Madek ransomware is type of malware that seeks to make users pay for their encrypted files

Madek ransomware is one of many variants of the STOP/Djvu virus and was first spotted in July 2019.[1] Just as its predecessors, the infection pollutes Windows operating system by performing a variety of changes to it and then starts the encryption of documents, pictures, videos, databases, and other files – all of them are appended with .madek extension.
Although it might seem like the data is corrupted, it is not the case. Hackers apply a sophisticated encryption algorithm (usually AES,[2] although it can vary from version to version) to lock up data, which can later be deciphered with the help of the unique key which only Madek virus authors have access to.
Madek ransomware then drops a _readme.txt note into each of the affected folders and the desktop, so that the victims could easily access it. Unlike other stealthy malware, ransomware does not hide its presence, as its goal is to make users pay the ransom – $980 in Bitcoin. However, users are also offered a 50% discount as an attempt to make them pay quicker, which consequently guarantees steady income from Madek ransomware victims.
| Name | Madek |
| Type | Ransomware |
| Family | STOP/Djvu |
| Extension | .madek |
| Ransom note | _readme.txt |
| Ransom size | $980/$490 |
| Contact | gorentos@bitmessage.ch, varasto@firemail.cc, @datarestore (Telegram) |
| Decryptable? | Might be possible with a decryptor [download link]. Otherwise, check alternative options below |
| Termination | Employ reputable anti-malware software |
| Recovery | To fix virus-damaged system files, scan your PC with FortectIntego |
Madek ransomware can be spread using various methods – it increases victim count, as well as profits for hackers. Here are a few malware distribution methods:
- Exploits
- Unprotected RDP
- Web injects[3]
- Spam emails
- Corrupted or infected installers
- Software cracks
- Fake updates, etc.
Regardless of how you got infected, it is Madek ransomware removal what you should be thinking of now, as the infected machine is compromised and not safe to use. Therefore, employ anti-malware software and perform a full system scan, as well as repair damaged system files using FortectIntego.
While there is no universal decryption tool available that would help all Madek virus victims, STOPDecrypter can be used to retrieve at least some files back. On the good note, those whose data was encrypted while being offline, the tool will be able to decrypt everything. Unfortunately, that is not usually the case.

As soon as Madek ransomware encrypts all the data, it drops _readme.txt ransom note which states the following:
ATTENTION!
Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-WbgTMF1Jmw
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.To get this software you need write on our e-mail:
gorentos@bitmessage.chReserve e-mail address to contact us:
varasto@firemail.ccOur Telegram account:
@datarestore
Mark Data Restore
Do not get lured by crooks promising a 50% discount – they just want your money. Fast. However, it does not mean that you will receive the alleged decryptor, or they might even ask for more money. Remember, these people criminals who distribute malicious software in order to extort money from victims worldwide, and they do not care about your well-being.
Instead, remove Madek ransomware from your device and then try restoring data using methods we provide below.
Be attentive while browsing the internet – ransomware can automatically infect your PC
There are people who up to this day do not employ anti-virus programs because they think that, as long as they browse safe sites and not download pirated software, they are safe. However, it cannot be farther from the truth, as various distribution methods require different protection measures, and anti-malware software is one of the primary ones.
Nevertheless, it is obviously not enough. Vulnerabilities can render your machine exposed to exploits, which can download and install the malicious payload automatically and without any signs. For that reason, updating your machine and all the programs installed is absolutely necessary.
Possibly the most ransomware infections come from careless users, however. Some malware samples can be never before seen, which would render security software ineffective. Thus, watch out for phishing emails, do not download pirated software or cracks, avoid torrent sites, and be overall warier when browsing the net.

Delete Madek ransomware by using reputable security application
While manual Madek ransomware removal is indeed possible, it would be too complicated of a procedure for regular users. Therefore, experts[4] recommend not meddling with system files and instead install a powerful anti-virus solution that would be able to find all the malware components and delete them. However, be aware that Madek virus might have modified Windows registry or other vital parts of the OS, so you should use FortectIntego to fix the damage done by the infection.
Once you remove Madek ransomware from your computer thoroughly, you can attempt file recovery. If the provided decryptor does not work, as well as all the alternative solutions, we recommend copying all the locked files and hope for the official decryptor released in the future.
Was this guide helpful?
Be the first to comment