Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jun 2020

How to remove EyLamo ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

EyLamo – another file-encrypting virus inspired by HiddenTear

Ransom note by EyLamo ransomware

EyLamo is a recently discovered ransomware which is based on the HiddenTear open source project.[1] It appends .lamo file extension to each of the targeted files with the help of AES encryptions algorithm.

Malware might enter the system as an obfuscated email attachment, fake program or using similar tricks. On the affected device is installed two executable files that start its malicious tasks immediately – hidden-tear.exe and EyLamo.exe.

Before starting the most important task – data encryption, this crypto-malware makes modifications on Windows. It might make entries in the Registry, install unknown files or inject malicious codes into legitimate system processes.

All these changes are necessary to run EyLamo virus with system startup and make its removal complicated. Once malware strengthens its presence on the PC, it starts scanning the system looking for targeted files.

Malware aims at the most popular Microsoft Office, OpenOffice, various multimedia files, databases, archives, etc. The file-encrypting virus is suspected of using the same AES cryptography as other variants of Hidden Tear.

Following data encryption, it might change computer’s desktop with a black image saying:

Oops, your files have been blocked. Please read the READ_IT.txt file on your desktop for more information.

Judging from the content of READ_IT.txt, we can tell that authors of the EyLamo do not act like professional cyber criminals. In the ransom note, they ask to send bitcoins or kebab to get decryption key. However, neither the sum of the ransom nor address where to send a kebab are not provided.

Thus, trying to guess how much money cyber criminals want is not recommended. Probably, such activity will end up with a waste of money. There are numerous cases when victims haven’t received decryption key after paying the ransom.

However, the most important fact about data recovery is that files might be restored with Hidden Tear decrypters. However, before giving them a try, you should perform EyLamo removal.

To eliminate ransomware along with all its components, you have to employ a professional security software. We suggest employing FortectIntego or SpyHunterCombo Cleaner. However, the extortionist might be resistant and prevent you from installing malware removal tools. In this case, you will find our removal instructions handy.

Once you remove EyLamo automatically, you could safely plug in USB or hard drive with data backups and copy necessary entries. Or you can use decryption software or try alternative recovery tools presented at the end of the article.

The image of EyLamo ransomware virus

Strategies used in crypto-malware distribution

Developers of the ransomware usually rely on traditional malware distribution methods, such as:

  • malspam;
  • fake software downloads;
  • malvertising;
  • exploit kits.

Authors of EyLamo are suspected of using the same strategies too. Thus, if you have suffered from the ransomware, the attack might have occurred when you opened a malicious email attachment, installed bogus program or update, clicked on a malware-laden ad or forgot to update operating system or software for a long time.

No matter where you live – America, France or Japan[2] – this cyber infection might reach you if you don’t follow these security tips:

  • Do not open spam emails and links or attachments included there.
  • Before opening email attachment make sure that it’s actually was sent from the company or organization.[3]
  • Install new programs from the credible and secure online sources. Keep in mind that using torrents might be dangerous.
  • Do not trick on ads that ask to update software, suggest installing unknown tools and offers too good to be true shopping offers.
  • Do not visit high-risk websites.
  • Keep all software up-to-date.

Terminate EyLamo virus with the help of reputable security software

In order to remove EyLamo from the computer safely and quickly, you have to employ professional software. Trying to locate ransomware-related entries might lead to irreversible damage to the system.

To avoid posing a threat to your computer, you should install malware removal program. We suggest dedicating this task to FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These tools are capable of detecting and eliminating all malicious entries. However, don’t forget to update them first!

If you need extra help with EyLamo removal, check our prepared instructions below. It will help you to deal with obstacles and reveals data recovery options.

Did this guide help?

Be the first to comment

Read in your language

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.