Infected with Arrow Ransomware? Need to decrypt your files?

What is Arrow Ransomware

Arrow Ransomware is a new version of encryption virus from notorious Dharma/Crysis ransomware family. Ransomware uses AES and RSA algorithms to encrypt user files and add .arrow extension to affected files. Actually, it appends a complex suffix, that looks like this: .id-{8-symbols-alphanumeric-id}-{e-mail}.arrow. Malefactors currently use following e-mail addresses:

marat20@cock.li, bitcoin888@cock.li, blammo@cock.li

Arrow Ransomware creates two files FILES ENCRYPTED.TXT and Info.hta. They contain following information:

All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail sabantui@tutanota.com
Write this ID in the title of your message B8F053EC
In case of no answer in 24 hours write us to theese e-mails:udacha@cock.li
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.
Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 10Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
https://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
http://www.coindesk.com/information/how-can-i-buy-bitcoins/
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

Ransom is 0.1 BitCoin, that currently equals to ~$1000. However, this amount may vary depending on cryptocurrency exchange rate. Arrow Ransomware targets most important user data, which makes it effective for malefactors. These are MS Office documents, OpenOffice, PDF, text files, databases, photos, music, videos, image files, archives, web page files and other web files, educational, application and specialized files, and other files. Currently, files infected or encoded by this threat are non-decryptable, but there are certain methods to restore .arrow files manually. Use this tutorial to remove Arrow Ransomware completely from Windows 10, 8, 7 and decrypt your files.

arrow ransomware

Update: Use following service to identify the version and type of ransomware you were attacked by: ID Ransomware. Also check following website for possible decryptor: Emsisoft Decryptors.

How Arrow Ransomware infected your PC

At this moment, we know that several e-mails are used to distribute .docx files with malicious macroses. E-mails are distributed all over the world. You can also get this ransomware on file-sharing networks, including torrent files. Ransom is asked to be paid in BitCoins, that also makes the task difficult for the police, as the user in this network is often anonymous. Encryption starts in the background. Way to protect your computer from such threats is to use antiviruses with crypto-protection like HitmanPro.Alert with CryptoGuard.

First of all, don’t panic. Follow these easy steps below.

1. Start your computer in Safe Mode with networking. To do that, restart your computer before your system starts hit F8 several times. This will stop system from loading and will show Advanced boot options screen. Choose Safe mode with networking option from the options list using up and down arrows on your keyboard and hit Enter.
2. Log in to the system infected with the Arrow Ransomware virus. Launch your Internet browser and download a reliable anti-malware program and start a full system scan. Once the scan is complete, review scan results and remove all entries detected.

Recommended Solution:

Norton is a powerful removal tool. It can remove all instances of newest viruses, similar to Arrow Ransomware – files, folders, registry keys.

 

Download Norton*Trial version of Norton provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Norton.

Step 2: Remove following files and folders of Arrow Ransomware:

Remove following registry entries:

no information

Remove following files and folders:

no information

How to decrypt files infected by Arrow Ransomware (.arrow files)?

Use automated decryption tools

kaspersky rakhni decryptor for Arrow Ransomware

There is ransomware decryptor from Kaspersky that can decrypt .arrow files. It is free and may help you restore .arrow files encrypted by Arrow Ransomware virus. Download it here:

Download Kaspersky RakhniDecryptor

You can also try to use manual methods to restore and decrypt .arrow files.

Decrypt .arrow files manually

Restore the system using System Restore

system restore

Although latest versions of Arrow Ransomware remove system restore files, this method may help you partially restore your files. Give it a try and use standard System Restore to revive your data.

  1. Initiate the search for ‘system restore
  2. Click on the result
  3. Choose the date before the infection appearance
  4. Follow the on-screen instructions

Roll the files back to the previous version

Previous versions can be copies of files and folders created by Windows Backup (if it is active) or copies of files and folders created by System Restore. You can use this feature to restore files and folders that you accidentally modified or deleted, or that were damaged (in our case – Arrow Ransomware by Arrow Ransomware). This feature is available in Windows 7 and later versions.

windows previous versions

  1. Right-click the file and choose Properties
  2. Open the Previous Version tab
  3. Select the latest version and click Copy
  4. Click Restore

Restore .arrow files using shadow copies

stellar-data-recovery

  1. Download and run Stellar Data Recovery.
  2. Select type of files you want to restore and click Next.
  3. Select the drive and folder where your files are located and date that you want to restore them from and press Scan.
  4. Once the scanning process is done, click Recover to restore your files.

Protect your files from ransomware

Most modern software can protect your data from ransomware and crypto-trojans, but thousands of people still get infected. There are several programs that use different approach to protect your files from ransomware and lockers. One of the best is SOS Online Backup. The product will automatically find important files, then simply make a daily backup on the remote server. SOS runs quietly and automatically in the background and supports any size and any file type. All SOS apps (desktop AND mobile) encrypt files using UltraSafe 256-bit AES before transferring them to the cloud. You will not lose your important data. Download One Year Plan.

SOS Online Backup

Information provided by Tim Kas

6 Comments

    • Unfortunately, a universal tool, able to decrypt arrow ransomware doesn’t exist, but we are trying to find new more advanced decryptors. Please, check up our updates. Some old ‘deadly’ ransomware viruses now become decryptable.

      • Unfortunately, there are no updates. You can try, for example, data recovery pro from our article. Some users (partially) recovered shadow and deleted copies by this software

Leave a Reply

Your email address will not be published. Required fields are marked *