Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jun 2021

How to remove Fdcz ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Fdcz ransomware – a cryptovirus that offers a 50% discount on its ransom if the victims act swiftly

Fdcz ransomware

Fdcz ransomware is a file-locking virus developed for cryptocurrency racketeering. It does that by encrypting all personal files and demanding a ransom to regain access to them. This cryptovirus infects devices only with Windows Operating System. Apart from locking all personal files, it also renames them by appending a .fdcz extension to their original filenames. Thus if you had a file named a.pdf, it would now appear as a.pdf.fdcz.

When this infection has done the first part of its purpose, it generates a ransom note titled _readme.txt. This text file holds instructions and demands from the ransomware developers. They demand to contact them through given emails (helpteam@mail.ch, helpmanager@airmail.cc) to receive further payment instructions.

The ransom amount is set at $980, but if victims contact their assailants within 72 hours of the attack, a 50% discount is promised. As always, we advise against reaching out to cybercriminals or paying the ransom. There might be other ways to recover your data.

This malware derives from the infamous Djvu ransomware family. Since it's one of the most pervasive infection lineages, companies like Emsisoft dedicate their time to create free decryption tools for victims. Malware ensures persistence by showing a fake Windows Update pop-up window and modify the host file in Windows, alters startup settings, registry. You can find the helpful guide below that shows how to repair these issues.

name Fdcz ransomware
type Cryptovirus, file-locking parasite
Family Djvu/STOP ransomware
Ransom note _readme.txt is usually created on the desktop
Contact emails helpteam@mail.ch, helpmanager@airmail.cc
Ransom amount $980/$490. It depends if victims establish contact within 72 hours of the infection
Distribution Deceptive ads, file-sharing platforms, spam emails, fake Flash Player updates. This particular family is known for spreading via pirated sites and packages with malicious code posing as part of licensed version installations or game cracks
Removal To quickly and safely eliminate the virus and any computer infections, you should use a reliable anti-malware tool
Decryption File recovery options for this threat are limited because of the changes made to encryption methods and other techniques. You can find all the alternative options below
System Repair Since ransomware often does extensive damage to the system, it's highly recommended to use the time-proven FortectIntego system diagnostics tool to resolve any issues and avoid abnormal system behavior, or even infection renewal

Djvu family ransomware has been first spotted at the end of 2018. And since then, it's been terrorizing people all over the world. When a version from this lineage, such as Ytbn virus, Ekvf virus, Enfp virus, or others, infect your computer, all your personal files (documents, pictures, music, databases, etc.) are encrypted within minutes.

Unfortunately, in most cases, the only way to unlock the data is to use a decryption key or software that the cybercriminals have in their possession. In no way does that mean that you should succumb to their demands and pay the asked amount of cryptocurrency. The ransom message is created to scare you and make the Fdcz file virus developer richer.

They could use the ransom money to develop new versions and research more effective attacking techniques. For your convenience, we've posted data recovery solutions for this ransomware at the bottom of the page, so be sure to check them out.

Djvu family ransomware has a lot of similarities. That's not a surprise as it's cooking up new versions at least once a week or even more frequently. Ransomware developers portray their demands within the _readme.txt file, which reads:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-9CYW99VhUR
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
helpteam@mail.ch

Reserve e-mail address to contact us:
helpmanager@airmail.cc

Your personal ID:

As you can see, malware creators try their best to push you into making rash decisions. Since these criminals are in the dirty business for 3 years, they know how to scare and convince their victims into agreeing with their demands. They use four persuasion tricks:

  • state that only their decryption software will unlock your data,
  • offer free decryption of one file from the infected device, to prove that such a tool exists,
  • include a link to a video where you can see their offered software in action,
  • provide a 50% discount on the ransom to victims that act swiftly and establish contact within 72 hours.

Fdcz ransomware virus

Criminals are criminals, and thus you should never trust them. There are other ways to recover your data, so remove Fdcz ransomware immediately. Cybersecurity specialists from DieViren.de[1] highly recommend using the SpyHunterCombo Cleaner or MalwarebytesMalwarebytes free security tools for this procedure. If the virus prevents you from opening the AV tool, reboot your PC and start it in Safe Mode with Networking (instructions posted below).

Detection[2] names might indicate the aliases, family of the malware, or show how the threat is distributed, but you should remove any intruders found after the AV tool scan.

  • Trojan.GenericKD.36632355
  • Trojan.Ransom.Stop
  • TR/Crypt.Agent.lkham
  • W32/Kryptik.HKFU!tr
  • Trojan.MalPack.GS
  • HEUR:Exploit.Win32.Shellcode.gen
  • etc.

After you delete the virus with reliable anti-malware software, you have to use system repair tools, such as the time-proven FortectIntego system diagnostics software, to restore all the changes that this cryptovirus has made to your system. It usually alters the Registry, host files, and other key system elements to establish persistence.

If these changes are left unattended, you might encounter BSoDs, freezing, and other abnormal device behavior, including infection renewal. Once the removal is properly finished, you can restore your data from backups. If you didn't keep them, try using other recovery options posted at the bottom.

Refrain from using file-sharing platforms to keep your PC virus-free

Various malware, including ransomware, Trojans, rootkits, keyloggers, etc., is spread using many techniques. Some of the most popular ones are spam emails, fake Flash Player updates, drive-by downloads[3] on hacked sites, RDP attacks,[4] and deceptive ads. But one of the peculiarities of the Djvu ransomware family is that it mainly spreads through file-sharing platforms and, in particular, the most popular torrent sites.

Fdcz file virus

Unlocked (pirated) expensive commercial software and cracks for the latest games could hold this family's virus payload files. Cybercriminals could prefer this method as it requires the least effort. They have to upload their vile creations with an alluring name and wait for someone to download them.

Once ransomware is on your device, and you execute the file thinking that there's nothing wrong with it, an infection starts, and your data is rendered inaccessible within a couple of minutes. Thus think twice before using such file-sharing platforms as it may result in a severe headache.

Guidelines to remove Fdcz ransomware from infected Windows computers

When the culprit of this article infects your computer, you're going to be locked out of your files within minutes. It will encrypt every personal file on your device and then ask for a ransom. People have to realize that obeying the criminals' demands only motivates them to attack other innocent people and finances their whole operation.

The only reasonable thing to do is to remove Fdcz ransomware. The best way to do it is to scan your infected PC with a trustworthy anti-malware tool such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Since it alters system files, it could be a bit more difficult as it could prevent you from launching a security tool. 

If that's the case, you have to reboot your device and launch it in Safe Mode with Networking. If you're not quite sure how that's done, please refer to our guides below. You will also find file recovery options listed there. Try using them if you didn't keep backups of your essential data.

To finish the removal process, you have to use the FortectIntego system diagnostics software. It will find and delete any residual files or entries of the hazardous virus, preventing its renewal. And it will restore any damage that the infection has caused to your system files so that you could enjoy a stable working environment.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.