Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2020

How to remove LANDSLIDE ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

LANDSLIDE ransomware – a cryptovirus from a group that calls itself a “King Of Ransom”

LANDSLIDE ransomware

LANDSLIDE ransomware is a cryptovirus that encrypts all data on the computer (backups, pictures, documents, archives) except for the system files and then demands a ransom for the promised decryption tools. This file-locking parasite uses AES and RSA[1] military-grade algorithms to accomplish the encoding.

At the very moment that the ransomware virus accesses a computer system, it starts the encryption, during which all non-system files on the device are renamed, appending a three-part extension. The first two parts of it consisting of an email address of the cybercriminals ([nataliaburduniuc96@gmail.com]) and the appointed victim ID ([id = ********]) are plated at the front of the file name. The .LANDSLIDE extension is appended at the end, right after the original file extension.

As soon as all of the personal data is encrypted and renamed, .LANDSLIDE file virus generates two ransom notes – a pop-up window, titled ReadThis.hta, and a text file, named ReadThis.txt. The message in both ransom notes is identical. You can see both of them at the bottom of this paragraph.

name LANDSLIDE ransomware, .LANDSLIDE file virus
type Ransomware
Ransom note Two ransom notes with identical content are created – ReadThis.hta and ReadThis.txt
Appended file extension All non-system files are appended with a triple extension: [nataliaburduniuc96@gmail.com].[id = 01234567].filename.file_extension.LANDSLIDE
Preferred payment method Cryptocurrency Bitcoins
Criminal contact details Hackers provide two emails to contact them – nataliaburduniuc96@gmail.com and aliseoanal@gmail.com
Malware Removal Victims shouldn't doubt for a second before removing the cryptovirus with a powerful anti-malware software
System fix We recommend using the FortectIntego tool after malware removal to find and fix any registry or other irregularities within the system settings

Within the ransom note, creators of LANDSLIDE ransomware let their victims know that all their data was encrypted and that the only way to unlock is by purchasing their decryption tool. To establish some fake trust between each other, they offer free decryption of one file from the infected computer. The file shouldn't exceed 200KB.

As usual with this type of malware, developers of the LANDSLIDE virus want to be paid in a cryptocurrency called Bitcoins. They school their victims to search on Google on how to obtain this cryptocurrency. Bitcoin wallet would be sent after the users establish contact.

To do that, the cybercriminals provide two email addresses. First, the victims should write to nataliaburduniuc96@gmail.com, but if they don't hear back from the LANDSLIDE ransomware makers within 24 hours, the victims should try sending another email to aliseoanal@gmail.com. The usual threats not to try renaming or decrypting the files aren't submitted.

As always, we strongly advise against establishing contact with cybercriminals. Instead, we suggest the victims remove LANDSLIDE ransomware from their infected computers and look for other data recovery options. To make sure malware is removed correctly, it should be done with trustworthy anti-malware apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.

LANDSLIDE ransomware virus

Experts[2] recommend using a system repair software like the FortectIntego tool right after LANDSLIDE ransomware removal to ensure that computers' registry and other essential core settings and system files are unaffected by the cryptovirus.

Developers of the LANDSLIDE virus that call themselves King of ransom send this message with their ransom note:

Your SERVER / COMPUTER is encrypted by us! _
Hello Admin / Guest!
[ENCRYPTER] => All your data is encrypted by us ..
[ENCRYPTER] => Your Server Unique ID: [D2C85 ***]
[ENCRYPTER] => Do you want to decrypt your data?
[ENCRYPTER] => To trust us, first send us a 100-200 KB file,
we will decrypt it to build trust for you.
[AFTERTRUST] => What should you do after building trust?
Help
(
All your data is encrypted,
If your data is important and you want to decrypt it,
You must pay the bitcoin amount set by us,
Send a message to our emails first, after pricing, us and your trust,
Do a Google search to buy bitcoins,
For example: “Buy bitcoins in rubles”.
After purchasing Bitcoin, you must
transfer the Bitcoin to our wallet,
After payment, the decryption tool will be sent to you
along with how to execute it properly
)
ENCRYPTER @ server ~ $ To contact us, first send a message to our first email.
[FiRsT Email:] nataliaburduniuc96@gmail.com
ENCRYPTER @ server # If your email is not answered after 24 hours, our email may be blocked.
So send a message to our second email.
[SeCoNd email:] aliseoanal@gmail.com

King of ransom
LANDSLIDE Ran$omW4rE

Avoiding one of the most common ransomware distribution – file-sharing platform

Malware could be hidden in many places on the internet, but ransomware like Lisp, CryLock, Weui, etc., are mainly hidden in file-sharing platforms such as The Pirate Bay, BitTorrent, and others. Pages like these are used by cybercriminals because they can camouflage their creations as any something that would catch the eyes of soon to be victims.

Hackers disguise ransomware as the latest game cracks,[3] pirated software, game cheat codes, and so on. Malware could be downloaded to your device as any file type – .exe, .jpg, .txt, .zip, .pdf, etc. We advise refraining from using these kinds of sites altogether. Support your beloved game or software developers by purchasing their products either directly from them or their official distributors.

LANDSLIDE virus encrypted files

LANDSLIDE virus removal guide from affected computers

All malware should be dealt with swiftly with the help of professional anti-malware software as manual elimination isn't easy. Remove LANDSLIDE ransomware with time-proven apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to ensure that the cryptovirus with all of its particles are truly and properly deleted.

Unfortunately, LANDSLIDE ransomware removal will not unlock the encrypted personal files, but that doesn't mean that the victims should doubt for a second to delete it. Take care of the device's overall health and look for other data recovery options. Try using our suggestions at the bottom of this article.

When it comes to system repair, we recommend using a powerful FortectIntego system tune-up tool to perform a full system scan to find and repair any alterations that the file-locking parasite could have done to the computer's settings, such as the system registry and other.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.