ReadMe ransomware is a type of malware that locks personal files

ReadMe ransomware is yet another cryptovirus that encrypts data in order to demand money from its victim. If the user wants to get a unique decryption key, cybercriminals behind the attack ask to pay the particular amount in cryptocurrency and contact them afterward. This infection name can be associated with variants of malicious software called BitRansomware or LolKek virus because these two threats use the particular .ReadMe extension to mark files after the encryption procedures.
ReadMe file virus encrypts all personal files with the help of a powerful encryption algorithm and appends .readme extension to each of them. For example, a picture “one.jpg” is turned into “one.jpg.readme”, making suchlike data unusable. It can affect images, video, audio files, documents, archives, databases, so there is a reason for the money demands. Once encryption is done, the malware drops a ransom note Read_Me.txt, which is placed on the desktop and all affected folders. The file contains further instructions for the victim, but paying shouldn't be considered as the best solution.
| Name | ReadMe ransomware |
|---|---|
| Type | Cryptovirus, ransomware, files locker |
| Ransom note | Read_Me.txt |
| File extension | All encrypted files get .readme extension, hence the name of this threat family |
| contact Email address | filessupport@cock.li |
| Symptoms | After the encryption is done, the victim can't open locked files with .readme extension. The user gets a ransom message on the desktop and in affected folders that encourages to pay up |
| Distribution Methods | Ransomware spreads through infected email attachments that contain macro viruses, malicious sites, and unsafe torrent websites, pirated programs, and files |
| Elimination | Get rid of ReadMe virus by running a full system scan with reputable anti-malware software that detects[1] the infection |
| System fix | If you found OS not to be working properly after malware removal, scan it with FortectIntego to fix system file damage |
In some cases, the victims get a very short ransom note from the ReadMe ransomware developers. In that text file, cybercriminals only give a link to create a ticket and email address – filessupport@cock.li – if the user wants to recover files by paying these criminals.
A longer ransom note informs users about the encryption and demands money. Cybercriminals try to scare their victim by saying that the only way to recover data is to pay them with Bitcoins or another cryptocurrency.[2] They provide a URL that the victim should open in the TOR browser. According to hackers, the user will see further instructions in that link.
The full ReadMe file virus ransom note looks like that:
Attention!
All your files, documents, photos, databases and other important files are encrypted
The only method of recovering files is to purchase an unique decryptor. Only we can give you this decryptor and only we can recover your files.
The server with your decryptor is in a closed network TOR. You can get there by the following ways:
——————————-
1. Download Tor browser – hxxps://www.torproject.org/
2. Install Tor browser
3. Open Tor Browser
4. Open link in TOR browser: hxxp://54fjmcwsszltlixn.onion/?VHIKWYZL
5. Follow the instructions on this page——————————-
On our page you will see instructions on payment and get the opportunity to decrypt 1 file for free.
Alternate communication channel here: hxxp://helpqvrg3cc5mvb3.onion/
According to the information provided by the developers of ReadMe ransomware, the price of the decryption tool is 0.085 BTC. It means that the victim should pay about 1000 USD in two days. If the user fails to send money in two days, the ransom will increase to 0.17 BTC – about 2000 USD according to the current exchange rate.

Of course, you shouldn't listen to cybercriminals. Even though they are right about the unique encryption key, paying the ransom is not the best option. You should remove ReadMe ransomware from the system and rely on backups if you want to recover important data. The easiest way to get rid of this threat is by using SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or any other powerful AV tool.
Moreover, even after the successful ReadMe ransomware removal, you should fix the system issues with a repair tool because the anti-malware program only removes the threat. We recommend using FortectIntego as one of the solutions for virus damage. After that, try different methods to recover your files. We listed a few of them at the bottom.
Ways to recover .readme files after encryption
Unfortunately, ReadMe file virus encrypted files can't be decrypted when the official tool is not released yet. You can try to recover some of the data with third-party tools in some of the cases. It is only possible after the successful ransomware[3] removal process.
That's why many people start to search for the .readme files recovery solutions. Some of them even decide to pay the ransom but cybersecurity experts[4] say that you shouldn't cooperate with malicious actors. Hackers can deceive you and demand more money or run away without giving the decryption key for those .ReadMe files.

You should remove the .readme file virus from your computer and try alternative ways to recover data. The easiest way to retrieve important files is by relying on file backups. But even if you don't have backups, there are other solutions too. We explained all the possible methods at the bottom of this article.
If you want to avoid any viruses in the future, you should act more carefully on the internet. Ransomware is spreading through infected email attachments, malicious advertisements, torrent websites, or other unsafe sources, so you might catch ReadMe ransomware virus without even noticing.
ReadMe ransomware removal and .readme file recovery
As we already mentioned, you should remove ReadMe ransomware as soon as possible and only then try to recover your personal data. The only way to properly get rid of this infection is by using a professional security program that has a powerful scanner, virus removal possibilities, and the latest virus database. We recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
If the ReadMe ransomware removal looks impossible because it infringes the antivirus program and keeps it disabled, you should restart Windows OS and reboot it in Safe Mode with Networking. We provided useful instructions above.
Only after the ReadMe ransomware virus is removed, you can try several methods to recover .readme files. Unfortunately, there is no free decryption tool for this infection. But you can recover data by using backups. Even if you don't have proper copies of your files, there are other ways to retrieve at least some of your files. We listed alternative data recovery methods at the bottom of this article. Remember to check for additional issues and virus damage with tools like FortectIntego.
Did this guide help?
Be the first to comment