Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jan 2018

How to remove Server ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

Cryptomix is back with Server ransomware virus

Server ransomware ransom note

Server ransomware is a new version of a CryptoMix virus.[1] This file-encrypting malware uses .SERVER file extension to make files inaccessible on the targeted computer. Following the encryption, crypto-virus drops a ransom note called _HELP_INSTRUCTION.TXT where crooks ask to send victim’s ID number in order to learn more about data recovery possibilities.

Server Cryptomix ransomware uses AES encryption cipher to corrupt various documents, audio, video, image and similar data. However, it not only adds a new file extension but also renames the files with a random string of letters and numbers. Therefore, it makes a total mess.

Unfortunately, files encrypted by Server virus cannot be decrypted yet. Developers use a sophisticated encryption which hasn’t been cracked by malware researchers. However, following the instructions provided in the ransom note is still not advisable:

Hello!
Attention! All Your data was encrypted!
For specific informaiton, please the send us an email with Your ID number:
serverup@keemail.me
serverup@protonmail.com
serverup1@yandex.com
serverup3@yandex.com
ann.c@iname.com
Please the send email to all email addresses The! We will help You as soon as possible !
IMPORTANT: DO NOT USE ANY PUBLIC SOFTWARE ! IT MAY DAMAGE YOUR DATA FOREVER!
DECRYPT-ID- [id] number

The name and the content of the ransom note are almost the same as we have already seen in the notes used by previous Cryptomix versions. The only significant change is new contact email addresses which are changing from one version to another. As you can see in the quoted ransom note, criminals now use these five email addresses:

  • serverup@keemail.me
  • serverup@protonmail.com
  • serverup1@yandex.com
  • serverup3@yandex.com
  • ann.c@iname.com

Security specialists want to discourage you from contacting developers of the Server Cryptomix virus. You will be asked to pay several hundreds of dollars in Bitcoins.[2] However, it does not guarantee that you will be given a decryption software. There were many cases were hackers disappeared or blackmailed into paying more money.

Therefore, instead of risking to increase your damage, you should remove Server ransomware from the computer. In order to do it safely, you have to use a professional security software and let it terminate all suspicious components from the system.

We recommend FortectIntego for the Server ransomware removal. However, you can employ any other professional tools. If you cannot download, install or run security program, please follow the guide given at the end of the article to disable the virus first.

Image of Server Cryptomix ransomware virus

Spam emails might include ransomware executable

Ransomware viruses typically spread via malicious spam emails. With the help of social engineering, cyber criminals trick people into opening an obfuscated attachment which contains malware payload.

However, security specialists from avirus.hu[3] advise being careful with software downloads and updates, click-bait ads and other suspicious links, buttons or pop-ups found on the web. “Too good to be true” offers and security alerts usually include malicious content.

Finally, you should also keep your software updated and protect your PC with reputable antivirus. Additionally, creating backups is also needed. In case of the cyber attack, you won’t lose the most important data.

Delete Server ransomware from the machine correctly

To remove Server virus from the computer, you have to obtain a reputable malware removal software and scan the system with it. The 2-spyware team recommends using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes because these tools are powerful enough to find and delete ransomware-related entries entirely.

However, Server Cryptomix removal might be complicated due to virus’s structure and functionality. Thus, before you start, you should reboot the device into Safe Mode to disable the virus. Follow the instructions below:

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.