Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jul 2018

How to remove 24H ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

24H – a crypto-virus which locks up files and demands 0.24 BTC for their release

24H virus24H ransomware is a severe computer infection which can be recognized by the .24H extension added to every infected file. To achieve that, the malware uses a complicated encryption algorithm – AES. Once the files are locked, the virus inserts a ransom note in a text format ReadME-24H.txt which contains details on how the infected computer owner should proceed. Hackers also detail the Bitcoin wallet address, which should be used to transfer digital currency. Once the payment is complete, users are urged to contact bad actors via 24H@tutanota.com or 24HDecryptor@Mail.ru.

Name 24H
Type Ransomware[1]
Encryption algorithm AES
Danger level Very high. Does serious damage to the computer system and personal files. Disables all security tools which makes the elimination even harder.
Extension .24H
Ransom note ReadME-24H.txt
contact email 24H@tutanota.com or 24HDecryptor@Mail.ru
Data reclaim condition Hackers demand payment into 1FniWsB6T3n7GjBGs3UizspTshBvt9qFqR wallet in Bitcoin cryptocurrency. The size of ransom is unknown
Deletion Use FortectIntego to eliminate the virus infection from your PC system

The 24H virus infiltrates the system using stealthy tactics – users are prompted to open a malicious attachment in the spam email or can be infected once they download an executable from a dodgy website. The malware does not instantly encrypts files, but rather performs a series of changes on the targeted machine first: 

  1. 24H ransomware modifies Windows Registry to obtain boot persistence
  2. It may prevent security software from detecting the virus
  3. A scan is performed for personal files, like .pdf, .jpg, .doc, and others (malware ignores the system and some other files)
  4. As soon as files are detected, an AES algorithm encrypts data and adds .H24 extension
  5. The encryption key is generated and sent to command & control server operated by hackers
  6. The C&C server then sends the ransom note back to the victim, stating its demands

Cryptovirus is a complex cyber threat and uses sophisticated infection techniques. Nevertheless, if you got infected, remove 24H ransomware from your device immediately. In order to do that, you should download and install an anti-malware tool. We recommend using FortectIntego or MalwarebytesMalwarebytes

Another reason to perform the 24H removal is that the cyber threat may render your machine vulnerable to other malware. This is because it performs a series of changes to the device, and usual security systems stop working. Thus, browsing the internet with the infected machine is not recommended, as users may have their personal information stolen by hackers.

Although the size of the ransom is unclear (it can range anything between $50 to $5000), we do not recommend contacting cybercrooks. No matter how desperate you are to get your files back, do not pay the ransom! There is no guarantee that hackers will send you the decryptor. Additionally, 24H authors may attack you in the future, knowing that you are willing to pay. 

Instead, we advise victims to use alternative methods for file decryption. A backup can be used (cloud services or an external device) to recover all data safely, or there is a possibility to decode files using the third-party software we present below. Additionally, security experts sometimes create an official decryption tool, although this might take awhile.

24H ransomwareAvoid ransomware infection an keep your PC safe

According to research done by tech experts[2], ransomware spreads through spam emails. Phishing emails usually are presented as legitimate messages, but in reality, contain malicious attachments or hyperlinks that lead to malware installation. Inbox is traditionally filled with spam messages, and some of them might be harmless. Nevertheless, we advise users to refrain from clicking on anything inside emails that come from suspicious sources.

Furthermore, if you like surfing the internet and downloading/installing software – you need to pay attention while proceeding with such actions. Malware can be hidden in websites that look genuine, as hackers can intercept these domains and inject malicious JavaScript that downloads and installs the virus automatically. Thus, it is vital to stay away from malicious websites, such as file-sharing, cracked software, keygens[3] and others.

We strongly recommend to download and install an antivirus, if you do not have one yet. It will eliminate the injected viruses and detect the incoming infections.

24H virus elimination steps

To remove 24H virus, you will need to download and install anti-malware software. We advise using FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. Trustworthy and professional help is needed as your computer system is seriously infected. It is essential to get rid of the cyberthreat as soon as you detect encrypted files to avoid further damage that can be done.

As the malware can block your security software in some cases, we recommend rebooting your machine and entering Safe Mode with Networking. This way, the 24H removal will be possible, as in this mode the system starts using only the most necessary system processes and drivers, limiting malware's capabilities. 

For file recovery, see instructions below.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.