Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2020

How to remove .google ransomware (Phobos)

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

.google ransomware – a sneaky cryptovirus from the Phobos family

.google ransomware

.google ransomware is a cryptovirus that holds absolutely no relation to the actual Google LLC. It is a computer virus that encrypts all user files on an infected computer and then demands a ransom for a decryption tool. Almost all ransomware works based on the same model. This particular virus belongs to the infamous Phobos ransomware family.

When viruses from this family are encrypting data, they append a three-part extension to all non-system files. The extension consist of a unique victim ID, email address of the criminals, and .google appendix. All files are rendered inaccessible until decoded. When .google ransomware is done with the encryption, it creates two types of ransom notes – a pop-up window and text files.

name .google ransomware, .google (Phobos) file virus
typer Ransomware
family Phobos ransomware
appended file extension A tricky triple extension is added to all personal victim files: 1. appointed victim ID (in brackets), 2. criminal email address (in brackets), 3. .google extension
ransom note A pop-up window (info.hta) and text files (info.txt)
criminal contact details jackbez@yeah.net
virus removal Malware should be dealt with swiftly with the help of some professional anti-malware software
System tune-up System files and settings should be checked with the FortectIntego tool after .google ransomware removal is completed

Ransom message in the text files is very concise and just informs the .google ransomware virus victims that their files have been encrypted and if they want to regain access their have to contact the creators of .google ransomware by email – jackbez@yeah.net. In contrast, the message in the ransom pop-up window is much more explanatory.

The cybercriminals provide the same email to establish contact and assign a unique ID to the victim. They offer free decryption of up to five files (not exceeding 4Mb) to prove that they really can unlock victim files. The ransom amount isn't specified, but the creators of .google ransomware want to be paid in cryptocurrency Bitcoins because half of the message is instructions on obtaining them. In the last part of the ransom pop-up window, the criminals threaten the victims not to rename the files and not to try any third-party decryption apps because that will lead to permanent data loss.

Criminals should never be trusted, that why we strongly advise to remove .google ransomware from all infected machines, because the longer it stays in any of them, the more damage it could do. Apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes should do the job perfectly as these are trustworthy anti-malware applications.

Once .google ransomware removal is completed, experts[1] suggest doing a full system scan with the FortectIntego tool to locate and undo all the alterations the cryptovirus might have done to the system files and its settings.

.google ransomware Phobos

Message from .google ransomware developers to their victims (in the ransom pop-up window):

All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail jackbez@yeah.net
Write this ID in the title of your message –
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the tool that will decrypt all your files.
Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

The short message in the text files (info.txt):

!!!All of your files are encrypted!!!
To decrypt them send e-mail to this address: jackbez@yeah.net

Most common techniques used by cybercriminals to infect user computers

Various kinds of malware[2] are created and spread worldwide each day. Cybercriminals are getting really creative with the infection methods they use. But still, most of the ransomware is spread using two old methods – file-sharing platforms and spam emails.

File-sharing platforms, like torrent websites, are crawling with viruses. For example, Djvu family viruses like the Lisp ransomware are mainly spread with cracking tools[3] uploaded to these sites. So we strongly advise staying away from these sites.

.google Phobos virus

Spam email is another popular technique used by cybercriminals to infect computers. Usually, they carry either mischievous hyperlinks to sites where a payload file of the virus would be downloaded onto a computer immediately after entering it or infected attachments, that right after gaining access to a PC starts infection processes. For your own safety, please don't open any hyperlinks in phony looking emails and never download any attachments without scanning them first with a powerful anti-malware app.

.google ransomware (Phobos) virus removal guide

Whether it's annoying adware or the dangerous trojan horses, every type of malware should be deleted immediately. We suggest SpyHunterCombo Cleaner and MalwarebytesMalwarebytes to remove .google ransomware from the infected systems automatically. These apps might even save you from future attacks.

After .google ransomware removal, you're not out of the woods yet. Malware typically modifies system files without encrypting them. These changes might affect how your device runs. To revert all changes and get your computer back on track, use the FortectIntego tool.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.