Bitcoinpayment Virus 🔐 (. Bitcoinpayment Files) — How to Remove?
Bitcoinpayment Virus: What Is Known So Far? the Scheme of Renaming Is the Following: Id[Xxxxxxx]. [Contact_Email]. Bitcoinpayment. in the Course of Encryption...
Bitcoinpayment virus: what is known so far?
The scheme of renaming is the following: id[xxxxxxx].[contact_email].BITCOINPAYMENT. In the course of encryption, a file entitled, for instance, “report.docx” will be renamed to “report.docx.id[9ECFA84E-1095].[].BITCOINPAYMENT”.
In each directory that contains the encrypted files, a info.txt text file will be created. It is a ransom money note. It contains information about the ways of paying the ransom and some other remarks. The ransom note most probably contains instructions on how to purchase the decryption tool from the tamperers. You can get this decrypting software after contacting via email. That is how they do it.
| Name | Bitcoinpayment Virus |
| Ransomware family1 | Phobos ransomware |
| Extension | .BITCOINPAYMENT |
| Ransomware note | info.txt |
| Contact | |
| Detection2 | Multi:Filecoder-H [Trj], Backdoor:Win32/Dridex.AA!MSR, Trojan.MalPack.FFS |
| Symptoms | Your files (photos, videos, documents) have a .BITCOINPAYMENT extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Bitcoinpayment virus |
The info.txt document coming in package with the Bitcoinpayment malware states the following:
Want return your files?Write to our xmpp account - The easiest way - register here hxxps:// After download pidgin client hxxps:// Press Add account,choose protocol xmpp and put username from xmpp.jp where are you sign up Domain - xmpp.jp Put your password and press add When you log in press Buddies --> Add Buddy-->and in Buddys username put cleverhorse xmpp.jp After you will see added account ,click twice on it and write your message You can send us 1-3 test files. The total size of files must be less than 10Mb (non archived), we will decrypt them and send to you that we are real If you have a problem with xmpp you can write to our mail
In the picture below, you can see what a folder with files encrypted by the Bitcoinpayment looks like. Each filename has the “.BITCOINPAYMENT” extension added to it.
How did my computer get infected with Bitcoinpayment ransomware?
There are currently three most exploited ways for evil-doers to have ransomware planted in your digital environment. These are email spam, Trojan injection and peer-to-peer networks.
If you access your inbox and see emails that look like familiar notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose sender is unknown to you, beware of opening those emails. They are most likely to have a malicious item enclosed in them. Therefore, it is even riskier to download any attachments that come with emails like these.
Another option for ransom hunters is a Trojan horse scheme3. A Trojan is a program that infiltrates into your PC disguised as something else. For instance, you download an installer for some program you want or an update for some software. But what is unboxed turns out to be a harmful program that encodes your data. As the update file can have any title and any icon, you’d better be sure that you can trust the resource of the files you’re downloading. The best thing is to use the software companies’ official websites.
As for the peer-to-peer file transfer protocols like torrent trackers or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So you’d better be using trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded files with the anti-malware utility as soon as the downloading is done.