Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2019

How to remove Browec ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

Browec is ransomware and one of Djvu virus variants asking for $980 in return for the decryption key

Browec ransomware

Browec ransomware is data locking malware that was first spotted by security researcher Michael Gillespie in mid-April 2019. The virus stems from the notorious STOP/Djvu virus family – one of the most widespread ransomware threats in the wild. Just as its predecessors, it uses AES-256[1] cipher to lock up data, appends .browec extension and drops a ransom note _readme.txt that demands a payment of $980 in Bitcoin for the alleged decryptor. After paying, victims are asked to contact hackers via vengisto@india.com or vengisto@firemail.cc emails to allegedly receive the decryptor that would allow them to reaccess their files. However, experts[2] highly discourage users from having any type of interaction with hackers and instead focus on Browec ransomware removal, as well as alternative file recovery methods.

Name Browec
Type Ransomware
Derivation STOP/Djvu
File extension .browec
Ransom note _readme.txt
Contact vengisto@india.com or vengisto@firemail.cc
Decryptable? No, but might be possible with STOP decryptor [direct link] if encryption was performed while offline
Termination Use reputable security software
Recovery Ransomware can infect system files; to restore them and avoid reinstallation of Windows, use FortectIntego as a quick recovery solution

Browec ransomware is mostly delivered to victims' computers using the following methods:

  • Spam emails;
  • Exploit kits;[3]
  • Brute-force attacks;
  • Pirated software installers and their cracks;
  • Fake updates;
  • Hacked websites, etc.

Once inside, the malicious Browec ransomware payload infects operating system – it then runs every time Windows machine is booted. It also deletes Shadow Volume copies, complicating the recovery procedures. After that, it only takes malware a few seconds to encrypt pictures, databases, videos, music, and other documents. 

Browec ransomware, just as STOP previous variants (GuvaraRaldugRefols, etc.) uses virtually identical ransom note, which reads:

ATTENTION!

Don’t worry my friend, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-vpovVceDWN
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” folder if you don’t get answer more than 6 hours.

To get this software you need write on our e-mail:
vengisto@india.com

Reserve e-mail address to contact us:
vengisto@firemail.cc

Your personal ID:

If your data is encrypted with .browec file virus, do not hurry to pay criminals, even if they offer such services as free test decryption or 50% discount. This is not an online shop where you buy stuff, and these people illegally restrained the access to your files – they can simply take your money and never send you what they promised. Additionally, by paying them, you would online prove that Browec ransomware works as intended and prompt them infecting even more victims.

Browec ransomware virus

While Browec virus is not yet decryptable, users can try alternative recovery solutions as explained below. Besides, if file encryption was performed while the computer was not connected to the internet, STOP decoder might be useful. 

Remember that you need to remove Browec ransomware before you attempt file recovery, or otherwise your files will be repeatedly encrypted. Additionally, we recommend using FortectIntego to recover from the infection completely and make sure that Windows is running properly once again.

Be attentive while opening emails and downloading software from the internet

Ransomware is most likely one of the most devastating types of malware around, as it might result in permanent data loss. Additionally, virus authors are quick to evolve their threats to ensure higher infection rates, along with possible payments from victims. Therefore, a variety of distribution methods are used to expand bad actors in malicious campaigns.

One of the most ransomware distribution techniques is spam emails. Hackers employ bots that send out phishing emails to thousands of users, and they typically contain an attachment that uses a variety of extensions, such as .exe, .html, .doc, .pdf, .txt, and similar. These files are obfuscated in a way that, once opened, would download and install ransomware payload on your device. Alternatively, bad actors might also use hyperlinks that would redirect victims to malicious domain.

Another popular malware distribution method is via fake updates and pirated software installers. Therefore, set your updates to automatic setting and scan every single executable with tools like Virus Total and make sure you have anti-malware software enabled at all times. Finally, ensure you have backups ready for a speedy recovery if you get infected with ransomware.

Terminate Browec ransomware from your machine with the help of anti-malware tool

Manual Browec ransomware removal should not be tried by most users, as digging in Windows Registry and determining where all the malicious files are is almost impossible. For that reason, you should download and install reputable anti-virus software and remove Browec virus automatically. Before you do that, however, you should enter Safe Mode with Networking, as ransomware might interfere with anti-malware software.

Once you terminate Browec ransomware, you can attempt to recover at least some of your files. You can use third-party recovery software – we provide download links and instructions on how to use those apps below. Also, you can wait for the security experts to create the decryptor for this variant of STOP. Besides, you can try STOP decryptor by Michael Gillespie.

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.