Zeoticus 2.0 ransomware — a file-locking computer virus that changes the desktop wallpaper to present its ransom demand

Zeoticus 2.0 ransomware is a cryptovirus designed to encrypt files on a targeted computer and leave a ransom note that demands cryptocurrency as a ransom. The name for this virus stems from a character in a Japanese manga/anime series known as School DxD High.
The “2.0” indicates that this malware is an update to the Zeoticus ransomware that was first spotted by researchers back in December 2019. Like its previous version, this cyber threat also used AES coding algorithm to encrypt personal files, although there are a few differences too.
When Zeoticus 2.0 virus appends filenames, it does it by adding a triple extension – a sequence of 19 random numbers, outsourse@tutanota.comcriminal contact email, and .2020END extension (hence the malware might be referred to as 2020END ransomware). Afterward, the desktop wallpaper is changed in order to redirect victims to read the created README.html ransom note.
| name | Zeoticus 2.0 ransomware |
|---|---|
| Type | File locking virus |
| Ransom note | Changed desktop background and README.html |
| Appended file extension | 19 random characters.outsourse@tutanota.com.2020END extension is added to all encrypted files |
| Criminal contact details | outsourse@tutanota.com, outsourse@cock.li |
| Virus removal | Ransomware like this should be eliminated from all devices with a reliable anti-malware application ASAP |
| System health | Take care of the registry of your system by performing a system tune-up with a robust FortectIntego app |
Cybercriminals love Bitcoins because it's fast, reliable, and anonymous. The same goes for developers of Zeoticus 2.0 virus. In the ransom note, they instruct their victims on how to buy that cryptocurrency because that's how the payment ought to be made (although the ransom size isn't specified). Hackers in the README.txt state the following:
—-===Zeoticus 2.0===—-
WARNING!
I am truly sorry to inform you that all your important files are crypted.
If you want to recover your encrypted files you need to follow a few steps.
You need to buy bitcoins and send them to the address you receive by mail.
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register,
click 'Buy bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/
write to Google how to buy Bitcoin in your country?
in order to guarantee the availability of our key
we can decrypt one file for free
the size of the files <1 mb, doc.docx.cls.xlsx.pdf.jpg.bmp.txt file format
other formats will not be free decryption
after payment we will send a decryption program
Do not try to decrypt your files with programs by the decoder,
you will only damage your data and lose them forever.
Only we can decrypt your data, write to the original mails specified in this file,
otherwise you will become a victim of scammers.
outsourse@tutanota.com
outsourse@cock.li
—
All further ransom details would be provided to the victims if they contact the assailants by any of the two (or both) given emails – outsourse@tutanota.com, outsourse@cock.li. We strongly advise against making contact with the cybercriminals and against paying the ransom, and there are numerous reasons for that:
- Victims could lose their money
- Sent payments increase cybercriminals motivation and finance new attacks
- Funds might be used to research new ways of attacking and new ransomware
- The delivered decryption tool (if delivered at all) might not work.
That's why victims should remove Zeoticus 2.0 ransomware from their infected computers. Anti-malware software is vital not only for eliminating viruses but for preventing them access to computers too. Keeping virus databases up-to-date is essential because cybercriminals spawn new viruses each day.
According to VirusTotal,[1] 49 out of 69 anti-virus engines apprehended one of the malware's sample. That's why we suggest entrusting Zeoticus 2.0 ransomware removal to time-proven anti-malware apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Choose to perform a full system scan and let the software do the rest.

When you get rid of the infection, you should take care of your device's overall health. We recommend using powerful system repair tools like the FortectIntego app to scan for any system irregularities caused by the cryptovirus and revert them with a push of a button.
Changed desktop background carries this message:
Dear [username]
All your files has been encrypted
Toss a coin to us and get decryptor tool
All information how to make it you can find in README file
Simple steps to improve cybersecurity level for home users
Tech giants like Microsoft, Google, and others are constantly implementing new security measures to make the internet a safer place. But unfortunately, malware developers are bending over backwards to bypass these measures. That's why we compiled guidelines of a few simple steps that would greatly increase your cybersecurity level and might prevent you from ever having to deal with cybercriminals (or at least minimize the damage):
- Purchase a trustworthy anti-malware application and keep its virus database updated at all times.
- All software, including the operating system, must be up-to-date.
- Always keep backups of all essential data. In case ransomware slips by your security, you can easily remove it and restore the data.
- Learn how to recognize phishing emails. Never open any links or download any attachments in emails that you don't know the sender.
- Try to avoid torrent sites. They might be riddled with different kinds of malware[2]

Remove Zeoticus 2.0 ransomware with anti-malware software
The longer malware stays in a computer, the more damage it could do. Cryptoviruses are capable of replicating themselves to other computers or storage devices connected in a network. So users should focus on immediate Zeoticus 2.0 removal before more harm came their way.
Although manual deletion is possible, it might seem like a tough cookie to crack even for highly-experienced users. So remove Zeoticus 2.0 with the help of reliable anti-malware tools like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. But export all encrypted files to an offline storage device before doing that. There's no decryption tool available right now, but there's always hope.
Ransomware is capable of making serious changes to the system registry and other key settings, which might lead to crashes, severe lag, and other abnormal behavior. Experts[3] recommend using the FortectIntego app to restore your device's health so you could enjoy it anew.
Did this guide help?
Be the first to comment