Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2020

How to remove ExecutorV3 ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

ExecutorV3 ransomware – a malicious program that holds files hostage until a ransom is paid for a decryption tool

ExecutorV3 ransomware

ExecutorV3 ransomware is a computer infection that specializes in locking of pictures, videos, music, documents, and other personal files. Likewise, these files are appended with .babaxed extension and can no longer be accessed by users. For example, a “picture.jpg” is turned into “picture.jpg.babaxed” – it also loses its regular icon, and users can see blank ones instead.

As soon as the ExecutorV3 virus locks all data, it inserts ten ransom notes into the folders where locked files are located. Each of them is sequentially numbered from 0 to 9, e.g., “RECOVERY INSTRUCTIONS 0.TXT,”  “RECOVERY INSTRUCTIONS 1.TXT,” etc. In these notes, there is a brief message from the attackers – either pay $50 worth of bitcoin to the provided crypto wallet (1Nehd3pSRF6ijmeumjpPmq7Nwn3hFJEsj) or never recover your files.

It seems, however, that malware is in its development stage and has plenty of bugs, as .babaxed files virus also encrypts executable and other files this type of malware should not be touching.

Name ExecutorV3 ransomware 
Also known as .babaxed extension virus
Type Cypro-virus, file locking virus
Extension Files appended with .babaxed extension, e.g., “picture.jpg” is turned into “picture.jpg.babaxed”
Ransom note  “RECOVERY INSTRUCTIONS 0.TXT,”  “RECOVERY INSTRUCTIONS 1.TXT,” “RECOVERY INSTRUCTIONS 2.TXT,” etc. 
Contact  haunexuwofwuf@protonmail.com
Ransom size $50 in bitcoin
File recovery  Restoring data by paying criminals is not recommended and, in this case, not possible. Instead, check the alternative methods below, although keep in mind that the chance of success is relatively low 
Malware removal  Perform a full system scan with powerful security software, such as SpyHunterCombo Cleaner 
System fix Malware can seriously tamper with Windows systems, causing errors, crashes, lag, and other stability issues after it is terminated. To remediate the OS and avoid its reinstallation, we recommend scanning it with the FortectIntego repair tool

ExecutorV3 ransomware is not the only example of extortion-based malware, although it does not belong to any larger family, unlike Copa, Geneve, or Blm. While the latter category is much more common, there are plenty of new strains like this one – many cybercriminals are attempting to extort money via the lucrative, but very illegal, ransomware business.

Since this virus is relatively new, there is not much information yet on how it spreads. However, the most common ransomware distribution methods are likely to be used, including:

  • Malicious spam email attachments or hyperlinks;
  • Software vulnerabilities[1] and exploit kits;
  • Fake updates and other fake alerts;
  • Pirated programs and software cracks;
  • Exposed Remote Desktop connections, etc.

One of the ExecutorV3 virus samples was spotted spreading as CardGame.exe, although other names could be used. This is done on purpose to mislead users and make them believe that the executable is safe. Once clicked, malware would launch Execv3.exe along with several processes. This action would then download the malicious payload onto a Windows system.

Once installed, .babaxed file virus would delete Shadow Volume Copies,[2] modify the Windows registry, and perform other actions to prepare the system for the encryption process (note that these modifications might sometimes be difficult to get rid even after ExecutorV3 ransomware removal, so we recommend using FortectIntego to fix system damage for that purpose).

.babaxed file virus

The virus then encrypts all personal files on the machine – pictures, videos, music, documents, databases, and even executables. Users can then see ten ransom notes on the desktop, each of which includes the same message, which reads:

All your Files have been crypted. Send 50$ wort of Bitcoins to this Address: 1Nehd3pSRF6ijmeumjpPmq7Nwn3hFJEsj | As soon as you sent the Money, sent an email to: haunexuwofwuf@protonmail.com | as soon as we see the email we will send you the decrypter.

There are several reasons why you should not pay the criminals, even though the ransom is relatively low (this also hints that the attackers are just starting up their illegal activities). Since ExecutorV3 ransomware is relatively new, there is no guarantee that the attackers will deliver the required decryption key. Besides, it will only reassure threat actors that their plan works, and they will be much more keener to infect more people and demand higher ransoms.

Before you proceed with file recovery, you should perform ExecutorV3 virus removal. For that, employ powerful anti-malware solutions, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, and scan the system fully.

Ransomware consequences: how to open .babaxed files?

Most users who got infected with ransomware have never encountered it before. For the most part, they have not even heard about such an infection. Hence, they mistakenly believe that .babaxed file recovery can be performed as soon as the virus is eliminated from the infected system. Unfortunately, this is not true, as security software is not designed to unlock ransomware-encrypted files.

Hence, even after you delete the infection from the system using anti-malware, you will not recover .babaxed virus files, and they will remain locked. This is because a unique encryption key is used, and the only ones who have access to it are the cybercriminals. They ask for $50 for the decryptor, although experts[3] usually discourage paying.

If you are not willing to pay, you can try alternative recovery solutions. Since malware is relatively buggy, it might be possible to recover all data without risking your money. For example, if malware failed to delete Shadow Copies, Windows automatic backups can be used to restore data to normal. Besides, third-party recovery software can be an excellent choice in some cases. If you want to find out how to recover .babaxed files without paying criminals, check the bottom section below.

ExecutorV3 ransomware virus

ExecutorV3 ransomware removal

It is important to note that you should not perform ExecutorV3 ransomware removal straight away if you do not have backups to recover your data from. It might be that security researchers will create a working decryption tool in the future, allowing them to recover data for free. However, since such a tool does not exist currently, you should backup .babaxed files first.

As soon as you copied your most important data, you can remove ExecutorV3 ransomware from your computer by scanning it with powerful anti-malware, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. This process will ensure that all the malicious processes, modules, and files are eliminated, and no further file encryption will occur. After that, use FortectIntego to repair damage to Windows, which could have been sustained during the attack.

Finally, proceed with alternative methods to restore your data. If none of the below-listed methods help, there is no other effective method at the present time that could help you recover ExecutorV3 virus files.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.