Severity scale:  
  (99/100)

Remove Blower ransomware (Virus Removal Guide) - updated Feb 2019

removal by Olivia Morelli - - | Type: Ransomware

Blower ransomware is crypto malware that infects users with the help of cracks and keygens

Blower ransomware

Blower ransomware is data locking malware and one of the Djvu virus variants which on itself stems from STOP ransomware – one of the most prominent threats currently. Researchers believe that the infection originated in Ukraine, although there are also some accomplices from other countries. The malicious payload is usually injected with the help of illegal cracks and keygens,[1] usually downloaded from torrent sites. Blower virus uses AES cipher to lock data and appends .blower extension – the encryption process usually takes only a few seconds, so victims cannot do much to stop it. Databases, documents, pictures, and other data becomes inaccessible, and users are shown a _readme.txt note that explains what happened, and they are asked for a ransom of $490 in bitcoin for the file release. Bad actors also clarify that the amount doubles if the sum is not transferred within 72 hours of the infection. However, this variant might be decryptable, so there is no need to contacting hackers. Users reported that they managed getting infected with two ransomware viruses – Blower and GEFEST (a variant of Scarab) at the same time.[2]

Name Blower ransomware
Type  Cryptovirus
Associated  Djvu ransomware
Belongs to ransomware family  STOP ransomware
File extension  .blower
Ransom amount $490 – $980
Ransom note _readme.txt
Related files 1.exe, 2.exe, 3.exe, updatewin.exe, 8651.tmp. exe, hehjrebu.exe, install.exe, vsruwcaw.exe
Contact emails  blower@india.com; blower@firemail.cc
Decryption Might be possible, contact security researcher for help
Distribution  Infected spam email attachments
Removal  Employ reputable anti-malware like Malwarebytes to remove Blower ransomware 

Cybercriminals who developed Blower ransomware suggest victims send one file for test decryption for free. But this action is done to create a fake sense of trust. We do not recommend trusting these people and contacting them in any way.

Also, note that Blower ransomware demands a huge amount and might not even consider restoring your data. The best solution for file recovery is data backups on external device or cloud services. If you are not sure that you have files you need, you can try data recovery software options that we suggest below the article. 

Blower ransomware starts with an encryption process and uses the AES algorithm to change the original code of your files in various formats from photos, documents, video files to audio and archives or databases.[3] All encrypted data get .blower file marker and become unreadable. 

Blower virus
Blower virus - ransomware which appears in the system after opening a hazardous attachment or visiting an infected website

The ransom note placement follows the encryption process when every folder on the machine gets _readme.txt. Blower ransomware ransom message reads the following:

ATTENTION! Do not worry my friend, you can return all your files! All your files are encrypted with the unique key. Decrypt tool for you. This software will decrypt all your encrypted files. What guarantees you have? You can send your PC and we decrypt it for free. But we can decrypt only 1 file for free. File must not contain valuable information. You can get a video of the decrypt tool: https://we.tl/t-1aaC7npeV9 Price is $ 980. 

Discount 50% available if you contact us first 72 hours, that's price for you is $ 490. 
Please note that you never restore your data without payment. 
Check your e-mail address if you don’t get it more than 6 hours. 
E-mail: 
blower@india.com 
Reserve e-mail address to contact us: 
blower firemail.cc @ 
Your personal ID: 
030GHsgdfT7878YsY9gsafL *** 

You need to proceed with Blower ransomware removal and follow expert[4] suggested routine: terminate the virus using professional anti-malware tools and then clean the device using PC repair program like Reimage Reimage Cleaner , recover your data using file backups or recovery software. 

When you remove Blower ransomware using the automatic method you have the advantage of cleaning the system thoroughly. However, you need to double-check before any data recovery because ransomware can damage your device and encrypt files again if not terminated completely.

Avoid opening and downloading files attached to suspicious emails

Make sure to pay more attention to emails you receive without expectation and do not rush to open files attached to the email itself. You can risk getting cyber infections or malware that delivers direct ransomware on your device from the infected email attachment.

Email often contains executables, Word or Excel documents, PDFs and ZIP files as attachments and when you open the file on your computer, you get the option to enable content that includes malicious macros. When you allow those macros to run payload dropper gets activated, and your system is easily infected.

You can avoid this infiltration if you delete suspicious emails without opening and downloading the attachment. Pay attention to emails you receive and try scanning the file before downloading if you have any doubts. 

Blower ransomware infection
Many AV engines recognize the payload as malicious. Make sure to install security software in order to prevent dangerous Blower ransomware infection

Terminate the dangerous Blower ransomware virus automatically

The Blower ransomware removal process might be too hard to perform by using a manual technique. For this case, we suggest you download and install reliable computer software. We also offer using a tool such as Reimage Reimage Cleaner , SpyHunter 5Combo Cleaner, or Malwarebytes for finding malicious components in the computer system. Note that all hazardous content needs to be eliminated at once.

Remove Blower ransomware before you proceed with data recovery purposes. Make sure that you reboot your machine to Safe Mode or activate the System Restore feature as this way you will be able to deactivate the malicious activity. Later on, try some data recovery methods that we have displayed below this text. Perform each step as required to reach the best results.

Offer
do it now!
Download
Reimage Happiness
Guarantee
Download
Reimage Cleaner Happiness
Guarantee
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage Reimage Cleaner, submit a question to our support team and provide as much details as possible.
Reimage Reimage Cleaner has a free limited scanner. Reimage Reimage Cleaner offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage Cleaner, try running Combo Cleaner.

To remove Blower virus, follow these steps:

Remove Blower using Safe Mode with Networking

Use Safe Mode with Networking to disable virus-related activities. Follow these steps to accomplish such goal:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove Blower

    Log in to your infected account and start the browser. Download Reimage Reimage Cleaner or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete Blower removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove Blower using System Restore

Activating the System Restore feature might help you to stop the spreading of the ransomware infection. Follow these steps to complete the process:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Blower. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage Reimage Cleaner and make sure that Blower removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Blower from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If you have spotted encrypted files on your computer, do not rush to make decisions. We suggest overthinking everything twice and evaluating every risk. Better try out our below-given data recovery methods and restore some of your files.

If your files are encrypted by Blower, you can use several methods to restore them:

The Data Recovery Pro tool might help you with your files:

Complete all these steps if you want to recover some of your files successfully.

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by Blower ransomware;
  • Restore them.

Using ShadowExplorer might allow you to restore some data of yours:

Try using this tool as it might help you with data recovery purposes.

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

No official decryptor has been released.

While no official tool has been released, you can contact security researcher Michael Gillespie – he might be able to help. Additionally, you can also try using STOPDecrypter created by the same security expert.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Blower and other ransomwares, use a reputable anti-spyware, such as Reimage Reimage Cleaner , SpyHunter 5Combo Cleaner or Malwarebytes

About the author

Olivia Morelli
Olivia Morelli - Ransomware analyst

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Olivia Morelli
About the company Esolutions

References


Your opinion regarding Blower ransomware