My Decryptor ransomware encodes your data to extort you

My Decryptor ransomware (also found as Magniber) is a file-encrypting virus that infects victim’s computer and encodes its files. According to the analysts, it is incredibly similar and possibly linked to Cerber ransomware[1]. Once the virus is in the system, it creates a “_HOW_TO_DECRYPT_MY_FILES__.txt” file as a ransom note. It provides further information on how to receive a decryption key.
Firstly, the user has to download and install Tor browser[2]. Later, open a personal link that leads to a Bitcoin account address and pay a ransom as fast as possible. This particular ransomware variant asks to pay 0.2 BTC which is approximately 1129 USD. If the victim fails to pay the requested amount of money in 5 days, the value of the ransom increases.
Besides, cybercriminals submit several temporary links that victim can use without downloading Tor browser. Thus, the researchers state that Cerber (which also uses the same payment page) and My Decryptor virus might be developed by the same group of hackers.
My Decryptor malware can be identified by the extension mark. Usually, it adds .[7 random chars] or .kgpvwnr file extension at the end of the encrypted file-name. Developers use the same method as encrypting military-grade secrets; therefore even IT professionals aren’t able to decrypt the files.
However, cybercriminals shouldn't be trusted. Dieviren.de team says[3] that there are no guarantees that the developers will provide a decryption key after the payment rather than ask for even more money. We recommend to remove the ransomware using FortectIntego security software and use the backup copies instead.

Ransomware is distributed through malicious attachments
My Decryptor virus is spotted spreading through malicious emails that contains an infected attachment. Once the user opens the file, it intrudes the computer and encrypts the documents, pictures, and other valuable data. Unfortunately, the only way to get access to your records is using the decryption key.
Another common distribution way is through the illegal downloads or ads from suspicious websites. Usually, the user might get redirected to malicious websites when clicking on rogue advertisements. Hence, we advise you to avoid clicking on ads. If you get redirected to unreliable sites immediately uninstall potentially unwanted programs (PUPs) or plug-ins and never visit that website again.
Other useful tips to avoid the ransomware:
- Avoid clicking on ads, because the appealing appearance may lure you into a scam or redirect to malicious websites.
- Download applications only from official distributors and use direct links.
- Always backup your files to protect yourself from paying the ransom for cybercriminals.
- Keep your software updated to eliminate the vulnerabilities that hackers take advantage of when developing all types of malware, adware, and other malicious programs.
The removal of My Decryptor ransomware
Our team suggests you not to try to remove infected files manually because it can lead to even more damage. Be aware of the consequences of My Decryptor ransomware attack and choose a reliable security software to remove the virus.
You should reboot your computer to Safe Mode and run a full system scan with your chosen security software. We strongly recommend using FortectIntego, SpyHunterCombo Cleaner and MalwarebytesMalwarebytes programs in order to remove My Decryptor virus and maintain your computer’s security in the future.
Did this guide help?
Be the first to comment