.Good ransomware – a file locking cyber threat which offers to decrypt a small file for free as evidence

.Good ransomware detected as Trojan.GenericKD.32335732 by Bitdefender is a file locking virus which appears in a computer system due to a secret infiltration. It usually comes via spam messages. However, sometimes it might approach your machine after clicking on a malicious link or fake ad. Once installed, .Good file virus starts modifying the Windows Registry section which lets the cyber threat to perform its actions. The ransomware uses AES encryption to corrupt files on the infected computer and ads the .good extension to each of it. After that, a ransom note called HOW_TO_RECOVER_FILES.txt, Restore-My-Files.txt, or RETURN FILES.txt is displayed. Crooks urge victims to pay the demanded ransom for the decryption tool and offer to send a small file for free unlocking.
| Name | .Good |
|---|---|
| Detection name | Trojan.GenericKD.32335732 |
| Category | Ransomware |
| Extension | .good |
| Ransom note | HOW_TO_RECOVER_FILES.txt, Restore-My-Files.txt, or RETURN FILES.txt |
| Encryption algorithm | AES cipher is used for file encryption |
| Ransom | It is known that cybercrooks urge for Bitcoin as the type of currency |
| Email address | dsupport@airmail.cc, etc. |
| Special offers | Crooks offer to decrypt three files for free as evidence that the decryption key does exist |
| Changes | Modifications are seen in the Windows Registry |
| Removal | Install FortectIntego |
.Good ransomware provides dsupport@airmail.cc email address which should be a way for contacting. Users are urged to pay Bitcoin. This is the most famous cryptocurrency used by cybercriminals as it lets the transfer to remain secret. You can detect .Good files virus from such text message:
Your personal identifier: –
Your important files are now encrypted due to a security problem with your PC!
Now you should send us email with your personal identifier.
This email will be as confirmation you are ready to pay for decryption key.
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us.
After payment we will send you the decryption tool that will decrypt all your files.
Contact us using this email address: dsupport@airmail.cc
Free decryption as guarantee!
Before paying you can send us up to 3 files for free decryption.
The total size of files must be less than 10Mb (non archived), and files should not contain valuable information (databases, backups, large excel sheets, etc.).
How to obtain Bitcoins?
* The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click'Buy bitcoins', and select the seller by payment method and price:
hxxps://localbitcoins.com/buy_bitcoins
* Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins
Attention!
* Do not rename encrypted files.
* Do not try to decrypt your data using third party software, it may cause permanent data loss.
* Decryption of your files with the help of third parties may cause increased price
(they add their fee to our) or you can become a victim of a scam.
We recommend staying away from any contact with the cybercriminals. Especially, do not get tricked by their false promises and avoid paying the demanded price. It is known that users are very likely to get scammed by cybercrooks. After they get the money from their victims, criminals run off and leave the users desperate. As an alternative, we suggest performing the .Good ransomware removal ASAP.

In addition, keep in mind that cyber threats such as .Good ransomware might be capable of injecting other bogus and dangerous components on the infected machine. Usually, malware-laden content that is left after the residence of the ransomware is discovered in the Windows Registry section or Task Manager.[1]
Besides the beforementioned feature, .Good ransomware might be capable of running malicious processes in the background, executing commands via Powershell that allow the malware to delete Shadow Volume Copies of encrypted documents. This is a way to harden the data recovery process for the victims and force them to buy the offered key.
You need to remove .Good ransomware from your computer system as soon as you spot the first ransomware-related symptoms to avoid further damaging consequences. You can fix the damage that was done by the infection with the help of an anti-malware tool. We suggest using FortectIntego or any other similar program if you are likely too.
Remember that you can never be fully protected from ransomware-type infections. If you want to avoid viruses such as .Good ransomware, you need to take some precautionary measures which are written in this article. Moreover, purchase a USB drive and keep important files there. If you do so, no hackers will be able to corrupt data that is safely kept on your external device.

Prevent ransomware from infecting your PC
According to IT specialists who investigate malware[2], ransomware-type viruses are often spread via spam messages. Such hazardous payload comes in the form of an attachment which is clipped to the phishing email, or as a link which is inserted into the message. If you overcome a dubious-looking email message, better eliminate it as you cannot know what can be hidden behind it.
Moreover, if you like visiting various rogue sites, especially third-party ones, you are very likely to catch a dangerous infection which will cause various harm to the system. Questionable pages often lack protection and might be infected will virus-related content that once clicked launches that same minute.
Additionally, get an antivirus[3]. Scan your computer with the security tool after you visit rogue sites. Perform system scans once in a while just to make sure that no cyber threat managed to slip through the security system. Of course, take care of all updates that are recommended. If not, you might overcome outdated registry entries in the future.
Get rid of .Good virus
If you spot encrypted files and other symptoms that show the ransomware[4] infection, you need to remove .Good virus from your computer permanently. Use professional anti-malware tools for this process. We advise installing FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. Note that you need to get rid of the cyber threat before you start recovering your corrupted data. Otherwise, the virus will lock up files again because it will still be inside your computer system.
After you perform the .Good ransomware removal, you should carry out some system backups to be sure that the system is fully clean. After that, you can start thinking about data recovery techniques. We offer some third-party software which might be helpful in such situation. You can find these methods below this article. Complete each step carefully to reach best results possible.
Did this guide help?
Be the first to comment