What is PGPSnippet ransomware?
PGPSnippet ransomware, new version of PGP ransomware, – is a dangerous virus, that is distributed around the world. Ransomware is a form of malicious software from cryptovirology that blocks all the personal files on your computer and makes them unreadable. First PGPSnippet infiltrates your system, then starts encrypting procedure with AES-256 (CBC) encryption algorithm. This ransomware adds .decodeme666@tutanota_com file extension to the name of all the encrypted data. In this article you can learn how to remove PGPSnippet ransomware and decrypt .decodeme666@tutanota_com files.
Once data on your computer is encrypted, PGPSnippet will drop a ransom note !!!README_DECRYPT!!!.txt. You can find demands and instruction on how to pay the ransom for decryption key in this file. This is what PGPSnippet ransom note contains:
All your documents and other files ENCRYPTED !!!
TO RESTORE YOUR FILES YOU MUST TO PAY: 500$ by Bitcoin to this address: 1Nvhebx6EHmFmXokSbXMxbCNGN2fwtgq8W
You can open an wallet here:
Send the file on the way “WIN + R >> %APPDATA%” file name hosts.txt to our e-mail after paymentat this email address: email@example.com
We will confirm payment and send to you decrypt key + instruction
Remember: you have a 72 hours and if you not paid, that price will up
ATTENTION : all your attempts to decrypt your PC without our software and key can lead to irreversible destruction
of your files !
PGPSnippet is a typical ransomware, its main purpose is to force you to pay these cyber criminals. They want you to pay ransom cost – 500$ in BitCoins. Once you’ve done payment, they are supposed to send you decryption key. But you should know that cyber criminals are not going to give you a decryption key. Mostly they are just ignoring their victims. That’s why there is no need to contact them, it wouldn’t help. Still, PGPSnippet ransomware does very complicated encryption, but it does not damage, move or delete your files, which means you have chance to restore your personal data.
How to remove PGPSnippet ransomware from your computer and restore files?
You may try to use anti-malware tool to remove PGPSnippet ransomware from your computer. Newly advanced ransomware detection technology is able to run an instant ransomware scan, which is perfect to protect your computer in case of a new ransomware attack.
How to decrypt .decodeme666@tutanota_com files encrypted by PGPSnippet?
Once you’ve removed virus, you are probably thinking of recovering files from encryption. Let’s take a look at possible ways of decrypting your data.
Decrypt .decodeme666@tutanota_com files with automated decryption tools
Unfortunately, due to novelty of PGPSnippet ransomware, there are no available automatic decryptors for this virus yet. Still, there is no need to invest in malicious scheme by paying ransom. You are able to recover files manually.
Decrypt .decodeme666@tutanota_com files manually
You can try to use one of these methods in order to restore your encrypted data manually.
Restore data with Windows Previous Versions
This feature is working on Windows Vista (not Home version), Windows 7 and later versions. Windows saves copies of files and folders which you can use to restore data on your computer. In order to restore data from Windows Backup, take following steps:
- Open My Computer and search for the folders you want to restore;
- Right-click on the folder and choose Restore previous versions option;
- The option will show you the list of all the previous copies of the folder;
- Select restore date and the option you need: Open, Copy and Restore.
Restore the system with System Restore
You can always try to use System Restore in order to roll back your system to its condition before infection infiltration. All the Windows versions include this option.
- Type restore in the Search tool;
- Click on the result;
- Choose restore point before the infection infiltration;
- Follow the on-screen instructions.
Recover data with Data Recovery
- Download and install Data Recovery
- Select drives and folders with your files, then click Scan.
- Choose all the files in a folder, then press on Restore button.
- Manage export location.
Restore data with Recuva
Recuva is a data recovery program for Windows, developed by Piriform. It is able to recover files that have been “permanently” deleted and marked by the operating system as free space.
- Once you’ve downloaded and installed this application, start it in Wizard mode: choose the Options button and then select Run Wizard;
- You will see Welcome to the Recuva Wizard page, choose Next;
- Open the File Type page and choose the type of data you need to recover, after select Next. If you don’t know what kind of data you are looking for, choose Other option;
- Choose the location of a search in the File Location window;
- In the Thank you window, select Start. After finishing searching process, Recuva will show you the results of search;
- Before recovering of the data, choose the Check Boxes near the file. You can see three types of colored dots. Green dot means that your chance to restore file is excellent. Orange one – chance to restore file is acceptable. And the red one shows you that it’s unlikely to happen;
- Select Recover option and choose the directory of the restored data.
How to protect PC from PGPSnippet?
It’s pretty difficult task to get rid of any ransomware, including PGPSnippet. But you can easily prevent any infection of your PC. HitmanPro.Alert’s CryptoGuard can help you with this problem. It’s one of the best anti-ransomware applications. No matter how sneaky it is, HitmanPro.Alert’s CryptoGuard will stop PGPSnippet infiltration to your system. After detection, this program removes all the related to the ransomware data and prevents your file from being encrypted.