware from your system and only then attempt file recovery

In case the virus managed to encrypt all your files, and you do not have a backup, then you have two choices – pay the ransom and expect criminals to have mercy, or remove RansomPlus ransomware and start recreating your files from the very beginning.

Although the second option sounds like a much more painful choice, at least you won’t risk losing your money. Besides, you can try these data recovery methods provided right below RansomPlus removal instructions. These instructions are meant to help you to deactivate the virus and successfully run the anti-malware program.

4 comments

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.