Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2019

How to remove Dotmap ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Dotmap ransomware is a file locking malware and a variant of Djvu virus family that demands ransom for the decryption tool

Dotmap ransomware

Dotmap is a ransomware-type virus that was first spotted by cybersecurity expert Michael Gillespie in mid-May 2019. The malware operates as an extortionist, meaning that it forcefully locks ups all personal files on the drive and demands ransom to be paid for the decryption tool.

Dotmap ransomware belongs to Djvu/STOP virus family, and also uses AES or similar robust encryption algorithms to perform the encryption which also appends .dotmap extension to picture, video, music, database, document, and other files. 

Victims are also present with a ransom note _readme.txt which explains what happened to their data and what steps they need to take in order to retrieve the access. Crooks prompt users to email them via bufalo@firemail.cc, gorentos@bitmessage.ch emails or contact via @datarestore Telegram account, and then pay a ransom of $980. Additionally, they also note that a 50% discount is offered within 72 hours of the infection.

Nevertheless, there is no need to contact crooks or pay the ransom, and rather focus on Dotmap ransomware removal. While no universal tool would decrypt all STOP variants, STOPDecrypter might be useful if the file-locking process was performed offline. 

Name Dotmap
Type Ransomware
Infiltration methods Spam emails, fake updates, repacked installers, software cracks, exploits, etc.
Malware family STOP/Djvu
File extension .dotmap
Ransom note _readme.txt
Contact bufalo@firemail.cc, gorentos@bitmessage.ch or @datarestore Telegram
Decryptable? No, although STOPDecrypter [download link] might be useful in some cases. Alternatively, you can try third-party recovery software – we provide all the links below
Termination Download and install reputable antivirus software
Recovery To repair infected system files, scan your computer with FortectIntego

There are several methods that hackers behind Dotmap ransomware use to propagate the virus. For example:

  • Spam emails;
  • Exploit kits;
  • Fake updates;
  • Web injects;
  • Unprotected RDP exploitation;
  • Drive-by downloads, etc.

Nevertheless, various STOP variants (Rumba and Tco) are known to be distributed with the help of adware bundles, as well as pirated software installers and its cracks. Additionally, other versions, such as Promorad, Promok, and Kroput, were also found to include a data stealer AZORult,[1] so be aware that Dotmap virus might consist of a secondary payload.

Once inside the system, Dotmap ransomware drops a ransom note into each of the affected folders, and it states the following:

ATTENTION!

Don't worry my friend, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-2jkyb95pOj
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
bufalo@firemail.cc

Reserve e-mail address to contact us:
gorentos@bitmessage.ch

Our Telegram account:
@datarestore

Your personal ID:

Do not trust the cybercriminals, even if they offer the discount and the free test decryption. Hackers might simply forget about you as soon as they get your money and never send you the decryption tool. Additionally, this would only prove that the ransomware scheme works and promote Dotmap ransomware development, infecting more victims worldwide.

Therefore, remove Dotmap ransomware with the help of powerful anti-malware software and then choose alternative methods for data restore. Additionally, experts[2] recommend scanning the device with FortectIntego for a quick recovery from the infection.

Dotmap ransomware virus

Do not download pirated software or its cracks – it is the quickest way to get infected with ransomware

Some of the infection methods that hackers use are sophisticated – they exploit software vulnerabilities and then redirect users to a malicious domain with the help of adware or ads on hacked sites. Once there, the malware can infiltrate the victims' machine without their interaction. In some cases, the virus might be hidden inside a picture or another seemingly harmless file with the help of Steganography[3] – a technique that allows malware to bypass security tools.

Nevertheless, most of the users get infected with ransomware in a very simple manner – they themselves initiate the infection process after opening the malicious attachments or clicking on links in a spam email, download pirated software or cracks, insufficiently protect their accounts, etc.

Therefore, besides employing tools like firewall, anti-malware software, ad-blocker, and similar, you also need to be internet smart and never endanger your computer. Avoid downloading suspicious installers, as well as software cracks/keygens, scan all the unknown executables with antivirus software, make sure to use two factor authentication where possible and ensure your account safety with strong passwords that are never reused and update your system along with all the installed programs as soon as security patches are released.

Delete Dotmap ransomware with comprehensive security software

To remove Dotmap ransomware, you will have to install anti-malware software if you have not done so already. Be aware that not all the AV engines might recognize the infection, and scans with multiple tools might be necessary to terminate the threat.

Nevertheless, probably the best way to take care of Dotmap ransomware removal is to access Safe Mode with Networking first because the safe environment is the best to troubleshoot problems, as well as delete viruses. We provide guidance on how to reach it below. Once inside, make sure you initiate a full system scan – it should terminate Dotmap virus along with any secondary payloads that might be hidden on your PC.

Once you are sure that the malware is gone, you can start the file recovery process. If you do not have backups prepared, there are several other options you can try – maybe it will help you recover at least some of your data, although the chances are relatively slim.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.