Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2021

How to remove MARS ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

MARS ransomware – a virus that asks for $500 to unlock your files that are changed to .mars or .vyb extensions

MARS ransomware

MARS ransomware is a malicious program that can be devastating for each of its victims. Malware attacks Windows systems after the malicious payload is executed, it begins scanning the system for vulnerable files. Its target – mostly MS Office documents. Each of the files is then marked with .mars or .vyb extension after encryption and can no longer be accessed by victims anymore.

After the encryption process is completed, a ransom note named “!!!MARS_DECRYPT.txt” can be found with the cybercriminals' demands. Users are asked to send an email to mars_dec@outlook.com or anton_ivan_8989@mail.ru which should include a unique ID and 3 files for test decryption. As an alternative means of communication, MARS virus authors also provide Telegram username “mars_dec” that can also be used if no reply is received via the email. To restore .mars files, users are asked to pay $500-worth of Bitcoin.

Unlike other malware of this type, MARS ransomware virus encrypts only a set number of file types, including xls, xlsx, doc, docx, ppt, pptx, odt, ods, pdf, dwg, psd, dbf, fpt, php, cdr, mdb, and accdb. Cybercriminals choose this data since it might hold the most sensitive information, such as schoolwork or important corporate data. Paying cybercriminals is risky, as they might never fulfill their promises, so we recommend checking for alternative solutions we provide below.

Name  MARS ransomware, .mars virus, MARS malware
Type Malware, Cryptovirus, Ransomware
appended Extension All affected files are appended with .mars or .vyb extension
Files vulnerable for encryption MARS virus doesn't encrypt all users' data, it locks only 17 types of files: xls, xlsx, doc, docx, ppt, pptx, odt, ods, pdf, dwg, psd, dbf, fpt, php, cdr, mdb, accdb
 Ransom note  !!!MARS-DECRYPT.txt
ransom amount Cybercriminals are asking for $500 to be paid in Bitcoins for file decryption
Criminal contact details Two emails mars_dec@outlook.com, anton_ivan_8989@mail.ru and a Telegram Messenger user name mars_dec is provided to make contact
Distribution  Spam email attachments, Torrent sites, Mischievous hyperlinks
Removal To remove MARS virus victims should use a trusted antimalware tool
System fix  To eradicate the aftermath of MARS ransomware, users are recommended to use FortectIntego tool to automatically detect system changes made by the virus

As soon as the MARS ransomware lands on victims' devices, it scans for frequently used documents and encrypts them right away. It appends .mars extension, and removes the regular file icon typical to the type. Although buying the decryption tool from the cybercriminals might seem like the only viable option to retrieve access to your files, but victims should be aware that they might not get what they're promised.

These days, a powerful anti-malware software should stand in-between the computer user and the internet. To automatically remove MARS virus from an infected device, use SpyHunterCombo Cleaner. These trustworthy apps will delete the virus and find all its pieces spread out through the computer system.

After successful MARS ransomware removal from a contaminated device it's highly recommended to do a system tune-up because such malware often altercates system files. A tool like FortectIntego will automatically scan, find, and fix any modifications done to victims' devices.

Ransom note, in file !!!MARS-DECRYPT.txt, contains this message:

All your files have been encrypted with MARS Virus.
Your unique id: 

Our virus encrypted 231 of your office files (xls, xlsx, doc, docx, ppt, pptx, odt, ods, pdf, dwg, psd, dbf, fpt, php, cdr, mdb, accdb).
You can buy decryption for 500$ in Bitcoins.
But before you pay, you can make sure that we can really decrypt any of your files.
The encryption key and ID are unique to your computer, so you are guaranteed to be able to return your files.

