XZZX virus – new member from CryptoMix ransomware family

XZZX is a new version of CryptoMix ransomware virus. Just like the name suggests, this cyber threat appends .XZZX file extension to targeted data. When all necessary files are locked, the malicious program generates the _HELP_INSTRUCTION.TXT file with recovery instructions.
XZZX ransomware uses a combination of RSA and AES cryptography. Just like the previous version of the malware, this one also uses 11 public RSA-1024 keys to encode the AES key. During the encryption, the virus not only appends a new file extension but renames files with a string of random letters and numbers too.
Following data encryption, the virus delivers ransom-demanding instruction in TXT file. The letter from the criminals tell that users have to send their unique ID number via one of four provided emails:
- xzzx@tuta.io,
- xzzx1@protonmail.com,
- xzzx10@yandex.com,
- xzzx101@yandex.com.
The ransom note does not tell how much money authors of the XZZX virus demand. It seems that the size might be set due to the amount and importance of the encrypted data. However, users are not advised to contact criminals and following their instructions.
Security experts from the udenvirus.dk[1] warn that file-encrypting viruses are created for making illegal income. Thus, there’re no guarantees that crooks will give your working decryption key once you pay the ransom. Besides, they might not have it. Therefore, it’s recommended to remove XZZX from the computer instead of trying doubtful data recovery methods.[2]
Unfortunately, data recovery after the XZZX Cryptomix ransomware attack might not be successful if you do not have backups. Malware researchers haven’t managed to crack ransomware’s code yet. Thus, the official decrypter is not available. However, we recommend staying patient and trying alternative recovery possibilities.
However, first of all, you should focus on XZZX removal. This malicious program might cause numerous destructive changes to the system and make your computer vulnerable. In order to use your PC normally again and try to get back access to your data, you have to run a full system scan with FortectIntego or MalwarebytesMalwarebytes and uninstall the virus first.

Tricky ways used for spreading malicious program
Malicious spam emails remain the main channel used for distributing malware payload. Clever malspam campaigns might trick users that they are opening an important document, statement or invoice. However, in reality, they are letting ransomware executable on the system.
However, users should not be careful with receive emails, but also:[3]
- stay away from suspicious ads;
- do not download security software or updates from pop-ups,
- install programs or updates from legit sources only,
- do not download illegal content,
- keep programs up-to-date,
- strengthen computer’s security with reputable anti-virus and anti-spyware.
The correct XZZX Cryptomix removal method
We want to discourage you from manual XZZX removal method. Trying to locate and delete malware-related components from the system might end up with a terrible and irreparable damage to your device. Malicious entries might be injected into system processes and terminating them manually might be complicated and dangerous.
For this reason, security experts recommend opting for the automatic elimination method. We recommend using FortectIntego or MalwarebytesMalwarebytes to remove XZZX Cryptomix ransomware safely. However, you can choose your preferred malware removal tool. If you face some difficulties, please check the guide below. It will show you how to disable the virus and run automatic elimination.
Did this guide help?
Be the first to comment