Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2020

How to remove Snatch ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Snatch ransomware is a crypto virus that attacks high-profile targets like SmarterASP.NET hosting provider

Snatch ransomware

Snatch ransomware is a file locking virus that does not have any connections with other strains. While it is not as active as more prevalent threats like Djvu or Phobos, virus developers released nine variants since Snatch ransomware debut back in December 2018, all appending different extensions after data encryption with AES cipher, including .snatch (original), .FileSlack, .jupstb, .cekisan, .icp, .jimm, .FKVGM, .EGMWV, .hceem, .cbs0z, .ohwqg and .qensvlcbymk, .clhmotjdxp.

After file encryption process, Snatch virus drops a ransom note Readme_Restore_Files.txt (although later versions were named differently) and asks users to visit Tor-based website or contact crooks via mBoristheBlade@protonmail.com email (again, differs based on the version). In the note, hackers state that they want victims to pay between 1 to 5 Bitcoin for file redemption, although this sum might vary depending on negotiations. At the time of the writing, Snatch ransomware decryptor had not been developed yet, although paying cybercriminals is not an ideal solution, either.

Snatch ransomware first targeted regular users, mainly by using spam emails. Since March 2019, malware authors started naming their ransom notes based on the infected company name, meaning that they started aiming at corporations instead. The most recent incident involves SmarterASP.NET – Snatch ransomware encrypted data of hosting provider's customers and also affected the company itself. According to news reports, all the affected clients had their files appended with .kjhbx extension.[1]

Name Snatch ransomware
Type Cryptovirus
First spotted The malware strain first showed up in December 2018
Distribution Malware developers use targeted spam email campaigns in order to infect victims (corporations mainly)
Encryption Snatch uses sophisticated symmetric encryption method AES
File extension Upon infection, malware scans the host machine for files to encrypt and appends one of the following extensions (depending on the version): .FileSlack, .jupstb, .cekisan, .icp, .jimm, .FKVGM, .hceem, .cbs0z, and .ohwqg, .qensvlcbymk
Ransom note Ransom note is dropped into each of the folders where encrypted files are located. Over time, the name of the note chanced, such as: Readme_Restore_Files.txt, Restore_[random]_Files.txt, RESTORE_[random]_DATA.txt, DECRYPT_[random]_FILES.txt, HOW TO RESTORE YOUR FILES.TXT
Contact imBoristheBlade@protonmail.com, gomer@horsefucker.org, gomersimpson@keemail.me, johnsonwhate@protonmail.com, johnsonwhate@tutanota.com, A654763764@qq.com, decrypter02@cumallover.me, piterpen02@keemail.me, jimmtheworm@dicksinmyan.us, sqlbackup3@mail.fr, doctor666@mail.fr, support911@cock.li, xilttbg@tutanota.com
Decryptable?

Unfortunately, Snatch ransomware files are currently not decryptable. Other options to recover files include:

  • Restoring from backup
  • Using data recovery software
  • Paying cybercriminals (not recommended)
Removal Before attempting file recovery, users should make sure that malware is eliminated from their machines. For that, they should scan their computers with anti-virus software (Safe Mode)
Optimization To fix virus damage, use FortectIntego

Snatch ransomware is distributed with the help of various tricks used by cybercriminals. However, user interaction is typically essential in order to finalize the malicious code execution on the computer. For example, hackers send out thousands of fake emails to users with attachments that, once executed, infect the machine. Additionally, .snatch file virus might be delivered with the help of exploit kits,[2] weak login credentials, fake updates, hacked or cracked installers, etc.

Once executed, the Snatch ransomware payload shuts down several Windows processes, contacts the Command and Control[3] server, and spawns new elements which assist malware with file encryption and the full infection of the PC. For example, modified Windows registry keys ensure that .snatch ransomware is booted with every system start.

The ransom note states the following:

All your files are encrypted
Do not try modify files
My email imBoristheBlade@protonmail.com

As evident, Snatch ransomware developers do not provide much detail about the attack, apart from the contact address and a warning about file modification. It is known, however, the hackers ask for 1-5 Bitcoin for decryption software from their victims.

Snatch ransomware virus

Regardless of the price, bad actors should not be contacted, as the loss of money is plausible. Additionally, it will prove that the business model they operate is working and continue to try blackmailing other people. Therefore, rather remove Snatch ransomware from your machine and then proceed with file recovery procedure.

Unfortunately, the only safe method of restoring files is by using backups. If you do not have any prepared, you can try alternative solutions – we provide instructions below. Also, you could keep a copy of data and wait until security experts create an official .snatch file virus decryptor.

Finally, experts[4] recommend scanning the machine with FortectIntego or similar software, and it will reverse the damage done by Snatch virus.

Ransomware is distributed with the help of spam emails, as well as other methods

As we already mentioned above, ransomware authors rely on users to make a mistake while browsing the internet and simply get tricked to install malware. Therefore, we advise to take the following actions which could prevent you from unconsciously installing malware:

  • Employ reputable anti-virus software with real-time protection function;
  • Patch your software and the operating system as soon as updates are available. This will help you not only keep your apps fresh but will also prevent hackers from using software vulnerabilities;
  • Do not treat every email you receive casually. Be aware that those with attachments (.doc, .pdf, .html, .txt, etc.) are the most dangerous. Scan the attachment with anti-malware software before opening. Additionally, deceptive hyperlinks can lead to malware-laden sites;
  • Use strong passwords and VPN when using Remote Desktop Protocol;
  • Avoid high-risk websites, such as porn, gambling, torrent, file-sharing, and similar.

Snatch ransomware attacks hosting provider SmarterASP.NET

Eliminate Snatch ransomware virus from your PC as soon as possible

If you noticed that your files are encrypted with .snatch extension, you should be aware that ransomware might be not the only threat that is established on your PC. Quite often, malware is set to download more malicious applications (backdoor), so victims end up with such infections like data-stealers, crypto-miners, spyware, and other malicious applications.

For that reason, Snatch ransomware removal is essential for computer security and virtual safety. Because malware is a complicated piece of software that affects multiple areas of the system, we highly recommend not to try to remove Snatch ransomware manually.

Instead, rely on security software that can detect and eliminate the threat. Be aware that, because the malware is entirely new, not all AV engines like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes might catch it, so scanning the computer with several programs might be a good idea. After the procedure make sure to repair any corrupted or altered parts and remove Snatch ransomware virus damage with FortectIntego.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.