Usam ransomware: what it is and how to remove it
Usam ransomware - a highly-malicious malware that locks the data on the Windows machine and blackmails victims to extort the money. The criminals behind this file-encrypting virus are infamous hackers that have launched STOP / Djvu ransomware a couple of years back and managed to release 233 new versions of the same virus.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Before you restore backups, a full scan can confirm the program that added .usam is gone.
Do it yourself · free Remove Usam ransomware yourself 6 steps, about 18 minutes, no software needed.
Start the steps
Usam ransomware: summary
| Name | Usam |
|---|---|
| Lineage | STOP / Djvu |
| Classification | Ransomware |
| Extension | .usam files is a distinctive feature of this new Djvu strain |
| Emails | victims have to contact hackers via gorentos@bitmessage.ch, gorentos@firemail.cc email, or @datarestore telegram account |
| Encryption/decryption | The virus uses an RSA encryption algorithm that generates unique online IDs that cannot be extracted. Cybersecurity experts keep looking for the flaws that would allow them to crack and leak IDs to help people decrypt .usam files. Note that the only reliable way to retrieve the locked files is to use backups. |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 16 more facts
| Ransom | Criminals demand people pay $490 or $980 ransom in Bitcoin cryptocurrency |
|---|---|
| Detection names | No Microsoft detection name is known |
| Contact | gorentos@bitmessage.ch, gorentos@firemail.cc, helpmanager@mail.ch |
| Encrypted file extension | .usam |
| Decryptor | No free decryptor is known for this variant; check No More Ransom (nomoreransom.org) for updates |
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Type | File-encrypting ransomware |
| Symptoms | Files renamed with a new extension and a ransom note left in folders |
| Evidence | 4 write-ups by security sites; no sample analysed yet |
| Encrypted files | .usam |
| Ransom note | _readme.txt |
| Attacker contacts | gorentos@bitmessage.ch |
| Free decryptor | No free decryptor is known (checked 6 October 2026) |
| First seen | 16 June 2020 |
| Facts checked | 6 October 2026 |
- File extension:
.usam - Note file:
_readme.txt - Contact:
gorentos@bitmessage.ch
From our report of Jun 2020 · not reviewed since
More from our earlier report on Usam
- The ransomware-type viruses cause harm not only to personal files.
- This type of threat is programmed to cause multiple system infringements on Windows registries, bootup processes, and others.
- Consequently, the system may start crashing, displaying errors, running into BSODs, etc.
- To prevent this from happening, take advantage of the repair utility
- Ransomware files cannot be eliminated manually since it's not possible to understand which of the running files are malicious.
- This process can be initiated with a robust anti-virus program only
How Usam ransomware behaves
From our report of Jun 2020 · not reviewed since
Usam ransomware is a cryptovirus that belongs to the STOP / Djvu ransomware family
Usam ransomware - a highly-malicious malware that locks the data on the Windows machine and blackmails victims to extort the money.
The criminals behind this file-encrypting virus are infamous hackers that have launched STOP / Djvu ransomware a couple of years back and managed to release 233 new versions of the same virus.
The Usam virus is the latest Djvu version, which stands 233 on the list. First spotted in the middle of June 2020, the malware is actively distributed via software cracks, keygens, and unprotected RDPs. If the unsuspecting victim launches the ransomware payload, the virus immediately encrypts most of the non-personal files (music, videos, photos, documents, etc.) with the .usam extension, thus completely restricting the user's access to them.
Unfortunately, .usam files cannot be decrypted for free. Even though there's an official STOPdecryptor available for anyone, it is fully functional with the old Djvu versions that have been launched before the autumn of 2019. Based on the information provided on the _readme.txt file, the victims of this virus are supposed to transfer $490 in Bitcoins within 72 hours after having a conversation with criminals via gorentos@bitmessage.ch or gorentos@firemail.cc email.
Usam ransomware virus belongs to the Djvu family - this fact tells almost everything about the virus for the users who are interested in cybersecurity. In fact, all the variants that belong to this gang released after August 2019 are identical.
Thus, taking a glance at its siblings, such as .kkll, .nlah, .pezi, .covm, .zwer, and many others are more or less the same, except file extensions and (in some cases) email addresses of the criminals differ.
If the Usam ransomware gets installed on the machine, first of all, it performs various changes on the Windows system with an intention to evade detection, ensure the successful launch of the encryption software, and grand persistence.
For that, it may create malicious entries within %AppData%, %User% or %Temp% directories, run the PowerShell commands under administrative privileges to remove Shadow Volume Copies, disable AV program, and can download data-stealing Trojan Azorult as a secondary payload. These changes are not definite, thus dealing with ransomware means many problems with the system's performance if Usam ransomware removal is not performed immediately.
The successful Usam ransomware infiltration is followed by a complete lockdown of personal files and the informational note dubbed as _readme.txt presentation on the desktop and other system folders. The note says:
Seeing .usam files on the machine and have no access to personal files is a frustrating experience. However, paying the ransom is highly not recommended as you can unconsciously uncover personal details to criminals or experience another phony if criminals decide not to provide you with a functional Usam ransomware decryptor.
If you have file backups, there's no reason for you to worry. Remove Usam virus from the system using updated anti-virus software. Do not try to eliminate malicious entries manually as you can accidentally delete some core Windows entries and, subsequently, trigger more Windows malfunctions.
Usam ransomware removal is a process that can only be performed with professional security software with an updated virus database. You can attempt to recover your encrypted files only after a full elimination of file-encrypting viruses. Our team has submitted a tutorial on how to decrypt .usam files without paying the ransom (at the end of the article).


