Decme ransomware – a cryptovirus that encrypts all files and appends a three-part extension to them

Decme ransomware is a file-locking parasite that, after it gains access to a computer it encrypts all files and demands a ransom for a promised decryption tool. This cryptovirus belongs to a small Voidcrypt ransomware family, with members like Shiton, Lalaland, Konx, and others.
During the encryption[1] process, the Decme ransomware virus appends all non-system files, like documents, archives, pics, etc., with a triple extension: email address of the criminals in brackets, appointed victim ID also in brackets, and .decme extension. When the encryption is done, files are rendered inaccessible.
When encoding of all personal user data is completed, the Decme file virus creates ransom notes, titled !INFO.HTA, in all folders with encrypted files so that the victims of the cyber attack would find them effortlessly, wherever they look.
| name | Decme ransomware, .decme cryptovirus |
|---|---|
| type | Ransomware |
| family | Void/VoidCrypt ransomware |
| Appended file extension | Decme ransomware appends a three-part extension to all non-system files: 1. [unique victim ID] 2. [email address of the distributors of this malware] 3. .decme extension |
| Ransom note | !INFO.HTA is generated in all folders that contain encrypted data |
| Criminal contact details | Two emails are given to make contact: Files2021@tutanota.com and Files2020@mailfence.com |
| Malware removal | Decme virus, and any other ransomware, should be removed with the help of a professional anti-malware app |
| System health | Malware typically corrupts system files, so after Decme ransomware removal, we recommend using the FortectIntego tool to undo all changes and harm done to the device's core files and settings |
The ransom note (posted below this article) of Decme ransomware isn't very informative, unlike other cryptoviruses, e.g., Lisp. In the beginning, the virus developers explain that all files were encrypted with a strong cryptography algorithm and that the only way to regain access to them is by paying the hackers.
The ransom amount isn't specified, although the cybercriminals urge to contact and pay the ransom within 48 hours of the infection or the demanded ransom will be doubled. The creators of Decme ransomware, like most of the hackers, would like to be paid in cryptocurrency Bitcoins.
To prove that they really possess the required tools for .decme file decryption, the cybercriminals are offering the victim to send them some small files (not containing any valuable data) for free test decryption. They also provide two emails to establish contact – Files2021@tutanota.com and Files2020@mailfence.com, and an appointed unique user ID.
We always advise against contacting the cybercriminals and agreeing to meet their demands. Victims should remove Decme ransomware from their infected devices and look for other means of data recovery. The longer any malware stays in a computer, the more damage it could do.

Decme ransomware removal should be entrusted to professional anti-malware software that could automatically locate, isolate, and delete it. Trustworthy apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes should do the trick. Furthermore, if you keep any of these apps' virus databases up-to-date, they could prevent cyberattacks in the future.
When the cryptovirus is removed from an infected device, the next step is to take care of the overall health of your computer system. Experts[2] recommend using the FortectIntego app to find and fix any issues that the Decme ransomware might have done to your system.
Instructions written by the creators of Decme file virus given to the victims with the !INFO.HTA files:
!!! Your Files Has Been Encrypted !!!
♦ your files has been locked with highest secure cryptography algorithm ♦
♦ there is no way to decrypt your files without paying and buying Decryption tool♦
♦ but after 48 hour decryption price will be double♦
♦ you can send some little files for decryption test♦
♦ test file should not contain valuable data♦
♦ after payment you will get decryption tool ( payment Should be with Bitcoin)♦
♦ so if you want your files dont be shy feel free to contact us and do an agreement on price♦
♦ !!! or Delete you files if you dont need them !!!
♦Your ID :-
our Email :Files2021@tutanota.com
In Case Of No Answer :Files2020@mailfence.com
The most typical methods of the cybercriminals used to infect computers
Different types of malware[3] are spread in different ways. for example, adware is spread mostly with freeware installation bundles, while ransomware is distributed mainly by spam emails and through file-sharing platforms. Cybercriminals are creating more viruses each day, so read our articles, and you might evade it.

Spam emails containing either mischievous hyperlinks or infected attachments are sent out each day in tens of thousands. If any of these villainous options are clicked or downloaded, the infection and encryption start almost instantly. Be aware of these emails, and please never open any shady-looking emails or their components.
Torrent websites, like BitTorrent, The Pirate Bay, and others, are full of different malware. It's an ideal environment to spread cryptoviruses because no one is scanning the files and assuring end-users security. Please refrain from using any torrent sites.
Guide for Decme ransomware removal and a quick system tweaking
As we mentioned before, the only right thing to do with Decme ransomware removal is to delete it immediately after detection or the first sight of ransom notes. As long as this malware stays in your computer – more harm could be coming your way.
To remove Decme ransomware, we suggest using professional anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These time-proven apps are trustworthy and will safeguard your passageways on the internet.
When the device is virus-free, users shouldn't rush to restore their data from backups. First of all, a system tune-up is in order. Use the FortectIntego app to locate and restore any modifications Decme ransomware virus might have done to your system files and its settings.
Was this guide helpful?
Be the first to comment