GuardBTC@cock.li – a new version of Dharma/CrySiS malware family

GuardBTC@cock.li is a malicious crypto-virus[1] which belongs to Dharma/CrySiS ransomware family. Malware appends .[GuardBTC@cock.li].java file extension to each targeted files. However, sometimes it can switch to other email address, such as filedecrypt@cock.li or similar. Additionally, malware delivers a ransom note where crooks demand to pay a specific amount of Bitcoins for data recovery.
GuardBTC@cock.li ransomware uses AES encryption algorithm and keeps decryption key on the remote server. While original Dharma/CrySiS viruses are decryptable without a secret key, the recent version, which can also be called as .java ransomware, is not. Therefore, after the attack, you can restore your files only from backups. However, this fact should not motivate you to pay the ransom!
Following data encryption, GuardBTC@cock.li virus leaves a ransom note, explaining what happened to users’ files. The text file reveals that all the data is locked and completely unusable. To obtain access to data, the user must pay a specific sum in Bitcoin cryptocurrency.
However, we do not suggest contacting cybercriminals. Crooks are known to completely ignore victims, even after the demanded amount of ransom is paid. Additionally, you are financing illegal criminal activity which helps culprits extract money from unsuspecting users.
As you can see, having business with criminals might only increase yours loses. Instead of that, focus on GuardBTC@cock.li removal which is needed to use your computer normally and safely again. Malware may have injected malicious code into legit system processes and installed other harmful files on your computer. For this reason, the system becomes vulnerable and attractive to other cyber threats.
Therefore, we advise you to remove GuardBTC@cock.li from your machine using a robust malware removal program such as FortectIntego. Keep in mind that manual removal is extremely complicated and should only be performed by IT professionals and we want to discourage you from such activity.
However, if you cannot install or run security software, check the instructions at the end of the article and use either Safe Mode with Networking or System Restore method. Additionally, read alternative methods that can help you recover access to at least some of your files.

Avoid dangerous ransomware attacks by paying attention to your email inbox
Cybercriminals rely on inattentive users who open every email or link directed towards them. Spam emails are the most prominent ransomware distribution method. Typically, the author of email pretends to be some important entity from a well-known organization, government employee or a bank representative. He/she actively encourages opening the file which is attached to the email or clicking on the link provided.
Please be careful and examine e-mails from unknown sources attentively. There are always warning signs; you just need to learn to spot them. Additionally, your email provider usually flags up suspicious emails, so do not ignore those warnings.
In addition to spam emails, ransomware can be distributed in other ways:
- Exploit kits;[2]
- P2P websites/clients;
- Fraudulent software downloads;
- Fake updates/ads/popups;
However, no matter how much precautions you undertake, you are never entirely safe from ransomware attack. Therefore, make sure you keep regular backups on an external drive.
Removal guide for GuardBTC@cock.li ransomware
As we previously mentioned we strongly advise proceeding with manual GuardBTC@cock.li removal as this procedure is complicated, especially for standard computer users. The risk of damaging system files and its registries is exceptionally high; therefore we advise you to pick automatic elimination method.
Security experts from viruset.no[3] warn that you should download a proper security software and remove GuardBTC@cock.li virus before proceeding with file recovery. We advise using a powerful security tool like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Otherwise, your recovered files will be encrypted immediately again.
Was this guide helpful?
Be the first to comment