Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2017

How to remove ATLAS ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

ATLAS ransomware is ready to encrypt your files

ATLAS virus operates as ransomware[1] which is devised to encode users’ personal files with the combination of AES+RSA-512 algorithms. This peculiarity makes the malware a full-fledged virus despite its plain design. In the ransom message, it provides three email addresses: atlashelp@protonmail.com, atlasfix@protonmail.com, and atlasfix@dr.com. It marks the encrypted files with .ATLAS file decryption. In the ATLAS_FILES.txt, the malware authors alarm victims to use any third-party decryption software but instead follow their requirements. The malware was constructed on the basis of Dale and Chip ransomware infections[2]. It is common tendency to exert pressure on victims. Instead of giving into their manipulations, we offer you to start ATLAS removal. OYou can speed up the process with FortectIntego or MalwarebytesMalwarebytes.

The screenshot illustrating ATLAS ransomware

Currently, there has been a string of crypto-malware threats which present the demands in the plain .txt file. The majority of them were based on the open source HiddenTear virus. Nonetheless, this time, the developers of Dale and Chip viruses fall to be the prime suspects for creating this virus. Similarly to the design of the former threat, ATLAS malware three alternative email addresses for the public. It also repeats the identification code of a victim several times. Taking a look back at the former attempts to extort money, the cyber crooks seem to have knowledge how to use Tor and dark web for disguising their identity[3]. The files are encrypted with an elaborate encryption method which suggests that the felons are not newbies. What is more, they do not indicate a specific amount of ransom[4]. The victims are supposed to contact the racketeers and follow further instructions. Let us warn you not to install their suggested software, but in fact, remove ATLAS right away.

The transmission techniques of the malware

Despite slight alterations in the modus operandi, ATLAS ransomware spreads the same way as other file-encrypting threats. You may notice it as an email attachment added to the email named as an important invoice or subpoena to the court. Note that ATLAS hijack may also occur if you tend to visit peer-to-peer file sharing domains, gambling, and gaming web pages. Fewer samples reveal the tendency that some fraudsters shift their attention to browser plug-ins. If you come across a website which suggests you enable a browser extension, do not rush to do it. Instead of temporal access to feature or service, you may accelerate the infiltration of a file-encrypting threat.

Terminating ATLAS efficiently

Taking into account the fact that this malware is a derivative version of previously mentioned viruses, you should not underestimate it. Thus do not waste time and entrust ATLAS removal to an anti-spyware tool. Do not get surprised if this malware modifies the system settings and you will not be able to run the application. In that case, the below-displayed guide will be of practical use. After you regain full access, remove ATLAS virus. Regardless of crooks’ alert not to use third-party decryption software, disregard such “recommendation.” You will find useful tips under “Bonus: Recover your data” headline. Note that your vigilance pays a significant role in the cyber security[5].

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.