Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2023

How to remove Tuslamon ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

Tuslamon ransomware is malicious software made by cybercriminals to extort money from victims

Tuslamon ransomware is a malicious program that specializes in extorting money from its victims. Once it gains unauthorized access to a targeted device, it can move laterally through the network and cause significant harm. The virus's primary objective is to encrypt all the files on the compromised system, rendering them inaccessible. One of the most noticeable indicators of a Tuslamon ransomware attack is that all the files are appended with a specific extension, in this case – “.tuslamon.”

After the ransomware completes the encryption process, it drops a ransom note named “HOW TO DECRYPT FILES.txt.” The note instructs victims to contact tuslamon@protonmail.com to restore their locked files. The cybercriminals behind the attack also provide a deadline for the money to be transferred. In these cases, they usually threaten to delete the key that could unlock the data. Luckily, there are a few alternatives you could try.

Name Tuslamon virus
Type Ransomware, file-locking malware
File extension .tuslamon extension is appended to every personal file on the system
Ransom note HOW TO DECRYPT FILES.txt
Contact tuslamon@protonmail.com
Malware family Xorist
File Recovery The only method to recover files is through data backups. If such is not accessible, or if it has also been encrypted, your options for recovery are extremely limited, although we recommend trying them
Malware removal Disconnect the computer from the network and internet and then perform a full system scan with SpyHunterCombo Cleaner security software
System fix After malware infects a system, it can corrupt several important files, which often leads to crashes, errors, and other issues. FortectIntego PC repair is an effective solution to automatically replacing any corrupted system files

Ransomware is a global threat to users

Given the success that ransomware attacks have had in the past, especially in the wake of a global pandemic, it seems that this trend is likely to persist. Therefore, it's crucial for both businesses and individual computer users to take all necessary measures to protect their systems from this significant threat.

Tuslamon ransomware is a member of the Xorist malware family, which was first introduced in 2012. Since then, the virus has undergone several revisions, infecting thousands of users around the world. Its previous versions include Korya, Zery, Crysphere, Feg, and many others.

There are various ways for malware to infiltrate the computers of everyday users, such as software vulnerabilities, spam emails, malicious advertisements, fake updates, and more. Once it gains access, the virus's primary objective is to locate and encrypt all non-system files on the Windows computer and other devices linked to the compromised network. In some cases, cybercriminals may even use management software installed locally to attack backup systems.

To ensure success in its mission, Tuslamon ransomware makes numerous modifications to the system before commencing the data-locking process. These changes may include deleting Shadow Copies, creating new tasks, modifying the registry, dropping malicious files, and more. Once these modifications are made, the virus employs the TEA encryption algorithm or another variant (depending on the version) to encrypt the targeted files.

The ransom note is written in Portuguese

In the past, Xorist variants used various languages in the ransom notes, including English, Russian, and others. In this case, the ransom note is written in Portuguese, with no English translation provided. This might indicate that the attack is targeted towards users/companies from particular areas where the language is spoken, although this is not always the case. The message reads:

Todos Dados/Backups foram criptografados
a unica forma de obter os dados em seu perfeito estado é
entrar em contato no Email:   tuslamon@protonmail.com
Dados em perfeito estado em até 1 hora
prazo para o contato [DATE]  ID-[ID]
(N = NÂO)
– N delete arquivos trancados
– N não renomeie os arquivos trancados .cobaltstricker
– N  não poste esta mensagem em nenhum site
  nem denuncie pois podem bloquear este email.

The message claims that all files and the backup databases have been encrypted, and the cybercriminals' contact details are provided. There is also a date given, probably the deadline for paying the ransom. In circumstances like these, the attacks then refuse to negotiate further or disclose sensitive information they have stolen during the attack, which is yet another method to extort money.

We don't recommend giving into these extortion methods and avoiding all contact with cybercriminals. Instead, we recommend following the instructions below to remove Tuslamon ransomware from the system and use alternative methods for data recovery.

Malware removal

It's understandable that users become highly concerned when they discover that their files have been encrypted by ransomware and are no longer accessible. However, reacting with panic will not help since the infection has already occurred. In fact, panicked victims may make mistakes that result in even more data loss. It's crucial to take the appropriate steps in the right order to prevent further damage.

To establish a remote connection with an infected Windows device, cybercriminals use what's known as a Command & Control server. Since this communication occurs over the internet, it's essential to disconnect the machine from any networked connections. If you need to do this quickly and easily, follow these steps:

  • Type in Control Panel in Windows search and press Enter
  • Go to Network and InternetNetwork and internet
  • Click Network and Sharing CenterNetwork and internet 2
  • On the left, pick Change adapter settingsNetwork and internet 3
  • Right-click on your connection (for example, Ethernet), and select DisableNetwork and internet 4
  • Confirm with Yes.

Once you have disconnected the computer, you can proceed with eliminating the ransomware. To do so, you will need to use professional security software such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. If the malware is attempting to obstruct the removal process, access Safe Mode and run a thorough system scan from there to ensure that the malware is completely removed from the computer. It's important to note that before doing this, you should update your security software to the latest version.

Windows 7 / Vista / XP

  1. Click Start > Shutdown > Restart > OK.
  2. When your computer becomes active, start pressing the F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  3. Select Safe Mode with Networking from the list.Windows XP/7

Windows 10 / Windows 8

  1. Right-click on the Start button and select Settings.
  2. Scroll down to pick Update & Security.
  3. On the left side of the window, pick Recovery.
  4. Now scroll down to find the Advanced Startup section.
  5. Click Restart now.
  6. Select Troubleshoot.
  7. Go to Advanced options.
  8. Select Startup Settings.Startup settings
  9. Click Restart.
  10. Press 5 or click 5) Enable Safe Mode with Networking.

We also advise scanning the system with FortectIntego PC repair utility, as some system files might get corrupted due to malware infection. This way, you can get rid of troubles such as BSODs, crashes, errors, and other stability issues without reinstalling the operating system.

Data recovery

The main objective of the Tuslamon virus is to encrypt all non-system files on any accessible Windows machine, along with other devices on the same network. In some cases, cybercriminals may exploit vulnerabilities in locally installed management software to target backup systems.

Unfortunately, many regular computer users fail to create appropriate data backups, which can be catastrophic when hit with ransomware. Paying the ransom is also a risky move, as there's no guarantee that the cybercriminals will provide a working decryption tool.

However, don't lose hope just yet, as data recovery software may be able to help to depend on the situation, such as the encryption algorithm used or if the ransomware was able to complete its tasks properly.

Before proceeding, it's crucial to back up any valuable encrypted files. Without doing so, recovery attempts may cause permanent damage to locked data, rendering a working decryptor useless. Use a USB flash drive or a similar storage device to keep your important files safe. Next, proceed with the data recovery instructions below.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.