Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2018

How to remove Maykolin ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

Maykolin locks files with .[fuga139gh@dr.com] file extension

The picture illustrating Maycolin virus

Maykolin is a severe cyber infection, which belongs to the crypto-ransomware family. It's constructed on the .NET ransomware pattern[1], which enables the communication with command and control server to report a new victim and pass along generated data (user ID and key). It uses a AES and RSA[2] cryptography to encrypt personal files and attaches .[maykolin1234@aol.com] file extension. According to the latest reports, ransomware researches detected a new Maykolin ransomware variant, which appends .[fuga139gh@dr.com] file extension. 

As soon as the virus finishes file encryption, it generates a README.maykolin1234@aol.com.txt or README.fuga139gh@dr.com.txt text file, depending on which Maykolin version initiated the attack. The .txt file stands for a ransom note, which provides all the necessary information for the victim to understand what has just happened and what he or she has to do. According to NoVirus security experts,[3] Maykolin ransom note and behavior might resemble Dharma family of ransomware.

Extortionist explain that the PC was attacked by Maykolin virus and that each individual file can be decrypted with a unique AES-key. The victim is prompted to establish contact with extortionists ASAP via e-mail maykolinl234@aol.com and indicate the personal ID number. The sooner he or she contacts the crooks, the smaller the ransom will be demanded. The exact ransom is not indicated, except that it will be accepted in Bitcoins. 

All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC.If you want to restore them, write us to the e-mail maykolinl234@aol.com
Your ID number is *** Write your ID number in e-mail and send us.
You have to pay for decryption in Bitcoins.The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.
Free decryption as guarantee
Before paying you can send to us up to 3 files for free decryption.Please note that files must NOT contain valuable information and their total size must be less than 10Mb.
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
https://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
http://www.coindesk.com/information/how-can-i-buv-bitcoins/
Attention!
• Do not rename encrypted files.
• Do not try to decrypt your data using third party software, it may cause permanent data loss.
• Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

To prove the reliability, extortionists offer to decrypt three files for free. The bad news is that the ransomware is currently not decryptable, well, at least for free. The only way to decrypt files encrypted by Maykolin ransomware is to pay the ransom and expect that hackers will send you a decryption code. Unfortunately, no one can guarantee you that. 

If you have backups for most important files, all you have to do is to remove Maykolin virus from the system. Even if you don;t have backups, we recommend doing the same. Maykolin removal will swipe all your personal files that have .[fuga139gh@dr.com] or .[maykolin1234@aol.com] file extension away, but you can try to recover them after the removal of a virus. Maykolin removal does not take long if you run FortectIntego or MalwarebytesMalwarebytes.

The example of Maycolin ransom note

If this malware were a variation of Dharma virus, there could be a chance to recover the files as this malware as the original version is decryptable. However, further analysis reveals that it is an independent file-encrypting virus. 

Ways to spread ransomware

Assaults of crypto-malware are often carried out with the assistance of trojans. In order for them to execute on the system, they cooperate with exploit kits. Often they are placed in torrent-sharing domains. Apart from these dissemination strategies, .[maykolin1234@aol.com] file extension virus can  can be distributed via email spam and malicious attachments. Therefore, it's important not to open email messages that contain grammar / typo mistakes, that are sent by unknown and suspicious senders, don't have body text, contain .doc, .txt, .pdf or other forms of attachments. 

Hackers can also exploit ads for their malicious campaigns. There is also a probability for this attack to occur if you enable a corrupted browser extension. Beware of corrupted Google Docs invitations as well. Besides remaining vigilant, you should also install and run malware removal program in addition to anti-virus. 

Maykolin elimination guide

Ransomware virus can hardly be terminated from the system manually. Therefore, don't waste your time to remove Maykolin by looking for related programs and files[4] under various system's folders. Most of them, except the c0e.exe exploit, which keeps sucking up CPU, can hardly be noticed without a dedicated software. Thus, to remove Maykolin virus completely use one of the programs suggested below. 

Even though criminals offer you to install Maykolin Decrypter for a particular number of Bitcoins, you should restrain from buying it. The decrypter may work and unlock your files, but each ransom is a motivation for hacker to keep doing the crimes. Thus, to not wait any longer and remove the ransomware from your PC. 

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.