To do this:
1) Send your unique id – and max 3 files for test decryption to mars_dec@outlook.com or anton_ivan_8989@mail.ru
2) After decryption, we will send you the decrypted files and a unique bitcoin wallet for payment.
3) Be careful! Fakes are possible in Telegram, never pay until you receive test files after decryption!
4) After payment ransom for Bitcoin, we will send you a decryption program and instructions. If we can decrypt your files, we have no reason to deceive you after payment.

or do this(If you have not received a reply by email):

1) Download and install Telegram Messanger: hxxps://desktop.telegram.org/ (for Windows, Linux, macOS)
2) Find user mars_dec
3) Send your unique id – and max 3 files for test decryption.
4) After decryption, we will send you the decrypted files and a unique bitcoin wallet for payment.
5) Be careful! Fakes are possible in Telegram, never pay until you receive test files after decryption!
6) After payment ransom for Bitcoin, we will send you a decryption program and instructions. If we can decrypt your files, we have no reason to deceive you after payment.

FAQ:
Can I get a discount?
    No. The ransom amount is calculated based on the number of encrypted office files and discounts are not provided. All such messages will be automatically ignored.
What is Bitcoin?
    read bitcoin.org
Where to buy bitcoins?
    hxxps://bitcoin.org/en/buy
    hxxps://buy.moonpay.io
    or use google.com
Where is the guarantee that I will receive my files back?
    The very fact that we can decrypt your random files is a guarantee. It makes no sense for us to deceive you.
How quickly will I receive the key and decryption program after payment?
    As a rule, within a few hours, but very rarely there may be a delay of 1-2 days.
How does the decryption program work?
    It's simple. You need to copy the key and select a folder to decrypt. The program will automatically decrypt all encrypted files in this folder and its subfolders.
I will complain about your Telegram account and mailbox's..
    God help you. You won't find us anyway. But many people will be deprived of any opportunity to recover their files.

Got your files locked with .mars virus or are they named .vyb now? Here's what to do

In many cases, users who get their systems infected with ransomware have never encountered such an infection before. This is why they believe that anti-malware software can return .mars files back to normal as soon as a full system scan is completed. Unfortunately, this is not how ransomware works – all files remain locked even after the infection is terminated. Your .vyb file virus is there as long as you are not able to decrypt your files.

MARS ransomware encrypted files

The only secure way to remove .mars extension and make data usable again is by using backups, although many victims fail to use this precautionary measure prior to malware attack. Thus, if you have no backups, it is indeed true that only cybercriminals could provide a unique key that would unlock your files. As previously mentioned, doing so is risky, as malware authors might fail to keep their promises, and you might lose your money as well.

If you are wondering what to do next and how to recover .mars files or .vyb files, not all is lost. You have a few options available, and some of them might just work:

  1. Use third-party recovery software
  2. Employ built-in Windows resources such as Windows Previous Versions
  3. Wait till security researchers find software bugs within the ransomware and provide a free, working decryption tool.

If you want to try the aforementioned methods, please check our recovery section below for details.

Ingenious methods used by cybercriminals to distribute their creations

Cybercriminals are using diverse ways to find their victims. Internet is full of malicious ads, mischievous hyperlinks, infected spam email attachments, and other deceptive wrongdoings, sitting and waiting for unaware computer users to click on them. People should stay attentive to what sites they're visiting and what files they're about to download.

During the so-called spam campaigns, developers of ransomware send out thousands of emails with infectious attachments. When such a file finds its way into a device, the contamination process is started immediately. A good way to prevent this is to always scan email attachments with powerful anti-malware tools prior to downloading.

Another popular platform for cybercriminals to hide their creations is torrent sites. Files disguised as game cheat codes, “cracks”, valid software installers could actually contain malware. Computer users should only use genuine software and should download it only from developers' websites.

Instructions for MARS virus removal

Threats, such as malware, should immediately be isolated and deleted from computer systems. The longer they're in the system, the more harm it could do. To safely remove MARS virus, use established anti-malware software like SpyHunterCombo Cleaner, and MalwarebytesMalwarebytes; these apps will automatically remove the threat and protect from such risks in the future.

MARS ransomware virus

Viruses, such as the MARS ransomware, is known for messing up the computers' system files. This could lead to devices' performance implications, such as overheating, lag, and so on. To revert whatever changes the virus might have done to the system, we strongly advise using the FortectIntego tool as it will automatically find all modified files and settings and restore them to a standard, pre-contamination state. Your device will work as efficiently as brand new.

Be the first to comment

Read in your language

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.