From our report of Jun 2020 · not reviewed since
Alternative methods to unlock inaccessible .usam files
The main trait allowing to stand the Usam ransomware virus from the crowd is its distinctive file extension.
Thus, if you have noticed that the icons of your files became all the same (plain white icon) with a unified .usam extension appendix, there's no doubt that the file-encrypting Djvu family member has hacked your machine.
Unfortunately, .usam file decryption is not possible without paying the ransom or using original file backups. If you have no backups or money to pay the criminals, there are very few changes that important work, documents, or family photos will be recovered.
As we have pointed out, one of the ways to decrypt Djvu files, including .usam encrypted files is to use a free Emsisoft's decryption software. However, don't give a lot of traction to this software as it can only unlock files for the versions using offline IDs.
If you don't want to be dejected by the unsuccessful decryption process, you can check whether your files have been encrypted using offline or online IDs by opening C: drive and accessing SystemID.txt. This directory contains all encrypted data. If you see some entries with the names ending with "t1," then the free Emsisoft's decryptor might work.
You can find a full guide for the decryption methods at the end of this article.
IMPORTANT: criminals have launched a fake DJVU decryptor which may be found on various discussion forums, torrenting sites, or other sites. This decryptor not only fails to unlock files. In fact, it's another ransomware that drops a malicious crab.exe file, which downloads new Zorab ransomware and encrypts already encrypted files with .ZRB file extension.
From our report of Jun 2020 · not reviewed since
The most common ransomware distribution methods listed
Hackers are using sophisticated methods to trick people into downloading malicious ransomware viruses.
That's a commonly known fact. However, millions of less tech-savvy people are still paying no attention to the websites they land on, to the content they download, to the ads they click, to the updates they download, and so on.
Therefore, we keep trying to increase people's consciousness and grow their perception of cybersecurity by publishing the news on how hackers spread their newborn viruses or what new means have been invented to distribute good-old cyber infections. The team of cybersecurity experts from Dieviren.de has provided us with a list of most widely used Djvu ransomware distribution techniques, which is the following:
To protect yourself from ransomware attacks, you should rely on a reputable AV security suite, which has in-built real-time protection, email filter, and other additional features.
- Djvu ransomware family is most frequently distributed via cracks, keygens, loaders, and similar tools. If you are about to download a software crack to hack the license of Windows, Adobe Acrobat, Adobe Photoshop, game keygens, etc.
- Fake software updates. If the machine is infected by a rather aggressive adware-type malware, web browsers can redirect to sites infected with malicious scripts or display infected ads that once clicked download ransomware payload.
- Malicious spam email attachments. People can receive catchy email messages that contain ZIP, PDF, Microsoft Word attachments that ask people to enable Macros to view the content. DO NOT enable the supposed macros to open questionable attachments sent by unreliable senders. That's a scheme used by hackers to spread ransomware, trojans, spyware, and other cyber threats.
The Usam ransomware note
ATTENTION!
Don't worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-WJa63R98Ku
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail "Spam" or "Junk" folder if you don't get answer more than 6 hours.
To get this software you need write on our e-mail:
helpmanager@mail.ch
Reserve e-mail address to contact us:
restoremanager@airmail.cc
Your personal ID:
How to remove Usam ransomware
Tools you'll need
All of these are free except where noted. Download them on a clean device if the infected PC is offline.
- A USB stick: to keep the ransom note, two or three encrypted files and screenshots off the infected PC.
- Microsoft Defender Offline: built into Windows 11 and Windows 10; scans before Windows starts, so running malware cannot hide.
- Microsoft Safety Scanner: a second, portable scanner with current signatures; each download works for 10 days.
- ID Ransomware: identifies the family from the note and one encrypted file and says whether a decryptor exists.
- No More Ransom: the free decryptors from police and security companies; check it again every few months.
- Fortect (optional): scans Windows for malware and repairs the system files and settings it damaged. The free scan is in the box above.
How to remove Usam and get your files back
Work in this order.
Disconnecting comes first, removal comes before any restore, and nothing here asks you to contact the attackers.
Step 1: Disconnect the PC and unplug backup drives
Unplug the network cable or turn off Wi-Fi, and disconnect USB drives, external disks and network shares, so Usam cannot reach more files. Pause OneDrive, Google Drive or Dropbox sync, because synced folders upload the encrypted copies over the good ones.
Leave the PC on but offline while you read the next steps, since a restart can let the ransomware run again. This applies to Windows 11 and Windows 10 alike.

