Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2020

How to remove Dex ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Dex ransomware – money extorting computer virus from the Dharma family

Dex ransomware

Dex ransomware is a computer virus that encrypts all non-system files on an infected computer and demands a ransom for a decryption tool. This cryptovirus belongs to the Dharma ransomware family. Viruses from this lineage were first spotted in 2016 and new versions are presented each week.

Like its previous versions, such as Zimba, MUST, Sss, Dex ransomware virus appends a complex three-part extension to all user files (pics, audio/video files, documents, etc.) when it's encrypting them. The triple extension consists of 1. unique victim ID; 2. email address of the cybercriminals (decryptex@airmail.cc); 3. .dex appendix. When this process is accomplished, the cryptovirus generates ransom notes, one as a pop-up window and the other as text files (named FILES ENCRYPTED.txt) located in all affected folders.

name Dex ransomware
Type Ransomware, cryptovirus
Family Dharma ransomware
Ransom note A pop-up window and FILES ENCRYPTED.txt files
Appended file extension Triple extension in this sequence – a unique victim ID, criminal contact email in brackets and .dex appendix are appointed to all personal user files
Criminal contact details Two emails are provided to make contact but the second one is incomplete – decryptex@airmail.cc, dex.dex.tuta.io
Virus removal You should remove Dex ransomware, and other malware by using a powerful anti-malware software
system health check After Dex Ransomware removal users should use the FortectIntego tool to find and fix any system issues the virus might have caused

Ransom message in the text files is very short and essentially only two emails to establish contact are provided – decryptex@airmail.cc, dex.dex.tuta.io. The second one is misspelled so only one email is legitimate. The pop-up window ransom note is a bit more explanatory.

Creators of Dex ransomware state that only they can decrypt the files, usage of third-party decryption software might cause permanent data loss. They provide the victim with his/her unique ID and the same two emails. No details about the ransom amount or the preferred payment methods are given. Although we can speculate that the ransom will be asked to be forwarded using cryptocurrency Bitcoins.

Paying the ransom and forgetting about this unpleasant situation might seem like the easiest way out but victims should never do that. The only way to stop ransomware attacks is to stop paying the ransom.[1] Instead, victims should remove Dex ransomware with reliable anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These apps will not only locate the virus automatically and remove it but will protect your computer system from future incidents.

Dex ransomware virus

When Dex ransomware removal is done, users should take care of the overall system health. To get your virus-free device back on track experts[2] advise using the FortectIntego software as it will find and repair any damage the virus might have cause to system core files and settings.

Message from the developers of Dex file virus to their victims (from the pop-up ransomware window):

YOUR FILES ARE ENCRYPTED
Don't worry,you can return all your files!
If you want to restore them, follow this link:email decryptex@airmail.cc YOUR ID –
If you have not been answered via the link within 12 hours, write to us by e-mail:dex.dex.tuta.io
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

 Ransom note in the FILES ENCRYPTED.txt states:

all your data has been locked us
You want to return?
write email decryptex@airmail.cc or dex.dex.tuta.io

Dex file virus

Instruction to remain safe on the internet

These days, the internet is crawling with all kinds of malware. Everyday computer users should be aware of the lurking threats and know how to stay safe while browsing the World Wide Web. Stick to these suggestions and you might evade ransomware and other malware:

  • Always have powerful and up-to-date anti-malware software running on your system and watching your back.
  • Always have the latest updates for your computer's operating system.
  • Always keep backups of your essential data on at least two separate devices, such as a USB drive, offline servers, etc.
  • Don't visit high-risk websites
  • Don't download anything from torrent sites like The Pirate Bay, BitTorrent, and alike.
  • Don't open spam emails. 
  • Don't download any email attachments without scanning them first with a dependable anti-malware app.

Instructions on Dex ransomware virus removal and system tune-up

According to VirusTotal,[3] 64 out of 72 anti-virus engines caught .dex file virus before it has done any harm to the computers. That just emphasizes the need for trustworthy anti-malware software. We recommend using SpyHunterCombo Cleaner and MalwarebytesMalwarebytes anti-malware software to automatically remove Dex ransomware and all its allocated files spread out through the device.

Once Dex ransomware removal is behind you and your device is virus-free, then you should consider using the FortectIntego tool to check on your system's overall health. Dharma family ransomware is known to modify system files and settings, and that could lead to various abnormal computer behavior, such as crashing, overheating, error messages, and so on.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.