Eman ransomware – Matrix version that locks data using AES-128 and RSA-2048 algorithms

| Name | Eman ransomware |
|---|---|
| Type | Cryptovirus |
| Related | Matrix ransomware |
| executable | nwovkcyl.exe |
| File extension | [EncodeMan@qq.com].[gibberish].EMAN |
| Contact emails | EncodeMan@qq.com; EncodeMan@protonmail.com; EncodeMan@tutanota.com |
| Encryption method | AES-128 and RSA-2048 |
| Ransom note | #README_EMAN#.rtf |
| Distribution | Spam email attachments, hacking RDP service |
| Decryption | Not possible |
| Elimination | Use FortectIntego to remove Eman ransomware |
Eman ransomware virus is a cyber threat that people are not happy to get because it costs money to get your files recovered. Unfortunately, often cybercriminals disappear after the payment and ignore the victims. It is possible that a decryption tool doesn't exist and hackers even lie about the whole file recovery aspect. At the moment, there is no information about the Eman decryptor.
This is the reason you shouldn't pay the demanded ransom because it may lead to money or permanent data loss. The best solution for this ransomware infection is performing Eman ransomware removal and then attempting to restore your files with the help of appropriate tools or backups.
As a typical crypto-demanding virus, Eman ransomware develops a ransom note and places that on victims' desktop and the system in the form of the #README_EMAN#.rtf file. This ransom note reads the following:
HOW TO RECOVER YOUR FILES INSTRUCTION
ATENTION!!!
We are realy sorry to inform you that ALL YOUR FILES WERE ENCRYPTED
by our automatic software. It became possible because of bad server security.
ATENTION!!!
Please don't worry, we can help you to RESTORE your server to original
state and decrypt all your files quickly and safely!INFORMATION!!!
Files are not broken!!!
Files were encrypted with AES-128+RSA-2048 crypto algorithms.
There is no way to decrypt your files without unique decryption key and special software. Your unique decryption key is securely stored on our server. For our safety, all information about your server and your decryption key will be automaticaly DELETED AFTER 7 DAYS! You will irrevocably lose all your data!
* Please note that all the attempts to recover your files by yourself or using third party tools will result only in irrevocable loss of your data!
* Please note that you can recover files only with your unique decryption key, which stored on our side. If you will use the help of third parties, you will only add a middleman.HOW TO RECOVER FILES???
Please write us to the e-mail (write on English or use professional translator):
EncodeMan@qq.com
EncodeMan@protonmail.com
EncodeMan@tutanota.com
You have to send your message on each of our 3 emails due to the fact that the message may not reach their intended recipient for a variety of reasons!In subject line write your personal ID:
1BB925C37CFF3DB1
We recommed you to attach 3 encrypted files to your message. We will demonstrate that we can recover your files.
* Please note that files must not contain any valuable information and their total size must be less than 5Mb.OUR ADVICE!!!
Please be sure that we will find common languge. We will restore all the data and give you recommedations how to configure the protection of your server.We will definitely reach an agreement 😉 !!!
The lengthy note states about the encryption process, the state of your files and possible solutions, contact information such as emails (EncodeMan@qq.com; EncodeMan@protonmail.com; EncodeMan@tutanota.com). However, as many reasearchers[2] advise, contacting these hackers can be very dangerous for you personally and for the system of your device.
Since this virus use both types of encryption methods, your files are even more difficult to restore. You should rely on your data backups and restore files after proper Eman ransomware elimination. You should perform that using tools like FortectIntego. These anti-malware programs can detect and remove any malware and analysis[3] shows that ransomware executable nwovkcyl.exe can be detected by various AVs.
These results may vary but you can see some names like these:
- HEUR/AGEN.1034258;
- Trojan.Ransom.Matrix;
- Trojan/Win32.Matrixran.R234829;
- Ransom.Matrix;
- Trojan.Win32.Krypt;
- Generic.Ransom.Matrix.B38FC644;
- etc.
You should immediately think about ways to remove Eman ransomware when you notice anything similar because in time this threat can change various settings of your device. It may affect Windows Registry keys[4] to make sure that malicious payload is launched every time your PC is rebooted.

Ransomware distribution ways
These crypto-demanding viruses vary from version to version but, in most cases, there is one way that most of the malware creators use to spread their products. This technique is spam email attachments with a malicious script or direct malware payload. Often these emails look safe and legitimate because masqueraded behind known company names or the main MS Word or Excel file is called “Invoice”, “Order info”.
These file attachments may be set to initiate the download of malicious payload or install ransomware directly to the computer. Various trojans or different kinds of threats are designed to infect devices with more severe intruders like ransom-demanding malware.
However, there are a few different methods to spread this particular type of cyber threat. Additionally, to the spam email campaigns, hackers use exploit kits and breaks through unprotected RDP service to initiate the infection and affect the data on the system.
Get rid of Eman ransomware until it is too late
The main concern when dealing with cyber threats like ransomware is the data that you may lose. You need to remove Eman ransomware using reputable anti-malware tools like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes and clean your system thoroughly. Then, you can try to restore files from a backup or use data recovery tools.
It is important to proceed with Eman ransomware removal as soon as possible so that you can terminate this threat before any severe damage to the system. Often, these cyber intruders can disable your antivirus and detection becomes difficult. Follow our guide below and enter eliminate this malicious crypto-extortionist.
Was this guide helpful?
Be the first to comment