Vanss ransomware is a cryptovirus that uses the same email address as previous Dharma versions

Vanss ransomware — a file-locking malware that adds .vanss file extension after it finishes its encryption process. This is the newest variant of Dharma ransomware that looks identical to previous versions and uses the same blacklist@cock.li contact email as previous threats released since May 2018. Typically to other versions hailing from this ransomware family, Vanss appends ransom note in the form of FILES ENCRYPTED.txt and Info.hta files. These contain recovery instructions, payment methods and more information about the attack performed behind the user's back. However, the test decryption that is offered by ransomware developers is not a good idea and paying the ransom, in general, can hardly give positive results. You should focus on virus removal first before worrying about encoded data. Unfortunately, there is no official decryption tool for this particular variant yet.
| Name | Vanss ransomware |
|---|---|
| Type | Cryptovirus |
| Related | Dharma ransomware |
| Previous version | |
| Ransom note | FILES ENCRYPTED.txt; Info.hta |
| File extension | .[Blacklist@cock.li].vanss |
| Contact email | blacklist@cock.li |
| Distribution | Spam email attachments |
| Decryption | There is no decryption tool for the particular version |
| Elimination | Use FortectIntego for Vanss ransomware removal |
Ransomware-type threats, including Vanss ransomware, have been starting their attack from changing the registry entries, adding files to a directory or modifying additional system content. The encryption[1] process is the final stage of the ransomware attack when all changes are already made. The virus modifies the following registry keys[2] on the system of victims' device:
- \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\996E.exe
- \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
- \Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
- \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll
- \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oleaut32.dll
- \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\version.dll
- \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll
- \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled
Additionally, ransomware works in the background until it encodes all victim's files. Cybercriminals develop this virus to scan the system and find the most used files for encryption. Previous variants use AES encryption method to make user's files useless. Every encrypted file is marked using .vanss file extension that displays which data is locked and unavailable for the use.
Once the files are encrypted, malware drops the FILES ENCRYPTED.txt and Info.hta ransom notes in every folder on the system. Unfortunately, there is no solution for encrypted data besides file backups and several options that we presented below. If you are looking for the decryption tool designed for this particular variant, we must warn you not to buy it from cybercriminals because you can be scammed.
You need to remove Vanss ransomware as soon as possible because cyber threats like these crypto-extortionists can affect the system in a more significant way. Ransomware can interact with Windows files in System folders or alter functions of an operating system without you even noticing to make the virus more persistent and dangerous.
Vanss ransomware removal can be performed using anti-malware tools like FortectIntego or a few other that we list below the article. Scan your system thoroughly and delete all detected intruders to make your system clear again. After this, you can try data recovery methods from down below or replace your files from a safe backup.

File attachments on spam emails used to infect computers
The most effective tactic used to spread ransomware intruders effectively is spam email attachments. Files added as an attachment to email message usually pose to be secure documents from services or companies. It may look like you got an invoice, a receipt, order information or banking statement. Senders often imitate big companies like PayPal, eBay or Amazon, and DHL.
However, these files are often be filled with macros or designed to self-extract the malicious file or even direct malware payload. Researcher[3] note that URLs on these email may also be infected and spread cyber infections immediately after you enter the website. Opening the page automaticaly downloads the ransomware and installs the malicious file. Clean the email box more frequently and avoid any suspicious email. Do not open the email you haven't expected.
Remove Vanss ransomware and all related files using reputable anti-malware
When it comes to cyber threats as dangerous as cryptocurrency demanding ransomware, virus elimination is a necessary and challenging process. To remove Vanss ransomware from the system completely, you need to employ anti-malware tools like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These programs detect malware, corrupted files, and other virus damage and delete possible threats entirely off the device.
Automatic Vanss ransomware removal is the best solution because there are tons of changes you cannot find manually. And data recovery cannot be made on an infected device because ransomware performs yet another encryption on newly added files. Double-check if the system is clear before adding new files on the computer or attempting data recovery. You may need to enter the Safe Mode before scanning the system, so your antivirus works properly.
Did this guide help?
Be the first to comment