Bdat Ransomware 🔐 (. Bdat File) — Removal Guide

What is Bdat virus?

The scheme of renaming is this: victim_id.[contact_email].bDAT. In the course of encryption, a file entitled, for example, “report.docx” will be altered to “report.docx.id-9ECFA84E.[].bDAT”.

In every directory containing the encoded files, a info.txt text file will be created. It is a ransom money note. Therein you can find information on the ways of paying the ransom and some other information. The ransom note usually contains a description of how to buy the decryption tool from the Bdat developers. You can obtain this decrypting software after contacting by email. That is how they do it.

NameBdat Virus
Ransomware family1Dharma ransomware
Extension.bDAT
Ransomware noteinfo.txt
Contact
Detection2PUA:Win32/Pearfoos.B!ml, Trojan.Ransom.Agent.DT, MSIL/Kryptik.ACRC
SymptomsYour files (photos, videos, documents) get a .bDAT extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Bdat virus

The info.txt document coming in package with the Bdat ransomware provides the following dispiriting information:

all your data has been locked us
You want to return?
write email  or  

In the screenshot below, you can see what a directory with files encrypted by the Bdat looks like. Each filename has the “.bDAT” extension added to it.

That is how encrypted “.bDAT” files look.

How did my machine catch Bdat ransomware?

There are currently three most popular methods for hackers to have ransomware working in your system. These are email spam, Trojan injection and peer-to-peer file transfer.

If you access your inbox and see emails that look like familiar notifications from utility services providers, postal agencies like FedEx, Internet providers, and whatnot, but whose addresser is strange to you, be wary of opening those letters. They are most likely to have a viral file attached to them. Therefore, it is even riskier to download any attachments that come with letters like these.

Another thing the hackers might try is a Trojan horse scheme3. A Trojan is an object that gets into your PC pretending to be something different. For instance, you download an installer of some program you want or an update for some service. But what is unboxed turns out to be a harmful agent that compromises your data. As the installation package can have any name and any icon, you have to make sure that you can trust the source of the stuff you’re downloading. The best way is to use the software developers’ official websites.

As for the peer-to-peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is a good idea to scan the folder containing the downloaded files with the anti-malware utility as soon as the downloading is done.

Alexander Ross

Alexander Ross

Gaming, Esports & Interactive Media Writer

Alexander Ross has covered the video game industry for a decade, writing deep dives on game design, esports tournaments, VR developments, and gaming culture.

Share this article
Twitter Facebook Pinterest