Infected with .zzzzz ransomware? Need to decrypt your files?
What is .zzzzz ransomware
.zzzzz is actually redesigned Locky crypto-virus. We remind that Locky (and its new version) uses asymmetric encryption algorithm to encrypt user files, images, videos, documents, game files. Now virus can detect and encode more than 450 types of files. After encryption virus appends .zzzzz extension and modifies filenames sol they get long alphanumeric 24 digit names. This ransomware still extorts ransom of 3 BitCoins (~$2200) from user to decrypt files. Zzzzz ansomware creates 3 files on users PC: INSTRUCTION.bmp, -INSTRUCTION.html and _6-INSTRUCTION.html. All this files are used to inform users, that their system is hacked and files are encrypted. Virus uses image to apply it as desktop background. Don’t be deceived, Locky or .zzzzz developers never send decryptors or decryption keys and paying the ransom will be waste of money. In addition, you can put your bank details at risk, as payment is performed on hackers owned websites to BitCoin wallets. We created step-by-step instructions to remove .zzzzz ransomware virus decrypt .zzzzz files on Windows 10, 7, 8, Vista or XP.
How .zzzzz ransomware infected your PC
.zzzzz ransomware uses spam e-mail attachments to infect users computers. For example, fake e-mail from Amazon with malicious archive ORDER-[random-number]”, like it is shown on the picture above. Virus is hidden inside archives of HTA, JS, or WSF documents attached to such e-mails. If user downloads this archive and opens HTA, JS, or WSF file, virus will run DLL files using system file Rundll32.exe. Once uses does it there is no way back because it will soon download small executable and will run it to encrypt files in user folders. Antiviruses have a small chance to catch .zzzzz ransomware virus as it is constantly modified. The only way to protect your computer from such threats is use antiviruses with crypto-protection like HitmanPro.Alert with CryptoGuard.
What to do if you are infected with .zzzzz ransomware virus?
First of all don’t panic. Follow these easy steps below.
1. Start your computer in Safe Mode with networking. To do that, restart your computer, before your system starts hit F8 several times. This will stop system from loading and will show Advanced boot options screen. Choose Safe mode with networking option from the options list using up and down arrows on your keyboard and hit Enter.
2. Log in to the system infected with the .zzzzz ransomware virus. Launch your Internet browser and download a reliable anti-malware program and start a full system scan. Once the scan is complete, review scan results and remove all entries detected.
Norton is a powerful removal tool. It can remove all instances of newest viruses, similar to .zzzzz ransomware – files, folders, registry keys.
*Trial version of Norton provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Norton.
Step 2: Remove following files and folders of .zzzzz ransomware:
Remove following registry entries:
Remove following files:
How to decrypt files infected by .zzzzz ransomware (.zzzzz files)?
Use automated decryption tools
1. .zzzzz decryption tool from Kaspersky
There is ransomware decryptor from Kaspersky that can decrypt .zzzzz files. It is free and may help you restore .zzzzz files encrypted by Vegclass Ransomware virus. Download it here:
1. .zzzzz decryption tool from Trend Micro
There is ransomware decryptor from Trend Micro that may decrypt .zzzzz files. It is free and may help you restore files encrypted by .zzzzz ransomware. Download it here:
There is currently no other automated decryption tool for .zzzzz ransomware files, but that doesn’t mean that you need to pay the ransom. We track the topic and will add any new decryption tool available in this part of the article. Now you can try to use manual methods to restore and decrypt .zzzzz files.
Decrypt .zzzzz files manually
Restore the system using System Restore
Although, latest versions of .zzzzz ransomware remove system restore files, this method may help you to partially restore your files. Give it a try and use standard System Restore to revive your data.
- Initiate the search for ‘system restore‘
- Click on the result
- Choose the date before the infection appearance
- Follow the on-screen instructions
Roll the files back to the previous version
Previous versions can be copies of files and folders created by Windows Backup (if it is active) or copies of files and folders created by System Restore. You can use this feature to restore files and folders that you accidentally modified or deleted, or that were damaged (in our case – encrypted by .zzzzz ransomware). This feature is available in Windows 7 and later versions.
- Right-click the file and choose Properties
- Open the Previous Version tab
- Select the latest version and click Copy
- Click Restore
Restore .zzzzz files using shadow copies
- Download and run Shadow Explorer.
- Select the drive and folder where your files are located and date that you want to restore them from.
- Right-click on folder you want to restore and select Export.
- Once the scanning process is done, click Recover to restore your files.
Protect your computer from ransomware
Most modern antiviruses can protect your PC from ransomware and crypto-trojans, but thousands of people still get infected. There are several programs that use different approach t protect from ransomware and lockers. One of the best is HitmanPro.Alert with CryptoGuard. You may already know HitmanPro as famous cloud-based anti-malware scanner. Check out ultimate active protection software from SurfRight.
Information provided by: Alexey Abalmasov