Ppam ransomware – a crypto virus that demands $700 ransom in Bitcoin for file decryptor

Ppam ransomware is a dangerous PC infection that locks up users' files and then demands a ransom to be paid for the decryption key. The malware was first spotted in mid-January 2019 and is a variant of the GlobeImposter 2.0 family. The virus usually gets to victims once they open contaminated email attachments, click on unsafe links, do not adequately protect the RDP, download malicious executables, and similar. Once installed, Ppam virus identifies files of interest (mostly pictures, documents, music, videos, etc.), and encrypts[1] them with the help of RSA + RC4/AES ciphers and appends .ppam file extension. It then scatters a Restore-My-Files.txt ransom note into every affected folder, informing the users about what happened to their machine. In order to recover data, users are asked to pay 0.19 Bitcoin, which is worth of $700 for the decryption key.
| Name | Ppam |
| Type | Ransomware |
| Family | GlobeImposter 2.0 |
| Ciphers | RSA + RC4/AES |
| Ransom note | Restore-My-Files.txt |
| Ransom size | 0.19 BTC |
| Contact | fileshelp@cock.lt |
| Decryptable? | No |
| Elimination | Use anti-malware software like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes |
Before Ppam ransomware encrypts the data, it performs various changes to the infected computer, including:[2]
- Changes the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce;
- Creates and object related to FileZilla (an FTP service);
- Attempts to delete Shadow Volume Copies;
- Creates several files in user/program directory;
- Etc.
All the modifications are needed in order for the virus to run and operate properly. Due to such a complex activity, manual Ppam ransomware removal becomes almost an impossible task for a regular user. Therefore, the use of professional anti-malware software like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes is recommended because it can recognize[3] the virus and eliminate it.
Once system modifications are complete, Ppam ransomware locks data and drops a ransom note into each of the affected folder and the desktop which states:
Your files are Encrypted!
For data recovery needs decryptor.
How to buy decryptor:
—————————————————–
1. Download “Tor Browser” from https://www.torproject.org/ and install it.
2. Open this link In the “Tor Browser”
http://huhighwfn4jihtlz.onion/sdlsnhtjwbhr
Note! This link is available via “Tor Browser” only.
————————————————————
Free decryption as guarantee.
Before paying you can send us 2 file for free decryption.
————————————————————
alternate address – http://isb5f7dxc6gjpprt.onion/sdlsnhtjwbhr
As evident, users are sent to a web page that can only be accessed with the help of Tor browser only. Once there, attackers explain that to retrieve the access to their files, they need to pay $700 in Bitcoin into a specified address. Additionally, .Ppam file virus authors offer a free test decryption service, which is very popular among cryptovirus developers because it might give victims a fake sense of security.
Nevertheless, it is all in vain, as bad actors might merely take the money and never send the decryptor. Additionally, it would encourage criminals to make more malware and increase their scale of operation. Therefore, do not contact hackers, remove Ppam ransomware instead and then try alternative file recovery methods.
If you had backups, you would be able to get all your data back. However, if not, then chances of recovery are quite slim. As a last resort, you can try using third-party recovery software – we have a few suggestions below.

Ransomware distribution techniques
Evidently, cybercriminals are usually using multiple distribution methods in order to increase the scale of the attack. It is in their best interest of doing so because more infections mean a higher chance of retrieving ransom. Of course, such actions are entirely illegal and are punishable by low. Unfortunately, tracking down malicious actors proved to be quite difficult, although not impossible.
Because ransomware is one of the most dangerous malware out there, it would be best to reduce the chance of infection to a minimum. Experts[4] recommend the following:
- Download and install security software with real-time scan feature and keep it updated;
- Create backups regularly;
- Beware of spam emails: attachments that ask you to enable macro are most certainly infected, so are the deceptive hyperlinks;
- Protect RDP connection with a secure password and use a VPN;
- Avoid downloading cracked or repacked files;
- Refrain from visiting gambling, porn, file-sharing, or similar high-risk websites;
- Patch your system and software as soon as updates are released.
Eliminate Ppam ransomware with the help of security application
As we already mentioned above, regular users should never try to remove Ppam ransomware manually, as it is too much complicated of a task. Instead, victims should rely on anti-malware applications that could safely detect and get rid of Ppam virus.
Ppam ransomware removal might be prevented by its functionality. In such a case, you should enter Safe Mode with Networking, as explained below. From there, you can perform a full system scan using FortectIntego, SpyHunterCombo Cleaner or other security software, as the virus' functionality will be disabled in a secure environment.
Be aware that you have to eliminate the malware before you proceed with file recovery, or backup files will be encrypted as well!
Did this guide help?
Be the first to comment