Apocalypse virus continues to attack computer users: aggressive and active in 2017
Apocalypse virus seems to be a poorly programmed ransomware[1] that has already been decrypted by a well known virus researcher Fabian Wosar[2]. If you are dealing with ApocalypseVM or Fabiansomware, which are two different versions of this file-encrypting malware, you should know that they both have been defeated and you can use free decrypters to recover your files. However, don’t forget that cyber criminals are stubborn people so have been trying to earn as much money as possible, so they can easily add new updates to each of their viruses. Besides, no matter if there is a free decrypt tool available on the Internet or not, you still need to remove Apocalypse ransomware from your computer. For that you can use FortectIntego.
The first version of Apocalypse ransomware encrypted files by appending .encrypted file extensions to them. However, the latest its version comes with changes and uses more complicated file extension which consists of such details as victim’s country code, victim’s ID, etc. The extension which is used by the latest version of Apocalypse looks like that:[the name of the file].id-*[8characters]+countrycode[cryptservice@inbox.ru].[random7characters]. Besides, this ransomware variant creates an individual copy of the ransom note for each file, named like [Filename].encrypted.How_to_Decrypt.txt. The ransom note is usually named as [md5].txt. As soon as this virus finishes its encryption procedure, it also deletes Volume Shadow Copies to prevent the user from recovering them. The virus also installs a malicious version of file named windowsupdate.exe which is usually used Microsoft or Apple[3]. This file is assigned to Startup programs and is used to display the lock screen that provides the following information:
IF YOU ARE READING THIS MESSAGE, ALL THE FILES IN THIS COMPUTER HAVE BEEN CRYPTED!!
documents , pictures, videos, audio, backups, etcIF YOU WANT TO RECOVER YOUR DATA, CONTACT THE EMAIL BELOW.
EMAIL:
WE WILL PROVIDE DECRYPTION SOFTWARE TO RECOVER YOUR FILES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
IF YOU DONT CONTACT BEFORE 72 HOURS, ALL DATA WILL BE LOST FOREVER
Different versions of Apocalypse malware provide different contact emails, such as decryptdata@inbox.ru, ransomware.attack@list.ru, decrptionservice@mail.ru, getdataback@bk.ru, datarecovery@bk.ru or fabianwosar@mail.ru. The most recent version of Apocalypse reportedly uses crypt32@mail.ru email address (this version was spotted on January 22, 2017). No other modifications were discovered, so we assume that previous email accounts were probably closed for security reasons. Speaking about Apocalypse/Al-Namrood ransomware, we cannot provide any information regarding the ransom price since these viruses do not provide any information on what amount of money do the cyber criminals want in exchange for the data. Either way, it is not advisable to pay up as it only benefits the crooks[4], whereas you may be left without your money as well as your data. Besides, you can try decrypting your files with decryption tools that have been released by malware researchers. You can find informative guide on how to remove Apocalypse as well as data recovery instructions in the tutorial provided below the article.

Can you keep your computer safe from ransomware viruses?
As long as your computer is not infected with any virus, your main priority should be protecting your device with a triple-layer protection. First of all, you should use the best antivirus technology, second, you should use it alongside anti-malware or anti-spyware software, and finally, you should create data backups. It is also recommended always to keep your operating system updated to its latest version, to eliminate any vulnerabilities[5]. On top of that, you should keep watch for the virus yourself. Pay attention to your Inbox because ransomware viruses like Apocalypse usually spread through malicious emails. Do not open suspicious emails or download added attachments. This should help to keep the virus away. However, viruses are unpredictable and can use a variety of different techniques to get into your computer. So if you have already been infected, you should start thinking about Apocalypse removal without wasting time.
Apocalypse removal help
If you are planning Apocalypse removal, you should seriously weigh your capabilities. Do you have the proper skills to do it? Is your computer equipped with powerful antivirus software? If you answered “YES” to both of these questions, you are ready for the virus removal. You will have to use a reputable antivirus scanner to detect and remove Apocalypse virus and its related files from your device. However, some computer knowledge will be needed if any problems occur in the process. If your antivirus is having difficulties removing the virus, you will have to follow special instructions to block some of the viruses most aggressive processes. You will find these instructions below.
Did this guide help?
Be the first to comment