Asistchinadecryption Ransomware — How to Remove Virus?

Asistchinadecryption virus: what is known so far?

The scheme of renaming is the following: asistchinadecryption.[victim\’s_ID]. After the encryption, a file named, for instance, “report.docx” will be turned into “report.docx.asistchinadecryption.ID103HBFU138”.

In each folder that contains the encrypted files, a !!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT text document will appear. It is a ransom money note. Therein you can find information about the ways of paying the ransom and some other remarks. The ransom note usually contains a description of how to purchase the decryption tool from the tamperers. That is it.

NameAsistchinadecryption Virus
Ransomware family1Zeppelin ransomware
Extension.asistchinadecryption.[victim\’s_ID]
Ransomware note !!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT
Detection2Win32:Xpirat-C [Inf], Win32:ReposFxg-F [Trj], Win64/CoinMiner.AEF
SymptomsYour files (photos, videos, documents) get a .asistchinadecryption.[victim\’s_ID] extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Asistchinadecryption virus

In the image below, you can see what a directory with files encrypted by the Asistchinadecryption looks like. Each filename has the “.asistchinadecryption.[victim\’s_ID]” extension appended to it.

That is how encrypted “.asistchinadecryption.[victim\’s_ID]” files look.

How did Asistchinadecryption ransomware end up on my PC?

Nowadays, there are three most popular ways for evil-doers to have the Asistchinadecryption virus settled in your digital environment. These are email spam, Trojan infiltration and peer networks.

If you open your inbox and see emails that look like familiar notifications from utility services companies, postal agencies like FedEx, Internet providers, and whatnot, but whose addresser is strange to you, be wary of opening those letters. They are very likely to have a ransomware file enclosed in them. So it is even riskier to download any attachments that come with letters like these.

Another option for ransom hunters is a Trojan file model3. A Trojan is an object that gets into your machine pretending to be something different. For example, you download an installer of some program you need or an update for some software. However, what is unboxed turns out to be a harmful program that corrupts your data. As the installation package can have any name and any icon, you have to make sure that you can trust the source of the files you’re downloading. The best way is to use the software companies’ official websites.

As for the peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. So you’d better be using trustworthy resources. Also, it is reasonable to scan the folder containing the downloaded objects with the anti-malware utility as soon as the downloading is complete.

Sophia Al-Mansoor

Sophia Al-Mansoor

Global Business & E-Commerce Reporter

Sophia analyzes international trade, startup ecosystems, retail transformation, and supply chain logistics for modern digital publications.

Share this article
Twitter Facebook Pinterest