Windows 11: turn off Wi-Fi to take the PC offline. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 2: Save the ransom note and confirm the family
Your files now end in
.usamand the instructions are in_readme.txt. Save both to a USB stick, a copy of the note and two small encrypted files, before anything else.On another device, check them with ID Ransomware or Crypto Sheriff: the family name decides which decryptor, if any, can help. Keep the note's ID and contact line for your report.

Windows 11: the ransom note and encrypted files to copy for identification. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 3: Check for a free decryptor
Our last check found that for Usam, no free decryptor is known (checked 6 October 2026). Look again yourself in the No More Ransom list and the free decryptor pages of Emsisoft, Avast and Kaspersky, which add new families every year.
A decryptor needs the ransomware gone first, or it encrypts the files again. Keep at least one copy of the encrypted files on an external drive, even if no tool works yet.
Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 4: Remove the ransomware before you restore or decrypt
Removing Usam does not bring the files back, but it has to come first. Start with Defender's Full scan, then the offline scan from the same Scan options page, which checks the disk before Windows loads.
If the scan cannot start, use Safe Mode with Networking. Delete the ransom notes only after you have saved a copy, because removal tools sometimes leave them behind on Windows 11 and Windows 10.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Look for shadow copies of the files
Windows keeps shadow copies for restore points and backups, and some ransomware fails to delete them.
vssadmin list shadowsin an administrator Command Prompt tells you at once whether any exist.If they do, right-click the folder that held your files, open Properties > Previous Versions, select a version from before the attack, and click Open to check it before you Restore or copy the files out. Windows 11 and Windows 10 both have the tab.

