Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2018

How to remove Vanss ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Vanss ransomware is a cryptovirus that uses the same email address as previous Dharma versions 

Vanss ransomware virus

Vanss ransomware — a file-locking malware that adds .vanss file extension after it finishes its encryption process. This is the newest variant of Dharma ransomware that looks identical to previous versions and uses the same blacklist@cock.li contact email as previous threats released since May 2018. Typically to other versions hailing from this ransomware family, Vanss appends ransom note in the form of FILES ENCRYPTED.txt and Info.hta files. These contain recovery instructions, payment methods and more information about the attack performed behind the user's back. However, the test decryption that is offered by ransomware developers is not a good idea and paying the ransom, in general, can hardly give positive results. You should focus on virus removal first before worrying about encoded data. Unfortunately, there is no official decryption tool for this particular variant yet.

Name Vanss ransomware
Type Cryptovirus
Related Dharma ransomware
Previous version
Ransom note FILES ENCRYPTED.txt; Info.hta
File extension .[Blacklist@cock.li].vanss
Contact email blacklist@cock.li
Distribution Spam email attachments
Decryption There is no decryption tool for the particular version
Elimination Use FortectIntego for Vanss ransomware removal

Ransomware-type threats, including Vanss ransomware, have been starting their attack from changing the registry entries, adding files to a directory or modifying additional system content. The encryption[1] process is the final stage of the ransomware attack when all changes are already made. The virus modifies the following registry keys[2] on the system of victims' device:

  • \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\996E.exe
  • \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
  • \Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
  • \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll
  • \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oleaut32.dll
  • \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\version.dll
  • \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll
  • \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled

Additionally, ransomware works in the background until it encodes all victim's files. Cybercriminals develop this virus to scan the system and find the most used files for encryption. Previous variants use AES encryption method to make user's files useless. Every encrypted file is marked using .vanss file extension that displays which data is locked and unavailable for the use. 

Once the files are encrypted, malware drops the FILES ENCRYPTED.txt and Info.hta ransom notes in every folder on the system. Unfortunately, there is no solution for encrypted data besides file backups and several options that we presented below. If you are looking for the decryption tool designed for this particular variant, we must warn you not to buy it from cybercriminals because you can be scammed. 

You need to remove Vanss ransomware as soon as possible because cyber threats like these crypto-extortionists can affect the system in a more significant way. Ransomware can interact with Windows files in System folders or alter functions of an operating system without you even noticing to make the virus more persistent and dangerous.

Vanss ransomware removal can be performed using anti-malware tools like FortectIntego or a few other that we list below the article. Scan your system thoroughly and delete all detected intruders to make your system clear again. After this, you can try data recovery methods from down below or replace your files from a safe backup.

Vanss ransomware

File attachments on spam emails used to infect computers

The most effective tactic used to spread ransomware intruders effectively is spam email attachments. Files added as an attachment to email message usually pose to be secure documents from services or companies. It may look like you got an invoice, a receipt, order information or banking statement. Senders often imitate big companies like PayPal, eBay or Amazon, and DHL.

However, these files are often be filled with macros or designed to self-extract the malicious file or even direct malware payload. Researcher[3] note that URLs on these email may also be infected and spread cyber infections immediately after you enter the website. Opening the page automaticaly downloads the ransomware and installs the malicious file. Clean the email box more frequently and avoid any suspicious email. Do not open the email you haven't expected. 

Remove Vanss ransomware and all related files using reputable anti-malware

When it comes to cyber threats as dangerous as cryptocurrency demanding ransomware, virus elimination is a necessary and challenging process. To remove Vanss ransomware from the system completely, you need to employ anti-malware tools like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These programs detect malware, corrupted files, and other virus damage and delete possible threats entirely off the device.

Automatic Vanss ransomware removal is the best solution because there are tons of changes you cannot find manually. And data recovery cannot be made on an infected device because ransomware performs yet another encryption on newly added files. Double-check if the system is clear before adding new files on the computer or attempting data recovery. You may need to enter the Safe Mode before scanning the system, so your antivirus works properly.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.