Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2016

How to remove DXXD ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

 

An overview of the DXXD ransomware:

It seems that hackers own some kind of ransomware manufacturing machine as they have recently struck the Internet users with yet another malicious creation – DXXD virus. As it is still a newbie, it is too early to decide what or who are the primary targets of this ransomware. Regarding the ransom note that this virus presents for its victims, one might suspect that it has connections with the recently swept-by restore@protomail.com and Fantom ransomware. In case you visited our website looking for a solution to remove DXXD virus, rest assured. We provide all the necessary instructions below this article. While you are getting accustomed to the operation ways of this ransomware, start DXXD removal by employing FortectIntego anti-malware.

Observing the current trends in the ransomware world, it is obvious that while some hackers concentrate on developing an invincible threat, others are more keen on showing off. This ransom may not give such ambiguous impressions as Cyber_baba@aol.com or Nagini ransomware. Certainly, the ransom note left by this virus does not leave an impression of refinement. The hacker makes fun of his victims by apologizing for the encrypted files. However, this poor play and disguise do not diminish the danger level of this file-encrypting malware. DXXD ransomware does not deviate from using ordinary encryption techniques.

The image of DXXD ransom note

However, it has one exceptional feature. While other viruses often leave their mark on the infected computer by appending an extension; the current malware leaves a bit different autograph. Let us take an example when notorious Locky first emerged; the virus marked the encrypted data by attaching the .locked extension. In this case, the corrupted files bear dxxd extension pinned after the original one. So, the infected computer file may look something like this: “randomfilename.jpgdxxd.”

Moreover, dxxd extension virus does not indicate the fixed amount of ransom in its ransom note that it drops on the computer after the data encryption. Instead, the ReadMe.txt document only features a couple of email addresses that the victims must contact in order to recover their files. Likewise, the current version of the file-encrypting malware might be just a test version before the grand improved edition will emerge. The .txt file contains brief instructions how to use a chat room. Besides such mocking notes, the ransomware provides two main email addresses: shellexec@protonmail.com and null_ptr@tutanota.de.

October 2016 update: Ransomware developers publicly announce having upgraded DXXD ransomware

Malware developers have joined DXXD support forums to announce that they are working on a more complex version of the virus. They claim having made the new version even more difficult to decrypt. Besides, they also seem to have changed their ways of hacking into servers. Now, the virus brute forces passwords using Remote Desktop Services. So, if your PC has already been infected with this ransomware, please change your Windows login details and other passwords on your computer.

Another new feature that the virus developers have decided to integrate is the lock screen. The virus alters Windows Registry entries to display a notification screen whenever you try to log into your computer. The lock screen imitates a BSOD notification, announcing that the computer has been attacked by hackers and Microsoft Windows Security Center urges the administrator of the device to contact the provided emails. These emails are the same ones as provided in the ransom note, so it leaves us no doubt that this Legal Notice is fake. An example of this notification is presented below:

 Picture of fake Microsoft Windows Security Center notification

How the hackers distribute this parasite?

DXXD ransomware might employ several and intriguing forms of transmission to carry out its malicious mission. As it is common with the majority of ransomware threats, they attack users via elaborate spam messages which come as fake financial and package delivery reports. Regarding DXXD malware, it is suspected to spread via malware which generates fake messages which are seemingly issued by Windows Security Center. The ransom note is accompanied by additional alert informing about the hacked server. In any case, IT experts warn users to be very vigilant when reviewing spam folder. It would be best to ignore such emails even if they address you personally. Similar emails may contain infected links or scripts with ransomware executables. In order to decrease the number of such emails, install a powerful malware removal utility.

Is there a way to terminate the ransomware and recover the data?

First of all, DXXD removal should be performed. In this regard, do not waste time and switch to automatic elimination. Install a security application, for example, FortectIntego or MalwarebytesMalwarebytes, and update it. The overall termination procedure does not require much of your time. If you struggle to remove DXXD virus because the essential computer functions fail to respond, feel free to employ our access recovery guide. Below it, you will also locate advice on data recovery.

4 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.