Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2020

How to remove AnoymouS ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

.AnonymouS virus – HiddenTear-based ransomware built for money extortion

AnoymouS ransomware

On October 23, 2020, new malware has arisen – AnonymouS ransomware. Like most ransomware, this one also infects victims' computer systems, encrypts all personal files, and demands a ransom to unlock their data. After encryption is done, all non-system files receive a file extension .AnonymouS, hence the name of the virus. The malware lands on the users' system via an executive file (.exe) – GTA V Setup.exe, although other samples might be using different names. It is also became apparent that the virus stems from one of the most prominent open-source ransomware known as Hidden Tear.

NAME  AnonymouS
FILE NAME GTA V Setup.exe
CLASIFICATION Malware, Ransomware, Cryptoware
ENCRYPTION USED RSA-2048, AES-128
RANSOM NOTE  Message_Important.txt appears in affected folders. The text file contains ransom details in two languages – French and English. 
DISTRIBUTION  Spam emails and their content, torrent websites
INFECTION AFTERMATH Victims' files are encrypted and receive a new file extension – .AnonymouS, rendering the files inaccessible
REMOVAL STEPS To remove malware infection from your computer, you should scan your machine with anti-malware. If needed, access Safe Mode with Networking – we explain how below
SYSTEM FIX Ransomware can pose a significant danger not only to personal but also system files. If your computer is crashing and experiencing other stability issues, you can attempt to fix them with FortectIntego or other repair software

Users find text files (“Message_Important.txt”) in contaminated folders with a ransom demanding message inside (see the whole message below this paragraph). It's presented in two languages – French and English. Perpetrators define that users' data was encrypted using two cryptographic algorithms – RSA-2048 and AES-128.[1] Unlike in most ransom notes, the cybercriminals behind the .AnonymouS virus aren't warning the victims not to try and alter the files by renaming them or trying to decrypt with third party tools.

The developers just tell that the decryption is only possible with their “private key and decryption program.” Then they're presenting the instructions on how to pay the ransom. As always, the cybercriminals cannot be trusted, so we strongly advise you not to meet their demands, because usually, the victims not only lose their data but their money too.

Ransom note in the Message_Important.txt reads as follows:

EMAIL:your-email

1) French Version :

Vos fichiers sont cryptés avec chiffrement RSA-2048 et AES-128.

Décrypter vos fichiers est uniquement possible à l'aide d'une clé privée et un programme de décryptage

Qui se trouvent sur notre serveur secret, il s'agit d'un ransomware et non pas de virus.

Pour décrypter vos fichiers, veuillez suivre les instructions suivantes :

instruction à faire pour nous aider à décrypter vos fichiers :

1)Achetez des bitcoins de prix $ ,USD

2)Vous pouvez acheter rapidement les bitcoins icihxxps://localbitcoins.com

3)Envoyez les bitcoins à cette adresse : your wallet bitcoins

4)Dès qu'on reçoit les bitcoins ,on décrypte vos fichiers:your-email

2) English version :

Your files are encrypted with RSA-2048 and AES-128 encryption.

Decrypting your files is only possible using a private key and a decryption program,

Which are on our secret server, it is a ransomware and not viruses.

To decrypt your files, please follow these instructions :

instruction to help us decrypt your files :

1) Buy bitcoins from prix $ ,USD

2) You can buy bitcoins quickly here : hxxps://localbitcoins.com

3) Send bitcoins to this address: your wallet bitcoins

4) As soon as we receive the bitcoins, we decrypt your files :your-email

According to VirusTotal.com, 48 out of 71 antivirus (AV) programs found the ransomware. This once again emphasizes the usefulness of a reliable antivirus. Bellow are few examples of how some popular AVs detect the malware:

  • Kaspersky – HEUR:Trojan.Win32.Generic
  • McAfee – RDN/Ransom
  • Malwarebytes – Ransom.HiddenTear
  • Panda – Trj/GdSda.A
  • Symantec – Ransom.HiddenTear!g1

AnoymouS ransomware encrypted files

We strongly advise you to use SpyHunterCombo Cleaner for detection and FortectIntego for system restoration after the .AnonymouS ransomware removal is completed. Otherwise, your PC might suffer from various crashes, errors, BSODs,[2] and other issues post-termination.

Keep in mind that you should copy all the encrypted files before you remove AnonymouS ransomware if you have no backups to restore data from. Otherwise, you might permanently damage files, and they might become corrupted due to malware elimination of the usage of third-party tools.

Ransomware distribution methods

Malware spreads in many different ways – file-sharing platforms, spam emails,[3] to name just a few. Instead of downloading what the user thought he was getting, he might obtain some mischievous software from the file-sharing platforms without knowing about it. People should always download software only from reliable sources, e.g., from the developers.

While conducting a spam campaign, cybercriminals send out thousands of infected emails to computer users all over the world. The emails might look like an official letter from your company, your bank, etc., but beware of the attachments and unnatural looking links. The attachments might contain malware that would attack your data by encrypting or stealing it. And one might never know what you could find at the other end of the phony link, but in most cases – some sort of virus.

Recommended AnonymouS ransomware removal tools

To prevent the criminals from success in their line of work, firstly it is recommended to use powerful antivirus software (such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes) and keep it updated at all times. To add more security to your data – keep backups of it in separate locations, such as the cloud, servers, removable drives.

AnoymouS ransomware virus

If you're one of the thousands of unlucky computer users that caught the AnonymouS ransomware infection – all is not lost. Your data might be, but your whole system still has hope. We strongly advise never against agreeing with the demands of the cybercriminals.

For AnonymouS malware removal, we recommend using a powerful and trustworthy anti-malware software. Usually, malware messes up the computers' registry, which might lead to your systems' irregular work, crashes, etc. To restore your system to its normal state, we advise you to use FortectIntego.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.