Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2020

How to remove Decme ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

Decme ransomware – a cryptovirus that encrypts all files and appends a three-part extension to them

Decme ransomware

Decme ransomware is a file-locking parasite that, after it gains access to a computer it encrypts all files and demands a ransom for a promised decryption tool. This cryptovirus belongs to a small Voidcrypt ransomware family, with members like Shiton, Lalaland, Konx, and others.

During the encryption[1] process, the Decme ransomware virus appends all non-system files, like documents, archives, pics, etc., with a triple extension: email address of the criminals in brackets, appointed victim ID also in brackets, and .decme extension. When the encryption is done, files are rendered inaccessible.

When encoding of all personal user data is completed, the Decme file virus creates ransom notes, titled !INFO.HTA, in all folders with encrypted files so that the victims of the cyber attack would find them effortlessly, wherever they look.

name Decme ransomware, .decme cryptovirus
type Ransomware
family Void/VoidCrypt ransomware
Appended file extension Decme ransomware appends a three-part extension to all non-system files: 1. [unique victim ID] 2. [email address of the distributors of this malware] 3. .decme extension
Ransom note !INFO.HTA is generated in all folders that contain encrypted data
Criminal contact details Two emails are given to make contact: Files2021@tutanota.com and Files2020@mailfence.com
Malware removal Decme virus, and any other ransomware, should be removed with the help of a professional anti-malware app
System health Malware typically corrupts system files, so after Decme ransomware removal, we recommend using the FortectIntego tool to undo all changes and harm done to the device's core files and settings

The ransom note (posted below this article) of Decme ransomware isn't very informative, unlike other cryptoviruses, e.g., Lisp. In the beginning, the virus developers explain that all files were encrypted with a strong cryptography algorithm and that the only way to regain access to them is by paying the hackers.

The ransom amount isn't specified, although the cybercriminals urge to contact and pay the ransom within 48 hours of the infection or the demanded ransom will be doubled. The creators of Decme ransomware, like most of the hackers, would like to be paid in cryptocurrency Bitcoins.

To prove that they really possess the required tools for .decme file decryption, the cybercriminals are offering the victim to send them some small files (not containing any valuable data) for free test decryption. They also provide two emails to establish contact – Files2021@tutanota.com and Files2020@mailfence.com, and an appointed unique user ID.

We always advise against contacting the cybercriminals and agreeing to meet their demands. Victims should remove Decme ransomware from their infected devices and look for other means of data recovery. The longer any malware stays in a computer, the more damage it could do.

Decme ransomware virus

Decme ransomware removal should be entrusted to professional anti-malware software that could automatically locate, isolate, and delete it. Trustworthy apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes should do the trick. Furthermore, if you keep any of these apps' virus databases up-to-date, they could prevent cyberattacks in the future.

When the cryptovirus is removed from an infected device, the next step is to take care of the overall health of your computer system. Experts[2] recommend using the FortectIntego app to find and fix any issues that the Decme ransomware might have done to your system.

Instructions written by the creators of Decme file virus given to the victims with the !INFO.HTA files:

!!! Your Files Has Been Encrypted !!!
♦ your files has been locked with highest secure cryptography algorithm ♦
♦ there is no way to decrypt your files without paying and buying Decryption tool♦
♦ but after 48 hour decryption price will be double♦
♦ you can send some little files for decryption test♦
♦ test file should not contain valuable data♦
♦ after payment you will get decryption tool ( payment Should be with Bitcoin)♦
♦ so if you want your files dont be shy feel free to contact us and do an agreement on price♦
♦ !!! or Delete you files if you dont need them !!!
♦Your ID :-
our Email :Files2021@tutanota.com
In Case Of No Answer :Files2020@mailfence.com

The most typical methods of the cybercriminals used to infect computers

Different types of malware[3] are spread in different ways. for example, adware is spread mostly with freeware installation bundles, while ransomware is distributed mainly by spam emails and through file-sharing platforms. Cybercriminals are creating more viruses each day, so read our articles, and you might evade it.

Decme file virus

Spam emails containing either mischievous hyperlinks or infected attachments are sent out each day in tens of thousands. If any of these villainous options are clicked or downloaded, the infection and encryption start almost instantly. Be aware of these emails, and please never open any shady-looking emails or their components.

Torrent websites, like BitTorrent, The Pirate Bay, and others, are full of different malware. It's an ideal environment to spread cryptoviruses because no one is scanning the files and assuring end-users security. Please refrain from using any torrent sites.

Guide for Decme ransomware removal and a quick system tweaking

As we mentioned before, the only right thing to do with Decme ransomware removal is to delete it immediately after detection or the first sight of ransom notes. As long as this malware stays in your computer – more harm could be coming your way.

To remove Decme ransomware, we suggest using professional anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These time-proven apps are trustworthy and will safeguard your passageways on the internet.

When the device is virus-free, users shouldn't rush to restore their data from backups. First of all, a system tune-up is in order. Use the FortectIntego app to locate and restore any modifications Decme ransomware virus might have done to your system files and its settings.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.