BadNews ransomware – dangerous cryptovirus which locks important files and requires the money for their decryption

BadNews virus is a ransomware-type virus which is meant to encrypt[1] all victim’s files and demand a ransom in exchange for a decryption key[2]. To put it simply, the program uses a public key for data encryption and then creates a decryption key (private key), which it stores on its server and hides it securely. When Bad News ransomware steps into the system, it encrypts files and adds the ID [victim's_ID].BadNews file extension to them. Finally, the virus launches a window and displays an HTML message named How To Decode Files.hta. Crooks announce about the encryption and demand a particular ransom for file decryption.
| Name | BadNews |
|---|---|
| Category | Ransomware |
| Extension | ID [victim's_ID].BadNews |
| Ransom message name | How To Decode Files.hta |
| Ransom | No closer details are provided for this case |
| Encryption algorithm | AES and RSA |
| Prevention | Install strong antivirus protection |
| Removal | Get FortectIntego and eliminate the virus effectively |
The ransom message looks like this:
ALL DATA ON THIS PC HAS BEEN ENCRYPTED
Your
ID iHupX3tzhxqXTo get the decryptor you should:
Send 1 test image or text file to BM-2cTAPjtTkqiW2twtykGm5mtocFAz7g5FZc@bitmessage.ch.
In the letter include your personal ID (look at the beginningof this document).
We will give you the decrypted file and say price fordecryption all files
after payment you will receive a decryptor and instructions
We can decrypt one file in quality the evidence that we have thedecoder.Attention!!!
Only BM-2cTAPjtTkqiW2twtykGm5cc0pyc@tfr0mpcr1sk@bitmessage.ch can decryptyour files
Do not trust anyone BM-2cTAPjtTkqiW2twtykGm5mtocFAz7g5FZc@bitmessage.ch
Attempts to self-decrypting files will result in the loss ofyour data
Decoders for other IDs are not compatible with your ID data,because each user's unique encryption key
The ransom price is currently unknown in this situation as there are no certain details provided. However, cybercrooks who spread ransomware such as BadNews ransomware usually urge for a type o cryptocurrency, e.g., Bitcoin or Monero. Moreover, the price often varies between $500 and $1500.
Nobody wants to lose all files in a second; however, that doesn’t mean that you should go and pay the ransom that cybercriminals hiding behind BadNews demand paying. You risk being left out without access to your files and also without a considerable amount of money in case cyber criminals decide not to provide you with the decryption key.
Therefore, our team suggests removing the virus instead and taking all possible actions to recover files for free. If you do not have an antivirus program, you should install anti-malware software (because it is capable of detecting a wider range of computer infections[3] than just viruses). Our team says that FortectIntego software is the one users should rely on. To remove BadNews ransomware, firstly restart the computer using instructions presented in the elimination guide.
Moreover, performing the BadNews ransomware removal is strongly recommendable as some ransomware-type viruses can “clean the way” for other malware forms. When your computer security level decreases, you might catch a serious infection and suffer even worse consequences. Be aware of such activity, eliminate the cyber threat ASAP.

Ransomware attack prevention tips
According to LosVirus.es malware experts[4], ransomware attacks should be avoided because, in the majority of cases, viruses manage to distort the victim’s files in a way that they become unrecoverable. To avoid the risk of losing files for good, you should do everything to avoid ransomware attacks. That is rather an easy task to do[5].
First of all, you should install anti-malware software to recognize malicious attempts to encrypt your files; secondly, you should create a backup of the most important data. To create a backup[6], take an external disk, plug it into your computer and transfer the most important files to the external device. Always keep such data storage devices unplugged from your PC – this way, the virus won’t be able to reach and infect them. Backups can be used anytime when you need them.
Moreover, avoid opening attachments that are clipped to phishing messages. Spam emails often carry hazardous content with them which comes in the form of a clipped attachment or a link. Additionally, install strong antivirus protection to prevent various infections. If you do so, you have a bigger chance of avoiding ransomware attacks as well.
Remove BadNews ransomware from your PC system by performing some steps

When strong ransomware virus strikes, the situation becomes unenviable as the most important data becomes unavailable for the use. However, one should not give up and take actions to remove BadNews virus from the system. That is rather a simple thing to do, but only if you have the anti-spyware software. We suggest installing FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. Speaking about ransomware viruses, manual removal method is not a recommended one.
Therefore, we suggest users using tools that we recommend for BadNews removal. Be cautious while performing every step. After you proceed with the elimination, there is one more goal you need to accomplish to secure your computer system fully. Performing system backups is a necessary action – you need to make sure that all virus-related content was removed from your computer successfully.
Taking about data recovery, you can try some third-party software that we have provided below this article. If you perform each step as shown in the instructions, these methods might help you to get your corrupted files back to their starter positions.
Did this guide help?
4 comments
samse
Well, can there be any goodnews about this ransomware?
Zita
I emoved the virus, but i cannot recover files. theyre lost forever...
Kody__7
I am screaming!!! I need to get my files back, all my work is on this computer. please please please...
ramen
Thanks for the help, please provide the decryption tool as soon as possible