Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2019

How to remove Combo ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Combo ransomware is a dangerous cryptovirus hailing from a notorious Dharma family

Combo ransomware virus 

Combo ransomware is a dangerous virus that comes from a well-known ransomware[1] family called Dharma. Since its development in November 2016, this ransomware has been reappearing with more than ten different versions. The latest virus version has been dubbed .Combo ransomware as it is using .combo file extension to lock encrypted data. The full extension appended to encrypted files reads either [Broodmother@cock.li].combo or .[combo@tutanota.de].combo. After data modification, ransomware saves the ransom note on victim's desktop and in every folder with the encrypted files. Typically, it is used to provide more information about the attack and instructions on how to recover encrypted files. However, any contact between criminals and victims is not recommended due to further dangers.  

Name Combo ransomware
Type Cryptovirus
Family Dharma
Extension .combo
Symptoms Files encrypted with the specific extension and cannot be accessed, the ransom note can be found in all folders with encrypted data.
Distribution Spam email attachments, dubious links
Elimination Use FortectIntego for Combo ransomware removal

Ransomware-type viruses are one of the most dangerous viruses of these days because of their ability to make the victim's data unusable. Additionally, we should take into account the fact that the developers of .Combo ransomware can access the operating system and initiate various changes on it. So, if your device got infected with this ransomware, the loss of some part of your data is not the biggest issue. You need to get rid of ransomware as soon as possible because of the fact that criminals can access your PC remotely and disable useful executables or initiate other unwanted tasks.

Since this alleged decryption tool might not even exist, do not contact the developers via given combo@tutanota.de and broodmother@cock.li email addresses. It might lead you to the money loss without receiving any tool for the decryption of your files. Dealing with ransomware developers has always been a dangerous activity, so focus on Combo ransomware removal and only then consider initiating data recovery. According to security researchers,[2] you can use FortectIntego to fix the system.

Previously-released versions of Dharma ransomware are known to have decryptors released. However, having in mind that each version is using a different encryption algorithm, same decryptors won't be helpful. Unfortunately, there is no tool developed for this ransomware version yet. The safest way is to restore your files is to remove Combo ransomware and then them recover files from a backup. 

Combo ransomware

One click on infected file can get you this virus

Spam email tab on your email box fills up quickly for a reason. Commercial content or repeatedly sent newsletters and other useless information end up there. Unfortunately, these letters can have malicious payloads and infected files. The minute you open one of them and click on the attached file your system gets a virus. 

You can tell that letter is not safe if an email text itself is suspicious, filled with ads or content does not relate to the file attached. You should never open these and clean your email box more frequently. But if you find Word or other safe-looking file attached to commercial letter stay away. These files can be filled with macro-viruses[3]. These are used to spread malware like ransomware around.

Terminate Combo ransomware now, before it's too late

To remove Combo ransomware, you should use professional tools designed for the malware detection. Anti-virus programs existing on your PC might be disabled by the virus so use anti-malware tools like FortectIntego or MalwarebytesMalwarebytes. These could help you scan the device fully and find all possible threats. Ransomware can install additional tools or programs, so this stem is very crucial if you want to clean your system properly.

Combo ransomware removal is essential for the system because you cannot use the device or recover your files without properly getting rid of an infection. Decryption is not always working since ransomware tends to encrypt files a few times, so the best way to recover your files is using an external backup. Remember that you cannot plug it in if the device is not clean. This will destroy your files permanently. Keep your anti-spyware and anti-virus tools up to date so you can avoid this infection in the future.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.