Windows 11: vssadmin list shadows shows whether shadow copies exist. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 6: Restore the files from a backup or recover deleted originals
A backup made before the attack is the surest way back. Connect it only once the PC is clean, then restore from File History, Windows Backup, OneDrive's Restore your OneDrive or your own external copies.
Without a backup, try file recovery: the originals that Usam deleted may still be on the disk until something overwrites them. Install nothing new on the drive you want to recover from on the Windows 11 or Windows 10 PC.
Full procedure with screenshots: Recover deleted files (Recycle Bin, backups, OneDrive) On uGetFix
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Manual removal using Safe Mode
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.

- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.
- Go to Advanced options.

- Select Startup Settings.

- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.

Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.

- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.

- Go back to the process, right-click and pick End Task.

- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.

- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.

- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
From our report of Jun 2020 · not reviewed since
Usam ransomware removal options: no manual removal possibilities
There is no option to remove Usam ransomware virus manually.
Victims should understand that the virus initiates too many changes on the system and runs too many malicious processes to be detected and eliminated without the help of professionals.
Although you can find some malicious entries as they may suck up CPU resources or display errors, there are very few chances that you will be allowed to disable any of them manually. Usam virus grants itself administrative privileges and, therefore, all related files are run "legally."
Having this in mind, we strongly recommend you make a cold copy of the .usam files using a USB stick, external hard drive, or cloud and then perform a full Usam removal using an automated anti-virus program. For this purpose, you should use , , or another reputable anti-malware suite.
Upon ransomware elimination, try to recover Windows system to the previous state by restoring Windows registry entries, startup files, and core processes. For that, take advantage of the recover tool. Finally, you can try to retrieve the locked files using alternative methods listed below.
[GI=method-1] If Usam virus prevents your AV engine from being launched, access Safe Mode with Networking to disable malicious executables:
[GI=method-2]If the previous method failed to work, try eliminating the ransomware using System Restore point.
The methods listed below can be safely tried, though there's no guarantee that any of them work. Nevertheless, if you don't have backups and have no intentions to pay the criminals for a Usam decryption software, the following tips may help you to get back at least some of your files.
If you have enabled System Restore prior to the ransomware attack, try to get your files back with the help of the Windows Previous Versions feature
Shadow Volume Copies are not likely to help in this case since Djvu family is programmed to command Windows to delete these copies.
No free Usam decryptor available
The latest versions of STOP/Djvu cannot be decrypted using the Emsisoft's decryptor as it works with offline keys only.
Report it and recover your files
Report it
Report the attack even if you do not expect the files back: insurers and banks ask for the report number, and police use the contacts in the note to link cases.
- United States
- FBI IC3 · FTC ReportFraud
- United Kingdom
- Report Fraud (formerly Action Fraud) · NCSC
- Australia
- ReportCyber (ASD)
- EU countries
- Europol: national reporting sites
Give the victim ID, the note and the date the files were encrypted. A business that holds personal data may also have to notify its data protection authority, in the EU within 72 hours.
Make the next attack harmless
Usam could only hurt the files that had no second copy, and the signs (files that end in .usam and no longer open) showed exactly which ones those were.
The 3-2-1 rule fixes that:
- three copies
- two media
- one disconnected
A practical version for a home PC: OneDrive or another cloud backup with version history, plus an external disk that you plug in once a week for File History and then unplug. Test a restore now and then by opening a few files from the backup on another device.
Details, schedules and what not to back up are in our 3-2-1 backup guide for Windows.
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
Questions about Usam ransomware
How do I open .usam files?
You cannot open them by renaming or by choosing another program. The .usam ending shows that Usam encrypted the content, and only the matching key can reverse it. Renaming a file back to .docx or .jpg changes nothing except the icon, and it can confuse a future decryptor, so leave the names as they are.
To get the content back, use a backup, an unencrypted copy elsewhere, or a decryptor listed on No More Ransom if one exists for Usam. Store the encrypted files on an external disk until then.
