What is known about Thedon78@mail.com ransomware?
Thedon78@mail.com virus is yet another ransomware, which indicates the renewal of FenixLocker ransomware virus[1], which has been recently cracked by iT experts who specialize in reverse-engineering malware. This virus has been identified as FenixLocker because it used to insert a string “FenixIloveyou!!” into every encrypted file. Speaking of the new version of it, which is dubbed Thedon78@mail.com ransomware, we must say that it appears to be an enhanced virus that uses KXCD number generator to protect password generation. The virus inserts a ransom note called Help to decrypt.txt into every file that holds encoded data, also drops one on the desktop. These ransom notes do not provide a lot of information, but informs the victim about what needs to be done to restore encrypted files. The culprits ask the victim to send the unique identification key to Thedon78@mail.com and wait for instructions. It seems that criminals have changed the contact email address because earlier they used the inbox of centrumf@india.com account.

If your files have been jeopardized by this virus, most likely you will not be able to open or edit them. This is the aim of cyber criminals – they want you to lose access to your files, memories, and all important data that you store in your computer[2]. Please bear in mind that malware analysts managed to defeat the previous virus’ version, and some signs show that Thedon78@mail.com decrypter might be published soon, too. We definitely recommend you to keep your money to yourself and not pay the ransom that these hideous frauds demand you to pay. They tend to ignore victims after they pay the ransom, so expect to be forgotten even if you pay the ransom[3]. You must understand that ransomware authors only care about money, and they do not waste time trying to send out decryption keys to everyone who paid the ransom. So instead of wasting your money, remove Thedon78@mail.com virus as soon as you can. The easiest way to eliminate the ransomware is to run a malware-removal tool, so you can use FortectIntego or similar software. You can find a short guide on how to start Thedon78@mail.com removal right below the article. Such viruses typically tend to block security programs, so you might not be able to delete it before you reboot your computer into a Safe Mode with Networking.
How ransomware viruses are distributed?
There are dozens of ways how ransomware finds a gap to slip into your computer system[4]. Of course, in the majority of cases, it obfuscates itself as a safe file and rides into the computer system as a Trojan horse when downloaded/opened by a user who doesn’t recognize that it is a malicious file. The most popular ransomware distribution method is sending this virus via email, so beware of deceptive emails that ostensibly deliver you important files or programs. Watch out for emails that contain a lot of grammar mistakes, also those that promise too good to be true deals, and never open file attachments or links (not even the Unsubscribe button!) if the email comes from an unknown sender. Next, ransomware is distributed via malvertising, so watch out for fake ads online. There are so many fake advertisements and untrustworthy websites, and it can be hard to identify which one is dangerous and which one is not. Clicking on a corrupted ad[5] can take you to hazardous websites or convince you to install a malicious program. A trustworthy anti-malware software can protect you and avoid these risks.
How to uninstall this virus?
Users who have their computers compromised by Thedon78@mail.com virus should backup encrypted data and wait for a decryption tool. Bear in mind that it is not easy to create it, so if you have been infected, better be patient. If you do not plan to pay the ransom, remove Thedon78@mail.com ransomware now using the anti-malware program. Thedon78@mail.com removal instructions are below.
Was this guide helpful?
Be the first to comment