What is Pashka Ransomware?

Pashka Ransomware is another virus that encrypts user files and extorts money to restore access to them. It appeared in early January of the new 2020. This malware encrypts all found images, MS Office documents, PDF files, videos and other files using the AES algorithm. Thus, users lose access to their data and may be forced to pay scammers to get their files back. After that, the ransomware adds the .pashka extension to the encrypted (i.e. infected) files and creates the text file HELP_ME_RECOVER_MY_FILES.txt in all the folders that were attacked by it.

remove Pashka Ransomware

In it, scammers carefully explain to you exactly what happened to your data and what you should do to recover it. Namely, transfer 0.03 BTC to the specified wallet, and then write to them at unlockransomware@protonmail.com. Computer security experts do not recommend being led by cybercriminals, as they tend not to send the promised tool to decrypt files, and you will be left with nothing. In this case, it is better to use antiviruses from well-known trusted suppliers of the corresponding software. Pashka Ransomware creates a text file on the desktop and in infected folders with the following contents:

ATTENTION! All your important files have been encrypted!
To return your files, send 0.03 bitcoins and contact us to confirm the payment and your unique identifier.
We will send you a decryption tool with your personal decryption password.

Where can I buy bitcoins:


Contact: unlockransomware@protonmail.com.

Bitcoin wallet to transfer:
Unique Identification Key (must be sent to us with payment confirmation):

As you can see from the message, a discount is also offered here if you fulfill the requirements of cybercriminals. In this case, the amount will be $ 490, not 980, as originally. This supposed benefaction is a very primitive ploy. The goal is for you to pay as quickly as possible until you come to your senses. There is no guarantee that your files will be returned in their original condition.

There are two solutions to this problem. The first is to use an automated removal tool. This method is suitable even for inexperienced users since the removal tool can delete all instances of the virus in just a few clicks. The second is to use the Manual Removal Guide. This is a more complex way that requires special computer skills.

How Pashka ransomware gets on my computer?

– Spam attachments and hyperlinks
– Software vulnerabilities and exploits
– Malicious sites
– Backdoors (defects of the algorithm that are intentionally built into it by the developer and allow you to gain unauthorized access to data or remote control of the operating system and the computer as a whole)

In the process of its work, Pashka places an executable file with a random name in the% TEMP% folder, modifies the Windows registry, disables the system restore function at boot, and performs all of some other actions. The encryption process itself takes from a few seconds to several minutes. After that, the .pashka extension is added to each of the files, for example, song.mp3 will become song.mp3.pashka and will no longer be opened by the music player.

How to remove Pashka Ransomware?

First of all, don’t panic. Follow these easy steps below.

1. Start your computer in Safe Mode with networking. To do that, restart your computer before your system starts hit F8 several times. This will Pashka Ransomware system from loading and will show Advanced boot options screen. Choose Safe mode with networking option from the options list using up and down arrows on your keyboard and hit Enter.
2. Log in to the system infected with the Pashka Ransomware virus. Launch your Internet browser and download a reliable anti-malware program and start a full system scan. Once the scan is complete, review scan results and remove all entries detected.

Recommended Solution:

Try SpyHunter

SpyHunter is a powerful tool that is able to keep your Windows clean. It would automatically search out and delete all elements related to malware. It is not only the easiest way to eliminate malware but also the safest and most assuring one. The full version of SpyHunter costs $42 (you get 6 months of subscription). By clicking the button, you agree to EULA and Privacy Policy. Downloading will start automatically.

Download SpyHunter

for windows

Try Stellar Data Recovery

Stellar Data Recovery is one of the most effective tools that can recover lost and corrupted files — documents, emails, pictures, videos, audio files, and more — on any Windows device. The powerful scan engine can detect compromised files and finally save them to specified destination. Despite its advancedness, it’s very concise and simple so that even the most inexperienced user can figure it out.

Download Stellar Data Recovery

Try MailWasher

Email security is the first line of defense against ransomware viruses. To do this, we recommend that you use MailWasher. MailWasher blocks ransomware viruses coming through spam and phishing, and automatically detects malicious attachments and URLs. In addition, malicious messages can be blocked even before the recipient opens them. Since the main source of the spread of ransomware viruses are infected emails, antispam significantly reduces the risk of a virus appearing on your computer.

Download MailWasher

You may find more detailed information about antivirus products in our article – Top 5 Antivirus Software for Windows

Restore your files using shadow copies


  1. Download and run Stellar Data Recovery.
  2. Select type of files you want to restore and click Next.
  3. Select the drive and folder where your files are located and date that you want to restore them from and press Scan.
  4. Once the scanning process is done, click Recover to restore your files.
Download Stellar Data Recovery

Step 2: Remove following files and folders of Pashka Ransomware:

Related connections or other entries:

No information

Related files:

No information

How to decrypt files infected by Pashka Ransomware?

You can try to use manual methods to restore and decrypt your files.

Decrypt files manually

Restore the system using System Restore

system restore

Although the latest versions of Pashka Ransomware remove system restore files, this method may help you partially restore your files. Give it a try and use standard System Restore to revive your data.

  1. Initiate the search for ‘system restore
  2. Click on the result
  3. Choose the date before the infection appearance
  4. Follow the on-screen instructions

Roll the files back to the previous version

Previous versions can be copies of files and folders created by Windows Backup (if it is active) or copies of files and folders created by System Restore. You can use this feature to restore files and folders that you accidentally modified or deleted, or that were damaged. This feature is available in Windows 7 and later versions.

windows previous versions

  1. Pashkat-click the file and choose Properties
  2. Open the Previous Version tab
  3. Select the latest version and click Copy
  4. Click Restore

How to prevent your system from Ransomware?

Make sure your Remote Desktop Protocol (RDP) connection is closed when you don’t use it. Also, we recommend using a strong password for this service. The most efficient way to avoid data lose is of course to make a backup of all important data from your computer.

Leave a Reply

Time limit is exhausted. Please reload CAPTCHA.