Did Usam steal my files or passwords?
We do not know yet. Nothing published so far shows data theft by Usam, but the only confirmed sign is files that end in .usam and no longer open, which says nothing about what happened before. Many current ransomware attacks copy files or run a password stealer first, so it is wise to act as if they did.
From a clean device, change the passwords that were saved in the browsers on this PC, starting with e-mail and banking, sign out of all sessions and turn on two-step verification. Watch bank statements and account activity for the next few weeks.
Is there a free Usam decryptor?
We last checked on 6 October 2026, and for Usam no free decryptor is known. We check No More Ransom, which collects free tools from police and security companies, and the decryptor pages of the major antivirus vendors. A working decryptor exists only when the encryption has a flaw or the keys were leaked or seized.
Ignore sites and videos that offer a "Usam decryptor" for download or for a fee: these are usually scams or malware. Real decryptors are free and come from known security companies or law enforcement. Keep the encrypted files in case a tool appears later.
Should I pay the ransom?
We advise against it, and so do the FBI, Europol and national cyber agencies. Payment does not guarantee a working tool: some attackers never reply, some tools damage files, and some variants have no decryptor at all. Paying also funds further attacks and can make you a target again.
Before considering payment, try every recovery option in this guide and report the attack. Companies must involve their legal adviser and insurer, because payments to sanctioned groups can be illegal. If files are truly irreplaceable, store the encrypted copies and wait; decryptors sometimes appear later.
Can a data-recovery company decrypt my files for a fee?
Only if a decryptor already exists or the company pays the attackers for you. Some "ransomware recovery" services advertise that they can decrypt families with no known flaw; in practice they negotiate with the attackers and add their own fee. Others use the same free tools listed on No More Ransom.
Before you hire anyone, ask in writing how they will recover the files, whether they will contact the attackers and what happens if they fail. A legitimate service answers clearly. If a free decryptor exists for your family, you can run it yourself.
How did Usam get on my computer?
The way Usam spreads has not been documented yet, so look at your own recent activity. On home PCs, ransomware most often comes with cracked programs, game cheats, key generators and fake updates, or with an e-mail attachment that was opened. On business networks, attackers usually log in through Remote Desktop with a stolen or guessed password.
Think back to what was downloaded or installed in the days before files that end in .usam and no longer open, and check the Downloads folder and Installed apps sorted by date. Keep anything suspicious for your report, but do not run it again.
Is Usam the same as other ransomware with a similar name?
Not necessarily. Ransomware names come from the file extension, the note or a word in the code, so unrelated families often end up with similar names, and one family can appear under several names. The difference matters: a decryptor or advice for one family does not fit another and can damage files.
Compare the ending added to your files and the exact name of the note with the summary table at the top of this guide, then upload the note and one encrypted file to ID Ransomware from a clean device. If the result names another family, follow the guide for that family instead.
Can I just remove .usam from the file names?
You can try it on a copy, but for real ransomware it will not help. The .usam extension is only a label; the file content has been scrambled with a key the attackers hold.
If a renamed copy opens normally, the malware only renamed files, which happens with some fake ransomware, and you can rename the rest back. If it does not open, leave the files as they are. Renaming encrypted files can confuse a decryptor later, so always work on copies.
What does _readme.txt tell me about the ransomware?
Quite a lot. The file name _readme.txt, the wording, the contact addresses and the format of the personal ID are typical for each family. Uploading the note together with one encrypted file to ID Ransomware or No More Ransom's Crypto Sheriff usually names the family within seconds.
That name decides your options: some families have free decryptors, some can be partially recovered, and some cannot be decrypted at all. The note's claims about stolen data should be taken seriously but not at face value.
Will Fortect remove Usam?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Usam, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Wikipedia: Ransomware (read October 6, 2026)
- Kaspersky: Encrypting the encrypted: Zorab Trojan in STOP decryptor (read October 6, 2026)
- Dieviren: SICHERHEIT- UND SPYWARE-NEUIGKEITEN (read October 6, 2026)
- CISA: StopRansomware (read October 6, 2026)
- No More Ransom (read October 6, 2026)