Blower ransomware is crypto malware that infects users with the help of cracks and keygens

Blower ransomware is data locking malware and one of the Djvu virus variants which on itself stems from STOP ransomware – one of the most prominent threats currently. Researchers believe that the infection originated in Ukraine, although there are also some accomplices from other countries. The malicious payload is usually injected with the help of illegal cracks and keygens,[1] usually downloaded from torrent sites. Blower virus uses AES cipher to lock data and appends .blower extension – the encryption process usually takes only a few seconds, so victims cannot do much to stop it. Databases, documents, pictures, and other data becomes inaccessible, and users are shown a _readme.txt note that explains what happened, and they are asked for a ransom of $490 in bitcoin for the file release. Bad actors also clarify that the amount doubles if the sum is not transferred within 72 hours of the infection. However, this variant might be decryptable, so there is no need to contacting hackers. Users reported that they managed getting infected with two ransomware viruses – Blower and GEFEST (a variant of Scarab) at the same time.[2]
| Name | Blower ransomware |
|---|---|
| Type | Cryptovirus |
| Associated | Djvu ransomware |
| Belongs to ransomware family | STOP ransomware |
| File extension | .blower |
| Ransom amount | $490 – $980 |
| Ransom note | _readme.txt |
| Related files | 1.exe, 2.exe, 3.exe, updatewin.exe, 8651.tmp. exe, hehjrebu.exe, install.exe, vsruwcaw.exe |
| Contact emails | blower@india.com; blower@firemail.cc |
| Decryption | Might be possible, contact security researcher for help |
| Distribution | Infected spam email attachments |
| Removal | Employ reputable anti-malware like MalwarebytesMalwarebytes to remove Blower ransomware |
Cybercriminals who developed Blower ransomware suggest victims send one file for test decryption for free. But this action is done to create a fake sense of trust. We do not recommend trusting these people and contacting them in any way.
Also, note that Blower ransomware demands a huge amount and might not even consider restoring your data. The best solution for file recovery is data backups on external device or cloud services. If you are not sure that you have files you need, you can try data recovery software options that we suggest below the article.
Blower ransomware starts with an encryption process and uses the AES algorithm to change the original code of your files in various formats from photos, documents, video files to audio and archives or databases.[3] All encrypted data get .blower file marker and become unreadable.

The ransom note placement follows the encryption process when every folder on the machine gets _readme.txt. Blower ransomware ransom message reads the following:
ATTENTION! Do not worry my friend, you can return all your files! All your files are encrypted with the unique key. Decrypt tool for you. This software will decrypt all your encrypted files. What guarantees you have? You can send your PC and we decrypt it for free. But we can decrypt only 1 file for free. File must not contain valuable information. You can get a video of the decrypt tool: https://we.tl/t-1aaC7npeV9 Price is $ 980.
Discount 50% available if you contact us first 72 hours, that's price for you is $ 490.
Please note that you never restore your data without payment.
Check your e-mail address if you don’t get it more than 6 hours.
E-mail:
blower@india.com
Reserve e-mail address to contact us:
blower firemail.cc @
Your personal ID:
030GHsgdfT7878YsY9gsafL ***
You need to proceed with Blower ransomware removal and follow expert[4] suggested routine: terminate the virus using professional anti-malware tools and then clean the device using PC repair program like FortectIntego, recover your data using file backups or recovery software.
When you remove Blower ransomware using the automatic method you have the advantage of cleaning the system thoroughly. However, you need to double-check before any data recovery because ransomware can damage your device and encrypt files again if not terminated completely.
Avoid opening and downloading files attached to suspicious emails
Make sure to pay more attention to emails you receive without expectation and do not rush to open files attached to the email itself. You can risk getting cyber infections or malware that delivers direct ransomware on your device from the infected email attachment.
Email often contains executables, Word or Excel documents, PDFs and ZIP files as attachments and when you open the file on your computer, you get the option to enable content that includes malicious macros. When you allow those macros to run payload dropper gets activated, and your system is easily infected.
You can avoid this infiltration if you delete suspicious emails without opening and downloading the attachment. Pay attention to emails you receive and try scanning the file before downloading if you have any doubts.

Terminate the dangerous Blower ransomware virus automatically
The Blower ransomware removal process might be too hard to perform by using a manual technique. For this case, we suggest you download and install reliable computer software. We also offer using a tool such as FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes for finding malicious components in the computer system. Note that all hazardous content needs to be eliminated at once.
Remove Blower ransomware before you proceed with data recovery purposes. Make sure that you reboot your machine to Safe Mode or activate the System Restore feature as this way you will be able to deactivate the malicious activity. Later on, try some data recovery methods that we have displayed below this text. Perform each step as required to reach the best results.
Was this guide helpful?
Be the first to comment