Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2018

How to remove Barack Obama Blackmail ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Barack Obama Blackmail ransomware is a crypto-malware which targets to encrypt .exe files only

Barack Obama Blackmail ransomware image

Barack Obama Blackmail ransomware is a new cyber threat which encrypts executable files on the targeted devices. Researchers note that this malware is also known as Barack Obama's Everlasting Blue Blackmail virus which opens a pop-up window as a ransom note once data encryption is finished. Victims are asked to pay the ransom and contact the attacker via 2200287831@qq.com email address for more information. 

Name Barack Obama Blackmail
Type Ransomware
Also known as Barack Obama's Everlasting Blue Blackmail virus
Symptoms After the encryption, all .exe files become unusable
Contact email 2200287831@qq.com
Distribution It might reach the system inside malicious spam email attachments
Elimination You should use FortectIntego or similar security tool to uninstall Barack Obama Blackmail ransomware safely

If the computer is infected with Barack Obama Blackmail ransomware, users can no longer open executable files. Alongside the encryption process, this virus modifies registry keys to change the icons of .exe files and run the ransomware once the user tries to launch the executable file on the computer. Here is the list of altered registry keys[1]:

  • HKLM\SOFTWARE\Classes\exe\Shell
  • HKLM\SOFTWARE\Classes\exe\Shell\Open
  • HKLM\SOFTWARE\Classes\exe\Shell\Open\Command
  • HKLM\SOFTWARE\Classes\exe\Shell\Open\Command\ “C:\Users\User\codexgigas.exe” “%1”
  • HKLM\SOFTWARE\Classes\exe\EditFlags 2
  • HKLM\SOFTWARE\Classes\exe\DefaultIcon
  • HKLM\SOFTWARE\Classes\exe\DefaultIcon\ C:\Users\User\codexgigas.exe,0
  • HKLM\SOFTWARE\Classes\exe
  • HKLM\SOFTWARE\Classes\exe\

The ransom-demanding message is displayed as a pop-up window which includes the following information:

Hello. your computer is
encrypted by me! Yeah, that
means your EXE file isn’t open!
Because I encrypted it.
So you can decrypt it, but you
have to tip it. This is a big thing.
You can email this email:
2200287831@qq.com gets
more information.

Further analysis revealed that Barack Obama Blackmail ransomware is highly sophisticated as it is programmed to stop numerous processes which are related to antivirus tools. This file-encrypting virus executes the following commands to kill Kaspersky, McAfee, and Rising Antivirus tools:

  • taskkill /f /im KVXP.kxp
  • taskkill /f /im Ravmon.exe
  • taskkill /f /im VsTskMgr.exe
  • taskkill /f /im kavsvc.exe
  • taskkill /f /im Rav.exe
  • taskkill /f /im Mcshield.exe

However, you can use other security tools, like FortectIntego, to remove Barack Obama Blackmail ransomware and protect your computer. Note that you might need to boot your system into Safe Mode first. The instructions showing how to do so are appended at the end of this article. 

Barack Obama Blackmail ransomware illustration

After Barack Obama Blackmail removal you have several options to recover encrypted .exe files[2]. There are effective tools along with the guidelines showing how to decrypt information. Find them below this report. Otherwise, you can use backups to retrieve your data.

Ways to protect your computer against ransomware

Ransomware-type cyber threats travel inside malicious spam emails. The electronic letters might impersonate notifications from legitimate companies to trick people into installing file-encrypting viruses. Note that the malware can disguise as .pdf or .jpg attachment.

Once the malicious attachment is opened, the computer is infected with ransomware. Therefore, you should stay vigilant and carefully monitor your inbox for spam emails. You can search for any grammar mistakes or misspellings along with urges to click on suspicious links or attachments. These are one of the best indicators that you might be a target of ransomware.

Researchers also encourage users to stay away from ads and peer-to-peer (P2P) file-sharing sites. Some ads might be programmed to execute malicious scripts and automatically install malware as well. Therefore, you should use only safe websites and download programs from authorized developers.

Security tools can help you uninstall Barack Obama Blackmail ransomware virus

Researchers[3] warn that regular computer users should never try to remove Barack Obama Blackmail ransomware on their own. There is a substantial risk that people might delete essential system files or kill fundamental processes and damage their computers permanently. 

You should get a professional antivirus software to complete Barack Obama Blackmail removal properly. Our IT experts suggest using one of the following security tools and read the instructions below:

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.