x1881 ransomware is a new version of an infamous CryptoMix

x1881 ransomware belongs to an infamous CryptoMix family which has been spreading for several years. It seems that the virus does not differ from its previous versions. The most visible change in it is a different extension used to mark affected files. After finishing the encryption process, the ransomware appends .x1881 extension. It also drops _HELP_INSTRUCTION.txt file to inform the victim about its expectations – the ransom fee.
This version mentions four email addresses that should be used to transfer the money:
- x1881@tuta.io;
- x1883@yandex.com;
- x1881@protonmail.com;
- x1884@yandex.com;
x1881 ransomware continues the tradition of Shark CryptoMix version to use 11 RSA-1024 keys to encrypt victim's files. This feature grants the virus a very special possibility – function offline. It also leaves its registry entry among the registry files –HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Admin”=”C:\ProgramData\[Random].exe[1].
Fortunately, the majority of security applications can detect and remove x1881 virus. It is found by alternative names: Win-Trojan/Sagecrypt.Gen, TR/Crypt.ZPACK.qwkzv, Win32/Filecoder.HydraCrypt.M, Ransom.CryptoMix, etc.
Unfortunately, it disguises under a random executable file. If you have been struck with this cyber misfortune, it is not recommended to pay the ransom. A while ago, Avast researchers released a free CryptoMix decrypter.
There is no information whether the developers sent the decryption key to the victims who remitted the payment. Therefore, x1881 ransomware removal might be a better decision. You can accelerate the process with FortectIntego or MalwarebytesMalwarebytes. Update them before scanning the system. If you encounter technical difficulties performing the elimination, take a look at the guide below the article.
Distribution methods used by ransomware virus
In order to keep up CryptoMix activity, the developers no longer rely solely on spam emails or trojans. This malware family gained attention after reports that its version, Revenge malware, has been spread with the assistance of RIG exploit kit[2].
This hacking tool is actually a Javascript code. Due to its flexible form, cyber villains can inject it any website, not just poorly secured domains.
The exploit kit is designed to target a specific vulnerability[3]. This peculiarity explains why WannaCry attack and Equifax data breach case were successful. If you have failed to update your browser or operating system, the risk to get infected with the kit is much higher. Thus, in order to limit the probability of x1881 virus infiltration, update crucial programs.
Remove x1881 ransomware completely
Unfortunately, CryptoMix virus is troublesome so is its elimination. Let security tool take care of x1881 ransomware removal. If the virus prevents you from launching the program, reboot the system in Safe Mode. It will grant you access to vital operating system functions, and you will be able to remove x1881 ransomware virus.
After the infection is deleted, proceed to data recovery methods. Use the official Avast decrypter. You will also find a few program suggestions at the bottom of the instructions. All, not only British, German[4] or French, users should be wary of the latest x1881 version.
Did this guide help?
Be the first to comment