1Btc Medusalocker Ransomware — How to Remove?

1btc Virus

1btc adds its specific “.1btc” extension to the name of every file. For example, your photo named as “my_photo.jpeg” will be transformed into “my_photo.jpeg.1btc“, report in Excel tables named “report.xlsx” – to “report.xlsx.1btc“, and so on.

!!!HOW_TO_DECRYPT!!!.mht file, which can be found in every folder that contains the encrypted files, is a ransom money note. Inside of it, you can find information about ways of contacting 1btc ransomware developers, and some other info. Inside of the ransom note, there is usually an instruction saying about purchasing the decryption tool. This decryption tool is created by ransomware developers, and can be obtained through the email, contacting , .

Name1btc (medusalocker) Virus
Ransomware family1MedusaLocker ransomware
Extension.1btc
Ransomware note!!!HOW_TO_DECRYPT!!!.mht
Contact,
Detection2Ransom:Win32/DoejoCrypt.A, Ransom:Win32/DoejoCrypt.A – [DoejoCrypt Virus Removal Instruction], Win32/Bifrose.ADR
SymptomsYour files (photos, videos, documents) have a .1btc extension and you can’t open it.
Fix ToolSee If Your System Has Been Affected by 1btc (MedusaLocker) virus

The !!!HOW_TO_DECRYPT!!!.mht file by the 1btc (MedusaLocker) ransomware states the following frustrating information:

All your valiable data has been encrypted!


Hello!
Sorry, but we have inform you that your order has been blocked due to the issue of securities. Make sure your data is not blocked. All your valuable files were encrypted with strong encryption algorithms AES-256 + RSA-2048 + CHACHA and renamed. You can read about these algorithms in Google. Your unique encryption key is stored securely on our server and your data can be decrypted quickly and securely.

We can prove that we can decrypt all of your data. Please just send us 3 small encrypted files which are randomly stored on your server. We will decrypt these files and send them to you as a proof. Please note that files for free test decryption should not contain valuable information.


As you know information is the most valuable resource in the world. That's why all of your confidential data was uploaded to our servers. If you need proof, just write us and we will show you that we have your files. If you will not start a dialogue with us in 72 hours we will be forced to publish your files in the Darknet. Your customers and partners will be informed about the data leak by email or phone.


This way, your reputation will be ruined. If you will not react, we will be forced to sell the most important information such as databases to interested parties to generate some profit.

Please understand that we are just doing our job. We don't want to harm your company. Think of this incident as an opportunity to improve your security. We are opened for dialogue and ready to help you. We are professionals, please don't try to fool us.

If you want to resolve this situation,
please write to ALL of these 2 email addresses:


In subject line please write your ID: -

Important!
* We asking to send your message to ALL of our 2 email adresses because for various reasons, your email may not be delivered.
* Our message may be recognized as spam, so be sure to check the spam folder.
* If we do not respond to you within 24 hours, write to us from another email address. Use Gmail, Yahoo, Hotmail, or any other well-known email service.
Important
* Please don't waste the time, it will result only additinal damage to your company!
* Please do not try to decrypt the files yourself. We will not be able to help you if files will be modified.

The image below gives a clear vision of how the files with “.1btc” extension look like:

Example of encrypted .1btc files

How did I get MedusaLocker ransomware on my computer?

However, nowadays there are only two ways of 1btc (MedusaLocker) injection – email spam and trojans. You may see a lot of messages on your email, stating that you need to pay different bills or to get your parcel from the local FedEx department. But all such messages are sent from unknown email addresses, not from familiar official emails of these companies. All such letters contain the attached file, which is used as a ransomware carrier. If you open this file – your system will get infected by MedusaLocker.

In case of trojans presence, you will be offered to download and install ransomware on your PC under the guise of something legit, like a Chrome update, or update for the software you are storing on your computer. Sometimes, trojan viruses can be masked as legit programs, and ransomware will be offered for download as an important update, or a big pack of extensions which are essential for proper program functioning.

There is also the third way of ransomware injection, however, it becomes less and less popular day-to-day. I am talking about peering networks, such as torrents or eMule. No one can control which files are packed in the seeding, so you can discover a huge pack of different malware after downloading. If circumstances force you to download something from peering networks – scan every downloaded folder or archive with antivirus software.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest