Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2020

How to remove Spade ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

Spade ransomware – cryptovirus that uses powerful encryption methods to prevent users from accessing their files

Spade ransomware

Spade ransomware is a data locking computer infection that originally stems from the malware family known as VoidCrypt, which was first released in April 2020. Since then, several variants have been released, each of which either uses .Void or .Spade extension, along with a combination of contact email and a unique ID, both of which are inserted during the encryption process. Speaking of which, the virus uses a combination of AES and RSA ciphers[1] to lock users' data, so the method is secure. In other words, the .spade file virus can not be decrypted at present without backups.

Besides encrypting data, the malware also drops a ransom note Read-For-Decrypt.HTA, which explains victims what happened to their files, and that they are required to pay a ransom in Bitcoin to retrieve the required decryption tool. Depending on the version, Spade ransomware drops different contact emails, e.g., rsaencrypt@tutanota.com,  rsaencrypt@protonmail.ch, VoidDeceryptor@tutanota.com, or VoidDeceryptor@protonmail.com.

Name Spade ransomware
Type File locking virus, crypto-malware
Family Void/VoidCrypt
Encryption  Malware uses a combination of AES and RSA encryption algorithms to encrypt files on the system 
File extension  Each of personal files is appended with .Spade marker, accompanied by a random character strain (ID) and contact email. Example of an affected file: picture.jpg.[VoidDeceryptor@tutanota.com][UTEO6F1MLDG30QH].Spade
Ransom note  Read-For-Decrypt.HTA is placed into each of the affected files' folders and the desktop
Contact encryptfile@protonmail.com, encryptfile@cock.li, rsaencrypt@tutanota.com, rsaencrypt@protonmail.ch, VoidDeceryptor@tutanota.com, VoidDeceryptor@protonmail.com
Data recovery There is no guaranteed way to recover files without backups. Paying cybercriminals is risky, as they might never deliver the required decryption tool. Alternatively, you can attempt to recover data using alternative methods, although keep in mind that the rate of success is relatively low
Malware removal To ensure that the infection is terminated correctly, you should employ powerful anti-malware software to perform a full system scan. In case such actions are hindered by malware, access Safe Mode with Networking as explained below
System fix To recover from the infection quickly and keep Windows operation bug-free, you can run PC repair software such as FortectIntego 

Spade ransomware is a very typical crypto-malware that functions on a very basic principle: it locks all data on the infected system and then asks victims to pay for a possibility to return it. Just as many other cybercriminals, hackers behind this virus use several methods to spread the infection around – they include, but are not limited to, the following:

  • Spam email attachments and embedded hyperlinks;
  • Fake Flash Player updates;
  • Malicious ads;
  • Software cracks and pirated installers;
  • Exploit kits and software vulnerabilities;[2]
  • Drive-by downloads, etc.

Upon infiltration, the Spade virus does not rush to perform file encryption immediately. For example, it would modify the Windows registry to retain persistence, delete Shadow Volume Copies to prevent a quick recovery, disables Firewall, shuts down several Windows services, etc. These modifications might be difficult to revert after Spade ransomware removal, so we recommend using an automatic repair tool such as FortectIntego.

As soon as malware drops all the malicious files and finishes system modifications, it will begin to look for data to encrypt – it targets the most commonly-used files, such as PDF, MS Office, Zip, TXT and many others. Typically, the encryption process lasts a short period of time, as the attackers only encrypt a few bites of the original files to prevent users from stopping it.

Spade ransomware virus

While many ransomware strains attach a word or a randomized string as an extension after encryption, the Spade file virus performs this process in a slightly different manner (although this method is adopted by many other crypto-malware families, including GNSEking, and others). In addition to appending an extension, the malware also modifies the name of each file in the following pattern:

Original_name.extension.[contact email][ID].Spade

Suchlike modified data can no longer be opened and requires a unique key that is the help of hackers' servers. 

You should not attempt to remove the Spade ransomware extension or modify the file name to its original one, as it will not help you to recover your data. Instead, you should delete the infection from the system with anti-malware software (we recommend SpyHunterCombo Cleaner or MalwarebytesMalwarebytes).

.Spade file virus: data recovery options

As mentioned above, users infected with ransomware will soon notice that they are unable to open files that are appended with the .Spade extension. Despite the popular belief, an anti-malware scan will not provide any solutions to this issue, as security software is simply not designed for that. Hence, ransomware is one of the most dangerous infections in the wild, as its termination from the infection PC would not revert modifications performed to .spade files.

Thus, many users may ask how to recover .spade files without backups. Unfortunately, the answer is not that simple. Upon infiltration, users will be presented with the following message embedded within a Read-For-Decrypt.HTA popup:

Your Files Has Been Encrypted
All Your Files , Documents , photos , Databases and other important files are encrypted
And have Extention .Spade
If You Need Your Files You Have To Pay
You can Send 1 Little File Less Than 2MB for Test (The Test Files Should not be Databases Large Excel Sheets or Backups
After 24 Hour Decryption Price Will be Doubled so You Better Contact us as soon as possible
Using Recovery Tools or 3rd Party Applications is useless you can try tough
1- Contact Email on Files And Send ID on The Files Then Do agreement on a Price
2- Send Some Files for Decryption Test ( Dont Pay to Anyone Else who is Not Able to Decrypt Your Test Files!)
After Geting Test Files Pay The price in Bitcoin And Get Decryption Tool + RSA key
Your ID :-
our Email :VoidDeceryptor@tutanota.com
In Case Of No Answer :VoidDeceryptor@protonmail.com

Malicious actors are attempting to convince users to contact them and negotiate the ransom payment amount. They even offer a free .spade file decryption service that would prove that the decryption tool is actually working. Nonetheless, keep in mind that these people are cybercriminals and can not be trusted.

Security experts[3] recommend staying away from criminals in most cases, as there is never a guarantee that they will keep the promises. Nonetheless, paying them might sometimes be the only way to recover .spade files.

Instead, you can choose alternative methods for data recovery – the built-in Shadow Copies or third-party recovery software might sometimes be helpful. If you are interested in trying these solutions, you can check our recovery section below this article. Nonetheless, you should keep in mind that .spade file recovery can only succeed under particular circumstances. Finally, you can also wait until researchers provide you with a working, free decryption tool, although this scenario might also never happen.

Spade ransomware infection

Remove Spade ransomware using anti-malware software to secure the incoming files

While some crypto-virus infections might self-delete, you should not risk and ensure that a proper Spade ransomware removal is performed with the help of powerful anti-malware software. Otherwise, all the incoming files might be encrypted as well. Additionally, some ransomware strains were observed to insert data-stealing components or other malware onto the affected system – users could face serious privacy risks due to this.

However, you should not remove Spade ransomware just yet if you have no backups to restore your files with. First, you should copy all the affected data to another medium, such as a USB flash (note that ransomware-encrypted files do not hold any malicious code, so are safe to copy over) and only then perform a full system scan with your anti-malware.

Finally, attempt to restore .spade file virus files with the help of alternative solutions we provide below. 

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.