Cwkkbzomdxj ransomware – a file-locking virus that urges its victims to establish contact within 48 hours

Cwkkbzomdxj ransomware is a cryptovirus from the Snatch ransomware family. This computer virus encrypts files (non-system) on targeted devices, appoints a .cwkkbzomdxj extension to all of them, and creates ransom notes (HOW TO RESTORE YOUR FILES.TXT) demanding money for a promised decryption tool.
Ransomware from this lineage, such as Zybvqxefmh, Nsemad, Gcahvv, and others, use a military-grade AES[1] coding algorithm to encrypt all personal data (documents, pictures, archives, databases, etc.), making it inaccessible until a specific decryption key is used to unlock them.
Ransom notes are created to convey instructions from the cybercriminals to their victims on what to do to get their data back. Cwkkbzomdxj ransomware virus creators would like to be contacted via the two given emails (55billy777@mail.fr, 8472host@cock.li), where they would disclose further ransom details.
| name | Cwkkbzomdxj ransomware, .cwkkbzomdxj file virus |
|---|---|
| Type | Ransomware |
| Family | Snatch ransomware |
| Ransom note | HOW TO RESTORE YOUR FILES.TXT |
| appended file extension | .cwkkbzomdx |
| Criminal contact details | 55billy777@mail.fr, 8472host@cock.li |
| Virus removal | Entrust ransomware elimination to trustworthy anti-malware software |
| System health check | Run system clean-up and tune-up with powerful system repair tools like the FortectIntego app |
The ransom note of Cwkkbzomdxj ransomware isn't particularly informative. The assailants state that they encrypted all personal data and that only they can restore it. They provide contact details, and to prove that they possess the necessary tools, they offer free decryption of any three files (not exceeding 1Mb).
Also, the cybercriminals warn their victims not to rename or edit the encrypted files and urge to contact them within 48 hours of the attack, or the data might be permanently lost. The whole ransom note message from HOW TO RESTORE YOUR FILES.TXT reads:
Hello! All your files are encrypted and only I can decrypt them.
Contact me:55billy777@mail.fr or 8472host@cock.li
Write me if you want to return your files – I can do it very quickly!
The header of letter must contain extension of encrypted files.
I'm always reply within 24 hours. If not – check spam folder, resend your letter or try send letter from another email service.Attention!
Do not rename or edit encrypted files: you may have permanent data loss.To prove that I can recover your files, I am ready to decrypt any three files (less than 1Mb) for free (except databases, Excel and backups)
HURRY UP!
! ! ! If you do not email me in the next 48 hours then your data may be lost permanently ! ! !
Although paying the demanded ransom can seem like the easiest way out of this nightmare, it's actually the worse thing a cyberattack victim can do. There's absolutely no guarantee that the promised decryption tool will ever be delivered, but the ransom money could be used to attack more innocent everyday computer users.

The only right move is to remove Cwkkbzomdxj ransomware from all affected devices right away. Manual deletion is possible but might be too difficult for regular computer users, so we recommend untrusting this dirty work to trustworthy anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
Based on research from VirusTotal,[2] only 41 out of 71 anti-malware (AV) engines have detected the culprit of this article, once again showing the necessity of reliable AV software. Here are a few examples of .cwkkbzomdxj file virus detection names:
- Ransom.Snatch
- HEUR:Trojan-Ransom.Win32.Gen.vho
- Ransom:Win64/Snatch.A!MTB
- Heuristic.HEUR/AGEN.1137781
- Gen:Variant.Ransom.GoRansom.2
Due to the fact that most cryptoviruses mess up system settings, such as the system registry, experts[3] suggest using the FortectIntego app or any other powerful system repair tool, after Cwkkbzomdxj ransomware removal, to scan the entire computer system and restore any changes back to normal.

Evading infection through spam emails – one of the most common ransomware spreading techniques
Cybercriminals have many weapons at their disposal when it comes to ransomware distribution, but one of the most common ways used to infect victim computers is spam emails. These emails might contain one of two (or both) virus spreading techniques:
- mischievous hyperlinks that lead to malicious sites riddled with malware;
- infected attachments that contain virus payload files, camouflaged as important documents, invoices, etc.
There's a spam folder for a reason. All emails there must be deleted regularly. Some of them might bypass email providers' security screening and end up in your inbox. Be aware of emails urging you to open any link or download an attachment right away. All email attachments must be scanned with anti-malware apps before downloading them.
Directions for Cwkkbzomdxj ransomware removal and system repair
If your device got infected with Cwkkbzomdxj ransomware virus, you don't have to panic and give in to the cybercriminals' demands. There might be other data recovery options. As we've mentioned before, paying the ransom is the worse option for a cyberattack victim.
Since there's no decryption software available at the moment before you remove Cwkkbzomdxj ransomware, you should copy all encrypted files to offline storage, such as a USB drive or similar. Only then use dependable anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to eliminate the infection. This will not recover encoded files, but infection gets treated.
Keeping in mind that file-locking viruses alter various system settings to help them thrive in the infected device, after Cwkkbzomdxj virus removal, you should consider using powerful system repair tools such as the FortectIntego app to undo these modifications.
Was this guide helpful?
Be the first to comment