DetoxCrypto ransomware releases two versions at once: Calipso and Pokemon. How do these viruses operate?
DetoxCrypto virus happens to be a severe ransomware-type computer infection, which has been discovered under two different names. The first one is Pokemon ransomware, and the second one is known as Calipso ransomware. Both of these viruses were created to encrypt victim’s files and make data inaccessible. The point of such malicious activity is to swindle money from the victim, asking to pay a ransom in exchange for a decryption software. No matter what, we do not recommend paying the ransom, so instead of reaching for your credit card, you should start thinking about DetoxCrypto removal. We recommend using a strong malware removal tool, for example, FortectIntego software to remove DetoxCrypto virus. For more information about its removal, follow instructions provided at the end of this article.
The infection is distributed in a form of a single executable file, which, once executed, drops the following files on victim’s computer:
- MicrosoftHost.exe – this file is intended to encrypt victim’s data and stop database servers. It also changes victim’s desktop wallpaper with an image displaying a message from cyber criminals.
- Pokemon.exe or Calipso.exe file – this is ransomware’s executable file that allows to decrypt victim’s data in case the victim has the right decryption key. It also plays the audio file.
- .wav extension file – this is the audio file, which is going to be executed by Pokemon.exe or Calipso.exe program.

Both these viruses act similarly and during the encryption process, they do not append any file extensions to encrypted data. However, there are some differences between these malware variants. Besides, new versions have been spotted, so we would like to list all DetoxCrypto virus variants below.
Versions of DetoxCrypto malware
Calipso ransomware virus – this virus creates a folder named Calipso, where it stores its components. This virus plays an audio file, which reads a short message informing the victim that files have been encrypted and to unlocked them the victim needs to pay 2 Bitcoins in 3 days. According to the message played, the ransom price increases each extra day by 1 BitCoin. The message claims that if the victim deletes the virus, all encrypted files will be removed as well. The ransomware sample that was tested provided motox2016@mail2tor.com email address. The victim can contact cyber criminals via it to get instructions on how to pay the ransom. What is also interesting about this ransomware variant is that it screenshots victim’s desktop image and sends it to cybercriminals’ server. Although there is no exact information why this virus acts like that, we assume that it might try to find valuable files on victim’s screen and attempt to ask the victim to pay a higher ransom.
Pokemon ransomware virus, also known as We are all Pokemons virus. Although it is named similarly to PokemonGo ransomware, this malicious program is an entirely different example of malware. Once it locks the computer, it executes the audio file, which basically plays a silly melody. The desktop background will be changed to an image displaying some text and a sad Pikachu next to it. The price of the decryption software does not differ from Calipso’s. The victim is asked to pay up in 96 hours; otherwise, all files on computer will be deleted. According to the ransom note, the same happens if the victim removes the ransomware components from the computer. The email provided on the lock screen is contact365@mail2tor.com.
Serpico ransomware virus. This is the latest version of this malware. Though it asks for a relatively modest ransom, do not consider paying the money. Its operation ways and encryption techniques are still under the veil of mystery. In addition, Serpico virus has a distinctive feature – it does not append any extension to the corrupted files. Its distribution techniques do not differ much from the rest of ransomware threats. Avoid reading spam emails and verify the sender before opening the form of a supposed official document. File sharing domains should be avoided as well. Finally, the virus presents the same email address as calipso malware – motox2016@mail2tor.com.
MotoxLocker ransomware virus. This is the newest variant of DetoxCrypto ransomware, which locks files with AES encryption and then demands a ransom of 50 Euros. Of course, the virus claims that it is impossible to recover data in any way except of paying the ransom. Luckily, that is not true because victims of MotoxLocker virus can now recover their files for free – MotoxLocker decryption tool has already been released. It appears that there were flaws in virus' code that allowed to reveal the unique decryption key quite easily. Before using this tool, MotoxLocker malware must be removed from the compromised computer.
September 2016 update: DetoxCrypto ransomware now imitates antivirus to get into the users' computers
DetoxCrypto ransomware does not cease to cause havoc on the users' computers, but the virus developers want more. They are still looking for the best virus distribution techniques and have recently released a test version of the virus which spreads disguised as malwerbyte.exe executable. You can clearly see a problem here. Though there is a mistake in the title, some less attentive users may easily mistake it for the legitimate MalwarebytesMalwarebytes antivirus file. You can be offered to download this file in some deceptive software update pop-up or receive it pinned to a malicious email directly to your inbox. Thus, you have to be very careful and update or download the desired software only through the reputable sources. Luckily, this praticular variant of the virus does not encrypt files and can be deleted from the computer quite easily. Nevertheless, as we have already said, the hackers might be simply testing the waters, and it is just a matter of time when this strategy of will be applied for spreading real ransomware.
Methods used to distribute DetoxCrypto malware
DetoxCrypto virus, just like any other crypto-ransomware type virus is distributed via malicious emails and malvertising. Sadly, we cannot provide any specific email addresses that send emails including this ransomware, because crooks create hundreds of them. Our advice is always to bypass emails that come from unknown sources, and not to open files attached to them. You might also install this ransomware after clicking on a malware-laden web advertisement. We suggest you to avoid clicking on aggressive ads that urge you to scan your computer system with some never-heard-of computer security software and do not agree to install Java or Flash updates if these offers come from suspicious third-party websites. If you think that you need to update these programs, just go directly to their official developer’s site and install legitimate ones. What is more, this malware might be distributed via exploit kits, although currently there is no official information claiming that a particular exploit kit spreads one of these DetoxCrypto viruses. However, we strongly suggest installing a strong anti-malware program to protect your PC from malware attacks.
DetoxCrypto removal tutorial
To remove DetoxCrypto virus, please use a strong malware removal software. Make sure you update it to its latest version before you allow it to perform a system scan. We do not recommend you to carry out DetoxCrypto removal manually because it is a highly important procedure that needs to be completed in a correct way. If you are not an advanced PC user, please do not try to delete this virus manually. If you cannot download anti-malware software or update the one that you have because this virus does not allow you to do so, please follow these instructions:
Did this guide help?
4 comments
Glass10
Its incredible how quickly these ransomware viruses spread and how many computers they manage to infect! My aunt has become a victim yesterday... no idea how to decrypt files. We were affected by the pokemon-themed ransomware version.
Tears
Ive got infected with Calipso, I think. No pokemons on my screen. But two bitcoins?? aint gonna pay that!
Omen
Why people pay ransoms at all? Why would you support a cyber criminal? if the ransom was not that big?
Tears
Nah, I wouldnt. Im just saying that cybercriminals are greedy as hell!