Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2017

How to remove XYZware ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

What should I know about XYZware ransomware?

XYZware virus is a new ransomware that falls into the large group of Hidden-Tear based[1] malware. The malicious program seems to be in the development process at the moment, which means that at least now cyber criminals[2] are not distributing it to victims actively. A few copies were sent out recently, and one managed to get into malware researchers’ eyesight. Once installed, the virus uses cryptography[3] ciphers (to be precise, a combination of RSA-2048 and AES-128 ciphers) to encode files on the compromised PC. Some malware researchers believe that author of this virus is likely to be from Indonesia, although this fact was not confirmed. The word “Indonesia” is only mentioned in ransomware author’s contact email address. When the virus finishes encryption routine, it saves a message on victim’s desktop, which says:

There is no way to decrypt without private key and decryption program. You can buy the private key and the decryption program just for 0.2 BTC (Bitcoin). You have 48 hours to buy it.

The rest of the message explains that the victim has to write to cyberking@indonesianbacktrack.or.id email to get instructions on how to pay the ransom and recover files. We do not recommend paying the ransom because it is likely that files can be recovered for free. We suggest patiently waiting for news from malware researchers – XYZware decryption tool might be available anytime soon. Until then, remove XYZware malware using anti-malware program, for instance, MalwarebytesMalwarebytes or FortectIntego.

XYZware ransomware

How does this ransomware spread?

While more dangerous and sophisticated viruses like Cerber employ exploit kits[4], infected ad networks, and other malware distribution techniques, developers of XYZware ransomware seem to be far less advanced. Therefore, they use the basic and very straightforward malware dissemination trick – malspam[5], also known as mail spam. They only need to compose convincing messages and attach some files to such email, then send it out to thousands of victims. A general tip is to bypass emails coming from unknown individuals – do not trust links or files sent to you by strangers. They can instantly compromise your PC and damage your files! To increase computer’s protection, keep programs up-to-date and add another layer of protection by installing an anti-malware program. Now, let’s talk about XYZware removal peculiarities.

XYZware removal explained

If you were attacked by XYZware virus unexpectedly, the chances are high that you received an updated version of this malware. We suggest deleting it immediately. For XYZware removal, you have to prepare your PC first, so reboot it into Safe Mode with Networking and then use the security software you have to exclude the malicious files from the system. If you do not have a tool to remove XYZware ransomware automatically, consider installing one of the programs we recommend using.

3 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.