Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2017

How to remove 0000 ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

0000 malware targets your personal files

0000 ransomware screenshot

0000 virus is the name of a file-encrypting threat classified to CryptoMix[1] category. Besides Globe Imposter group, which keeps bothering the virtual community with new versions, the developers of the former also keep IT experts busy. This version accompanied another recent XZZX virus variation.

The developers are also known for their sense of humor by adding extensions referring to pop culture, movies and random words. Likewise, this version gained the name after due to the .0000 file extension it appends to the corrupted data. This specific number is said to be angel number, known in numerology. 0000 malware does not possess any elaborate changes except the file extension and four email addresses:

  • y0000@tuta.io;
  • y0000@protonmail.com;
  • y0000z@yandex.com;
  • y0000s@yandex.com;

It also drops a _HELP_INSTRUCTION.TXT file with a brief message that the affected users should contact the owner of this CryptoMix variation via all four addresses. It does not indicate specific ransom sum. It is likely that it depends on how fast the victims will contact the perpetrators. In contrary, it is recommended to focus on 0000 ransomware removal rather than complying with the demands.

Destructive commands behind the “angelic” disguise

Despite the reference to angelic creatures, the virus possesses quite menacing power. 0000 malware retains the feature to use 11 public RSA keys[2]. What is more, the malware launches a series of commands, which trouble restore processes, and deletes shadow volume copies[3]:

  • sc stop VVS
  • sc stop wscsvc
  • sc stop WinDefend
  • sc stop wuauserv
  • sc stop BITS
  • sc stop ERSvc
  • sc stop WerSvc
  • cmd.exe /C bcdedit /set {default} recovery enabled No
  • cmd.exe /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
  • C:\Windows\System32\cmd.exe” /C vssadmin.exe Delete Shadows /All /Quiet

Considering the frequency of new versions, it is not recommended to contact the felons and pay the ransom. Note that there is a free decryption software created by Avast IT experts. Before using it, remove 0000 crypto-malware completely.The image displaying 0000 virus

Distribution campaign remains the same

BC4C39B0AE.EXE or another random file can activate 0000 virus hijack. It suggests that the malware is spread disguised as apps. Therefore, pay utmost attention when you install new programs. Examine all stages of the installation wizard.

In addition, be wary that this malware uses bots to send out emails with the attachments bearing 0000 virus or another CryptoMix variation. Finally, the developers also use RIG exploit kit. It targets specific vulnerabilities in web browsers.

If found any, it directs targeted users to phishing sites asking to download the executable of the malware disguised as a legitimate file. Thus, update your browsers as well as security tools, such as FortectIntego or MalwarebytesMalwarebytes. They will also help you complete 0000 malware removal.

Terminate 0000 ransomware

Regarding the ominous features of this malware, it is necessary to remove 0000 virus as soon as you notice the locked files or the ransom message. You might be unable to run malware elimination program in normal mode, so follow below-shown instructions. After that, launch malware elimination program to start 0000 virus removal. After that, proceed to data recovery process.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.