Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2020

How to remove BBGT ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

BBGT ransomware – cryptovirus that carries out targeted attacks for maximum profits

BBGT ransomware

BBGT ransomware is a computer virus that steals some valuable data before encrypting it with military-grade AES and RSA algorithms. Afterward, a ransom note containing instruction, titled BBGT_INFO.rtf, is created and placed along the locked files.

Unlike most other ransomware, when encrypting files, the virus doesn't append an extension to the original filenames – it replaces them with a three-part extension, which consists of the email address of the criminals (BobGant82@criptext.com), a random sequence of 17 characters, and .BBGT extension.

The malware belongs to the Matrix ransomware family, which has been terrorizing companies and everyday computer users since late 2016. Its previous versions include BNFD, SNTG, SCR, and others. Since the attackers are running a double extortion scheme, many victims are more inclined to pay the ransom, even if backups are available.

name BBGT ransomware
type Ransomware
Family Matrix ransomware
ransom note BBGT_INFO.rtf
Appointed file extension

Replaces the original file name with [BobGant82@criptext.com], random sequence of 17 characters, and .BBGT extension

Additional info Cybercriminals state that they steal valuable information before encrypting data. If the victims don't start dialog within 48 hours, the criminals will start to publish their files.
Criminal contact details Three emails are provided to start negotiations – BobGant82@criptext.com, BobGant82@yahoo.com and BobGant82@tutanota.com
Virus removal Perform a full system scan and eliminate the infection with reliable anti-malware software 
System health Cryptoviruses modify system settings and files. To undo that, use a powerful system repair tool like the FortectIntego app

BBGT ransomware ransom note message below this paragraph, but we'll summarize it for you. The cybercriminals start by declaring that all files on the victims' devices are encrypted but not corrupted, and that decryption is possible only with their tools. They also state that some of the valuable and confidential information was downloaded to their private servers.

Next, the perpetrators issue a warning that if the victims don't start negotiations by contacting them within 48 hours of the attacks, they will start publishing the stolen confidential data on the internet. If no contact is made within 96 hours, the hackers threaten to attack clients and partners of the victims with ransomware. Moreover, they will try to sell stolen databases to anyone who shows interest.

Then the creators of the BBGT virus explain that the victims aren't random. They are chosen. The assailants state to know that the picked victim can pay the ransom. And then threaten once more by declaring that they will launch DDoS attacks[1] on the victim's website and IT infrastructure.

Afterward, three emails are given to establish contact – BobGant82@criptext.com, BobGant82@yahoo.com, and BobGant82@tutanota.com. Also, a personal ID is appointed. And then a gesture of good faith is shown – free decryption is offered for any three files from the infected machine. Lastly, the developers of the ransomware urge the victims not to waste time and contact them immediately. Any shenanigans will only increase the ransom amount.

All in all, it's a terrifying ransom note, and the victims could feel pressured to meet the demands of the criminals, but we recommend the victims to remove BBGT ransomware instead for a couple of reasons. First, it is illegal,[2] second, if victims pay once, they can pay again so that the cybercriminals might attack you more and more.

The best way to delete any malware, including ransomware, is by using professional anti-malware software. We suggest using time-tested anti-virus apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes for BBGT ransomware removal. Some malware can prevent AV tools from deleting it. In that case, use our guide below on how to do it in Safe Mode with Networking.

BBGT ransomware virus

When the virus is eliminated from your devices, you're still not out of the woods as many cryptoviruses make alterations to system files and settings to help them accomplish their purpose. To revert all these changes that might impede device performance, cause crashes, and so on, we recommend using the FortectIntego app or a similar system tune-up tool.

The ransom note message displayed in the BBGT_INFO.rtf reads:

Our congratulations. You become a victim of ransomware attack.

First оf аll wе hаvе tо infоrm уоu thаt уоur dаtа is nоt соrruptеd аnd саn bе rеstоrеd quiсklу аnd sаfеlу. Dоn't wоrrу аbоut it. оur sоftwаrе wоrks pеrfесtlу.

Аs уоu саn sее аll уоur filеs wеrе еnсrуptеd аnd rеnаmеd. уоur dаtа is еnсrуptеd with а strоng сrуptо аlgоrithm АЕS+RSА. Уоu саn rеаd аbоut thеsе аlgоrithms in Gооglе. Уоur uniquе dесrуptiоn kеу is sесurеlу stоrеd оn оur sеrvеr аnd nо wау tо rеstоrе уоur dаtа withоut оur hеlp.

