Excuses ransomware (Free Guide) - Removal Instructions

Excuses virus Removal Guide

What is Excuses ransomware?

Excuses ransomware — crypto-virus that demands money in exchange for a special key used to decrypt data

Excuses ransomware Excuses ransomware is a virus that demands ransom for encrypted files

Excuses ransomware is a virus capable of encrypting files and additionally asking a certain amount of money for their decryption. However, it's not a brand new cyber threat. It's one of the versions of KRIPTOVOR virus. Immediately after this virus encrypts target files, victim's data becomes useless. Affected files can be found by looking at their extensions – “.excuses” extension added to each of the filename means that you won't be capable of using it. These files can be anything from images, photos and videos to text files and archives. As typical ransomware, after compromising data, virus drops a ransom note on every existing folder in the computer. Text file “MESSAGE.txt” contains information about the demanded ransom and files' condition. Also, in includes details on how to contact hackers hiding behind this malware.

Name Excuses
Type Ransomware
Family Kriptovor ransomware
Target Russian speakers
Ransom file MESSAGE.TXT
Extension .excuses
Symptoms Encrypted files become useless, changed Windows registry key
Distribution Spam email attachments
Removal Best tool for Excuses ransomware elimination is FortectIntego

The entire ransom message is written in Russian, and we can only assume the primary target of Excuses ransomware virus is Russia. There is no information about ransom amount or encryption method. But usually, ransomware developers ask between $500 and $1500.

Virus developers want you to contact them via excuses@protonmail.com email, but we can assure you that is not a good idea. Contacting and paying the ransom can lead to no positive results and your money or data may be lost. You should remove Excuses ransomware if you want to be sure that your information is not misused. These criminals can infiltrate your system and do more changes to your Windows registry key or other PC settings.

Often virus developers offer to decrypt one or two test files before paying the ransom, but it is unknown if these people even have that decryption tool. Most of the times after the payment is done criminals ignore their victims and disappear with their money and your files.

Although, your files can not be decrypted using tools we do not recommend to focus on that. It is better to get rid of Excuses ransomware[1] and other viruses from your system and only then think about file restoring. You need to be sure that your system is spotless before you plug in an external drive. File backups are the only option when it comes to data recovery after ransomware attack.

Excuses ransomware removal is better to be done as soon as you notice the changes in your system. It is recommended that you do the elimination using professional anti-malware tools. We can suggest FortectIntego, but you can choose any other trustworthy program.

Excuses ransomware virus Excuses ransomware - crypto-virus that changes your Windows registry key

Legitimate-looking letters might contain infections

Usually, spam[2] emails look legitimate and contain safe-looking attachments like Microsoft Word files. Although these files often have malicious macros that install malware on the system immediately and without your knowledge. It is essential to consider these received emails as a possible threat.

Dieviren.de[3] specialists highly recommend you to keep away from this box and do not open those emails and especially attachments. That clickable content is dangerous. Advertisements can contain other viruses that open access to ransomware and other malware. This is risky as well as getting your software from suspicious providers. You can never know what are you installing if you skip through important installation steps.

Excuses ransomware elimination is vital for the security of your system

To remove Excuses ransomware we recommend using certified and trustworthy anti-malware tools like FortectIntego, SpyHunter 5Combo Cleaner and Malwarebytes. This is vital if you want to get rid of all ransomware relating content and avoid any repetition in the future. Ransomware comes with other files and programs, so you could not find those additional pieces manually.

These tools help you to do Excuses ransomware removal correctly and eliminate all possible threats. By doing so, you can be sure that file recovery, later on, will be successful. If not appropriately cleaned your system might still contain ransomware traces and the second you plug in that external drive, virus encrypts files in it. This means you lost all of your essential data. There is a guide below that can be helpful in all of these steps of ransomware removal and file recovery.

do it now!
Fortect Happiness
Intego Happiness
Compatible with Microsoft Windows Compatible with macOS
What to do if failed?
If you failed to fix virus damage using Fortect Intego, submit a question to our support team and provide as much details as possible.
Fortect Intego has a free limited scanner. Fortect Intego offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Fortect, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Intego, try running Combo Cleaner.

Getting rid of Excuses virus. Follow these steps

Manual removal using Safe Mode

First step you can do when dealing with ransomware is rebooting your PC in Safe Mode using Networking

Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.

Step 1. Access Safe Mode with Networking

Manual malware removal should be best performed in the Safe Mode environment. 

Windows 7 / Vista / XP
  1. Click Start > Shutdown > Restart > OK.
  2. When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  3. Select Safe Mode with Networking from the list. Windows 7/XP
Windows 10 / Windows 8
  1. Right-click on Start button and select Settings.
  2. Scroll down to pick Update & Security.
    Update and security
  3. On the left side of the window, pick Recovery.
  4. Now scroll down to find Advanced Startup section.
  5. Click Restart now.
  6. Select Troubleshoot. Choose an option
  7. Go to Advanced options. Advanced options
  8. Select Startup Settings. Startup settings
  9. Press Restart.
  10. Now press 5 or click 5) Enable Safe Mode with Networking. Enable safe mode

Step 2. Shut down suspicious processes

Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Click on More details.
    Open task manager
  3. Scroll down to Background processes section, and look for anything suspicious.
  4. Right-click and select Open file location.
    Open file location
  5. Go back to the process, right-click and pick End Task.
    End task
  6. Delete the contents of the malicious folder.

Step 3. Check program Startup

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Go to Startup tab.
  3. Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files

Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:

  1. Type in Disk Cleanup in Windows search and press Enter.
    Disk cleanup
  2. Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
  3. Scroll through the Files to delete list and select the following:

    Temporary Internet Files
    Recycle Bin
    Temporary files

  4. Pick Clean up system files.
    Delete temp files
  5. You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):


After you are finished, reboot the PC in normal mode.

Remove Excuses using System Restore

You can also try System Restore feature

  • Step 1: Reboot your computer to Safe Mode with Command Prompt
    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Excuses. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with FortectIntego and make sure that Excuses removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Excuses from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If your files are encrypted by Excuses, you can use several methods to restore them:

Data Recovery Pro is a tool created for file restoring

If you accidentally deleted your files or got them encrypted by the Excuses ransomware you need to try to restore them using Data Recovery Pro

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by Excuses ransomware;
  • Restore them.

Windows Previous Versions feature is a good choice for individual file recovery

If System Restore feature was enabled prior the attack you can recover your individual files using Windows Previous Versions feature

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

Restore your Excuses ransomware encrypted data using ShadowExplorer

If this ransomware did not delete Shadow Volume copies of your files you can use ShadowExplorer for file recovery

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Decryption tool is not available

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Excuses and other ransomwares, use a reputable anti-spyware, such as FortectIntego, SpyHunter 5Combo Cleaner or Malwarebytes

How to prevent from getting ransomware

Choose a proper web browser and improve your safety with a VPN tool

Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online. One of the basic means to add a layer of security – choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features. However, if you want true anonymity, we suggest you employ a powerful Private Internet Access VPN – it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.


Lost your files? Use data recovery software

While some files located on any computer are replaceable or useless, others can be extremely valuable. Family photos, work documents, school projects – these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur: power cuts, Blue Screen of Death errors, hardware failures, crypto-malware attack, or even accidental deletion.

To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, Data Recovery Pro can be your only hope to retrieve your invaluable files.

About the author
Olivia Morelli
Olivia Morelli - Ransomware analyst

If this free guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Olivia Morelli
About the company Esolutions