Infected with BadNews Ransomware? Need to decrypt your files?

What is BadNews Ransomware

Recently, cryptoviruses are gaining the most distribution, in this article, we will examine one of them, which is called BadNews. Like many analogs, this virus encrypts user files and makes them unusable. In more detail, BadNews encrypts files and assigns them a new extension for this pattern: ID [victim’s_ID].BadNews. Files that are encrypted can be of different formats, for example, office documents, archives, photos or videos, PDF files and so on. After encryption, BadNews displays a pop-up that contains information about the redemption:

BadNews Ransomware

textual content:



To get the decryptor you should:
Send 1 test image or text file to
In the letter include your personal ID (look at the beginningof this document).
We will give you the decrypted file and say price fordecryption all files
after payment you will receive a decryptor and instructions
We can decrypt one file in quality the evidence that we have thedecoder.


Only can decryptyour files
Do not trust anyone
Attempts to self-decrypting files will result in the loss ofyour data
Decoders for other IDs are not compatible with your ID data,because each user’s unique encryption key

According to the contents of the note, it becomes clear that scammers try to avoid prosecution under the law, so they need to contact them via e-mail and pay ransom in the cryptocurrency. The amount of redemption is not specified, but it can be with full confidence that it can reach several thousand dollars. Of course, you do not need to pay, because the main task of scammers is to get your money. We strongly recommend that you read our recommendations to remove BadNews and decrypt your files.

Update: Use following service to identify the version and type of ransomware you were attacked by: ID Ransomware. If you want to decrypt your files, please follow our instruction below or, if you have any difficulties, please contact us: We really can help to decrypt your files.

How BadNews infected your PC

The lion’s share of penetrations is due to insecurity of network settings, moreover, users use free versions of antiviruses or completely, neglect them, which makes their computers vulnerable, because BadNews can come as an attachment to spam mailing or as a false update for a program. Whatever it was, you need to remove BadNews right now using our guides.

First of all, don’t panic. Follow these easy steps below.

1. Start your computer in Safe Mode with networking. To do that, restart your computer before your system starts hit F8 several times. This will stop system from loading and will show Advanced boot options screen. Choose Safe mode with networking option from the options list using up and down arrows on your keyboard and hit Enter.
2. Log in to the system infected with the BadNews virus. Launch your Internet browser and download a reliable anti-malware program and start a full system scan. Once the scan is complete, review scan results and remove all entries detected.

Recommended Solution:

Norton is a powerful removal tool. It can remove all instances of newest viruses, similar to BadNews – files, folders, registry keys.


Download Norton*Trial version of Norton provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Norton.

You may find more detailed information about antivirus products in our article – Top 5 Antivirus Software for Windows

Restore your files using shadow copies


  1. Download and run Stellar Data Recovery.
  2. Select type of files you want to restore and click Next.
  3. Select the drive and folder where your files are located and date that you want to restore them from and press Scan.
  4. Once the scanning process is done, click Recover to restore your files.
Download Stellar Data Recovery

Step 2: Remove following files and folders of BadNews:

Related connections or other entries:

No information

Related files:

No information

How to decrypt files infected by BadNews?

You can try to use manual methods to restore and decrypt your files.

Decrypt files manually

Restore the system using System Restore

system restore

Although latest versions of BadNews remove system restore files, this method may help you to partially restore your files. Give it a try and use standard System Restore to revive your data.

  1. Initiate the search for ‘system restore
  2. Click on the result
  3. Choose the date before the infection appearance
  4. Follow the on-screen instructions

Roll the files back to the previous version

Previous versions can be copies of files and folders created by Windows Backup (if it is active) or copies of files and folders created by System Restore. You can use this feature to restore files and folders that you accidentally modified or deleted, or that were damaged. This feature is available in Windows 7 and later versions.

windows previous versions

  1. Right-click the file and choose Properties
  2. Open the Previous Version tab
  3. Select the latest version and click Copy
  4. Click Restore

Protect your computer from ransomware

hitmanpro alert with cryptoguard

Most modern antiviruses can protect your PC from ransomware and crypto-trojans, but thousands of people still get infected. There are several programs that use different approach t protect from ransomware and lockers. One of the best is HitmanPro.Alert with CryptoGuard. You may already know HitmanPro as famous cloud-based anti-malware scanner. Check out ultimate active protection software from SurfRight.

Download HitmanPro.Alert with CryptoGuard

Written by Rami Douafi

Leave a Reply

Time limit is exhausted. Please reload CAPTCHA.