Trojan.Encoder.6491 is the first ransomware variant written in Google’s Go programming language
Trojan.Encoder.6491 virus is a newly released ransomware that has been defeated just after three days since its first emergence. This unsuccessful ransomware example is coded using Go language, and reportedly is distributed in the form of Windows_Security.exe file. If you follow computer security news, you probably know that ransomware authors love to use a new technique to encrypt victim’s files quickly and silently – they launch a fake screen that looks like Windows Update screen, and in the meantime, corrupts all files on the system. Trojan.Encoder.6491 ransomware uses the same technique and locks the files with advanced encryption standard (AES cipher). The virus encrypts files by file extensions they have, and it targets more than 140 different file types. Once it finds target file, encrypts it and appends a .enc file extension to it. Please do not confuse this virus with TrueCrypter or Crypt0L0cker viruses, which also attach the same extension to encrypted files. However, Trojan.Encoder.6491 malware does not only append new file extension but also distorts the filename by applying the Base64 algorithm. This modification does not allow the victim to identify corrupted files.
After applying all changes to victim’s files, the virus displays a ransom note, which contains all information about the data encryption and decryption processes. The victim is asked to pay around 25 USD in Bitcoins, which is 0.052300 BTC. There is also an e-mail provided at the end of the note for those who have any questions – helpmedecrypt@protonmail.com. However, if your files have been encrypted by Trojan.Encoder.6491 ransomware virus, do not waste your money and better use it for a better purpose, for example, protection of your computer system. We have some good news for you – this virus has some flaws that allows victims to decrypt .enc files. The decryption tool has not been released publicly yet, but soon it is going to be available to everyone. However, you should try to decrypt data only after removing the virus. To remove Trojan.Encoder.6491 malware, use FortectIntego software or the one you already have. Make sure you update it first to ensure a successful Trojan.Encoder.6491 removal!

How does this ransomware infect computers?
You can infect your computer with this ransomware by opening random email letters and files attached to them. Sending tons of malicious email attachments to victims is the primary ransomware distribution method, so before opening an email that is sent by an unknown sender, think twice. We bet that you do not want to compromise the computer system by accident, so stay away from Spam and Junk sections in your email, but keep in mind that some malicious letters can bypass these email filters and go straight to the Inbox.
Ransomware can infect unprotected computers as soon as the victim clicks on a malevolent ads or visits an infectious website that contains an exploit kit. Avoid such dangers by installing a trustworthy anti-malware software.
Remove Trojan.Encoder.6491 virus and decrypt .enc files
Please use Trojan.Encoder.6491 removal instructions provided below to prepare your PC before you run an anti-malware software. This way, the virus will be deactivated, and anti-virus software will be able to do its job. To remove Trojan.Encoder.6491, use one of the programs we recommend, but please, do not try to uninstall this virus manually. You can leave some malicious files on the system and make it vulnerable to further malware attacks!
Did this guide help?
4 comments
Donald
Thats not nice. Why dont that "company" let all victims use it? Not nice.
Controlla
I am so lucky... i had a backup, so recovered my files with a help of it, just had to remove Trojan.Encoder.6491 virus first.
Tunne
Cant run my antivirus to remove this cr4p!!!
Killah155
start it in a safe mode first