Аlsо аll intеrеsting vаluаblе аnd соnfidеntiаl dаtа wаs uplоаdеd tо оur sеrvеrs.
If уоu will nоt stаrt diаlоg with us in 48 hоurs wе will stаrt publishing уоur соnfidеntiаl dаtа in thе Dаrknеt. Аftеr 96 hоurs stоlеn pаrtnеrs аnd сliеnts соntасts will bе usеd fоr nеw rаnsоmwаrе аttасks. Аlsо, If pоssiblе, wе will sеll уоur dаtаbаsеs tо intеrеstеd pаrtiеs.

Plеаsе nоtе thаt уоu аrе nоt а rаndоm tаrgеt. Wе knоw thаt уоu аrе аblе tо pау аnd wе will dо оur bеst tо соmplеtе this аttасk with pауing а rаnsоm pауmеnt frоm уоur pаrt. If уоu dоn't gеt in tоuсh, wе will lаunсh а DDоs аttасk оn уоur sitе аnd IT infrаstruсturе.

If уоu rеаllу wаnt tо sоlvе this situаtiоn уоu hаvе tо writе tо оur 3 еmаil аdrеssеs:
BobGant82@criptext.com
BobGant82@yahoo.com
BobGant82@tutanota.com
In subjеct linе please writе уоur ID: –

Уоu саn аttасh up tо 3 smаll еnсrуptеd filеs fоr frее tеst dесrуptiоn. Wе will dесrуpt thеsе filеs fоr frее аnd sеnd thеm tо уоu. This will bе prооf fоr уоu thаt wе саn dесrуpt аll уоur dаtа. Plеаsе nоtе thаt filеs must nоt соntаin vаluаblе infоrmаtiоn.

Important!
* Wе аsking tо sеnd уоur mеssаgе tо аll оf оur 3 еmаil аdrеssеs bесаusе fоr vаriоus rеаsоns, уоur еmаil mау nоt bе dеlivеrеd.
* Оur mеssаgе mау bе rесоgnizеd аs spаm, sо bе surе tо сhесk thе spаm fоldеr.
* If wе dо nоt rеspоnd tо уоu within 24 hоurs, writе tо us frоm аnоthеr еmаil аddrеss. Usе Gmаil, уаhоо, Hоtmаil, оr аnу оthеr wеll-knоwn еmаil sеrviсе.

Important!
Plеаsе dоn't wаstе thе timе, it will rеsult оnlу аdditinаl dаmаgе tо уоur соmpаnу!
Dоn't trу tо fооl us, it will оnlу inсrеаsе thе priсе!
Wе аrе prоfеssiоnаls аnd just dоing оur jоb!
Wе аrе аlwауs оpеnеd fоr diаlоguе аnd rеаdу tо hеlp!

Investing in cybersecurity pays off

Nowadays, ransomware cyberattacks are a common thing. Some are aimed at specific companies, some target random everyday computer users. We're here to help, so we provide a short tutorial that might help people evade these attacks and stay safe while using their devices connected to the internet.

  • Always keep backups. One of the most important things to do is to keep backups of essential data on at least two separate devices, one of which should be offline storage.
  • Purchase, constantly update, and regularly use a trustworthy anti-malware application so it could prevent malicious software from gaining access to your device.
  • If you have a company, invest in cybersecurity by teaching your employees about phishing emails and other hackers' techniques to attack computers.
  • Please install the latest updates available to all software. Whether it's an Operating System or a web browser, all soft must be up-to-date.

BBGT virus detection

Guide to remove BBGT ransomware from infected computers

Ransomware can be aimed at random everyday computer users or specific companies, but either way, it's a nightmare to become a victim of a cyberattack. Although BBGT virus victims are chosen deliberately, it could be modified and distributed to regular people too. So acquire a time-proven anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to prevent such attacks.

Instead of meeting the demands of the criminals, all cyberattack victims should focus on BBGT ransomware removal. Manual elimination is possible but requires time and extensive knowledge, so we suggest using the aforementioned anti-malware apps for this task.

When BBGT ransomware and all its components are cleared out, experts[3] recommend performing a full system scan with the FortectIntego tool (or any similar system repair tool) to restore any changes the cryptovirus could have made to the system registry and other core system settings.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.