Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2019

How to remove 888 ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

888 ransomware is one of many Dharma ransomware variants discovered in the same few weeks 

888 ransomware virus888 ransomware is a cryptovirus that appends files after encryption using a .888 file marker.

is one of many researchers that constantly deliver new information about malware. Starting at the end of January Dharma ransomware released new variants one after the other and Kroustek reported about them all. More recent ones including 888 ransomware virus were ETH ransomware, Qwex ransomware, and Frend virus. All of them base their encryption on the AES algorithm and delivers ransom note in a matching pop-up window and also releases FILES ENCRYPTED.txt file with contact information. The particular name 888 comes from the full pattern of file extension – .[donald888@mail.fr].888. This appendix appears on every encoded file after the encryption and marks useless files. The ransom may differ from $500 to $1500 in Bitcoins, and we do not recommend paying this huge amount for questionable decryption tool.

Name 888 ransomware
Type Cryptovirus
Family Dharma ransomware
File extension .[donald888@mail.fr].888
Ransom amount $500-$1500 in Bitcoin
Contact email donald888@mail.fr
Encryption method AES or DES 
Distribution method Infected email attachments
Elimination To remove 888 ransomware, use FortectIntego and scan the system

Since 888 ransomware virus is only one of handful versions discovered in a few weeks between the end of January and the start of February and it is not the first variant of Dharma we can easily state a few facts that unify all of these versions:

  • AES or DES encryption algorithms;
  • FILES ENCRYPTED.txt – ransom message including contact information;
  • program window with payment instructions;
  • minor changes from version to version.

888 ransomware and other versions got released almost at the same time, and it means that versions are not very different from each other and were only slightly altered. However, this is the family of crypto malware that was discovered back in 2016 and virus developers know what they are doing.[1] 

Based on the ransomware family and the general facts about a cryptovirus category, you should focus on 888 ransomware removal and DO NOT think about paying or contacting cybercriminals. This solution cannot get you positive results because various statistics show that less than half of paying victims get their files back.[2] 

888 ransomware as previous Dharma members delivers a window with step-by-step payment instructions and warnings like:

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

This is a common feature as well as the FILES ENCRYPTED.txt file that gets added to every folder on the computer and reveals a brief message containing the following text:

all your data has been locked us
You want to return?
write email donald888@mail.fr

Remember to remove 888 ransomware first, before any decryption attempts or plugging the external device with backups. Experts[3] advise using anti-malware programs for the process so that virus damage can be eliminated during the same system scan. We can suggest using FortectIntego but feel free to select another tool. 

.888 file virus

Payload dropper initiates the launch of malicious script 

Files containing this malicious script that triggers malware distribution gets spread on the internet, and this way targets people all over the world. Unfortunately, if the email appears on your system and you download the document attached, you risk getting ransomware or any other malware infection. 

Once the infected file lands on your device and gets executed, the computer becomes infected with direct ransomware or trojans that spread around different threats. The malicious script needs to be executed, and you can trigger this by allowing the embedded content on a PDF or Word document, clicking the link provided in the email or its attachments.

Eliminate 888 ransomware and do it as soon as possible

As we mentioned, 888 ransomware virus is not a simple intruder that can easily be deleted manually or even found on the system. You need to scan the device entirely to find the payload files, associated programs or different data that affect the persistence of this virus.

You can easily remove 888 ransomware and its contents while scanning the machine with proper malware termination tools like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Anti-malware programs improve the performance of your PC after this full scan because all useless files and applications can be deleted at the same time.

It is understandable that data recovery is your main concern but you need to focus on 888 ransomware removal, and only then any file restoring can be attempted. The best solution could be file backups on an external device or data recovery software. 

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.