Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2018

How to remove RansomAES ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

RansomAES – ransomware targeting Korean PC users

RansomAES virus

RansomAES is a ransomware[1] virus that has been developed to encrypt people's files and then urge them to pay a ransom. It uses AES cryptography algorithm and targets Korean PC users. The data encrypted by RansomAES can be easily recognized by a .RansomAES file extension, as well as READ ME.txt ransom note. The victims are supposed to email hackers to fbgwls245@naver.com or powerhacker03@hotmail.com for payment instructions. At the moment of writing, victims are expected to transfer 100,000 KRW in Bitcoins.

RansomAES
Classification Ransomware
Related files RansomAES.exe, READ ME.txt
   
File extension .RansomAES
Email address fbgwls245@naver.com or powerhacker03@hotmail.com
Decryption method AES cipher
Main dangers It locks files and renders them useless unless the victim pays the ransom. Thus, the two main dangers are the loss of data and money. Besides, it may open backdoor to other malicious programs. 
Elimination process Manual removal is not possible. Download FortectIntego and run a full system scan with it to get rid of ransomware infection. 

The crooks behind RansomAES virus rely on diverse ransomware distribution strategies, including but not limited to malicious spam email attachments and rogue software downloads. If the victim executes the payload (RansomAES.exe), the virus unravels and targets Windows GUI with Intel 386 or later chipset.[2] Earlier version won't be attacked.

It uses AES cipher to render people's files useless. It locks them with a hard code and generates a unique victim's identifier and corresponding file decryptor. In the meantime, the user of the compromised PC is presented with files locked with .RansomAES file extension and the READ ME.txt ransom note, which is written in the Korean language.

The note does not contain much information, except that it informs the victim about an attack and provides contact information. Currently, RansomAES ransomware virus developers can be intercommunicated via the following email addresses:

  • fbgwls245@naver.com
  • powerhacker03@hotmail.com

According to ransomware researchers, it demands a ransom in Bitcoins. At the moment of writing, the sum ranges from 100,000 to 500,000 KRW, which is equal to 0.010 to 0.051 Bitcoin.

Despite the size of the redemption, we would not recommend you to pay it. Supporting hackers is not a good idea, is it? Besides, transferring your money to crooks does not prove to ensure that you'll be provided with a RansomAES decryptor so that you can be left without both data and money.

In case of attack, we would strongly recommend you to download FortectIntego, SpyHunterCombo Cleaner, MalwarebytesMalwarebytes or another reputable anti-virus, run a full system scan with it, and perform a complete RansomAES removal.

It's very likely that you won't be allowed to remove RansomAES virus easily. The malicious software can use malicious processes to block anti-virus and evade easy removal. Therefore, you may need to restart your PC into Safe Mode with Networking.

As soon as you get rid of the malware, try to retrieve your files using alternative methods. Most of them require the installation of third-party data recovery programs. Our top selections are provided at the end of this article.

RansomAES virus target Korean PC users

Computers get infected after opening malicious spam email attachments

Malicious spam email messages with ransomware-infected attachments are the most popular virus distribution technique for more than a decade. Less tech-savvy people lack knowledge about cyber security and quickly fall for opening emails that camouflage IRS, Amazon, Microsoft, and other well-known companies.

The ransomware is executed as soon as the potential victim opens a Word, PDF or Zip file. However, NoVirus.uk[3] specialists indicate the following techniques that are commonly used to spread ransomware as well:

  • Exploit Kits;
  • Fake software updates;
  • Illegal or obfuscated program in file-sharing sites or networks;
  • Malicious advertisements;
  • Hacked Remote Desktop Services (RDS).

Therefore, you should be careful with content you click or download online. Besides, make sure to keep your anti-virus and OS up-to-date.

RansomAES removal options

Manual ransomware removal is practically impossible. Any attempt to restart your PC, change registry entries or rename encrypted files can lead to permanent data loss. Therefore, we would strongly recommend you to perform automatic RansomAES removal with FortectIntego or another robust security tool.

The guide given below will explain you in details how to remove RansomAES if malicious processes keep your anti-virus disabled. Besides, you will find a list of data recovery possibilities down below. However, make sure that the ransomware is entirely deleted before any attempts to decrypt your files.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.