Bmo Ransomware (. Bmo Files) — How to Remove Virus?

What is Bmo?

The renaming will be done according to this pattern: id-*******.[email address].bmo. As a part of encryption, a file entitled, for instance, “report.docx” will be turned into “report.docx.id-924CBVA76.[].bmo”.

In each directory that contains the encoded files, a info.txt text document will be found. It is a ransom money memo. It contains information about the ways of paying the ransom and some other remarks. The ransom note most probably contains a description of how to buy the decryption tool from the tamperers. You can obtain this decrypting software after contacting by email. That is it.

NameBmo Virus
Ransomware family1Dharma ransomware
Extension.id-*******.[email address].bmo
Ransomware noteinfo.txt
Contact
Detection2UDS:Trojan-Ransom.Win32.Blocker.vho, VHO:Trojan-Ransom.MSIL.Convagent, BScope.Trojan.Blamon
SymptomsYour files (photos, videos, documents) have a .id-*******.[email address].bmo extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Bmo virus

In the screenshot below, you can see what a directory with files encrypted by the Bmo looks like. Each filename has the “.id-*******.[email address].bmo” extension added to it.

An example of encrypted .id-*******.[email address].bmo files.

How did my machine catch Bmo ransomware?

There are currently three most popular ways for tamperers to have the Bmo virus working in your digital environment. These are email spam, Trojan infiltration and peer-to-peer networks.

If you open your mailbox and see emails that look like familiar notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose sender is unknown to you, beware of opening those emails. They are most likely to have a malware item attached to them. Thus it is even more dangerous to download any attachments that come with emails like these.

Another thing the hackers might try is a Trojan virus model3. A Trojan is an object that infiltrates into your machine pretending to be something else. For instance, you download an installer of some program you want or an update for some service. However, what is unboxed reveals itself a harmful agent that compromises your data. As the installation package can have any name and any icon, you have to make sure that you can trust the resource of the things you’re downloading. The optimal way is to trust the software developers’ official websites.

As for the peer file transfer protocols like torrents or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So you’d better be using trustworthy websites. Also, it is a good idea to scan the folder containing the downloaded items with the anti-malware utility as soon as the downloading is done.

Elena Rostova

Elena Rostova

Lead Health, Wellness & Medical Journalist

Elena Rostova holds a Master's degree in Public Health Journalism. She covers groundbreaking medical research, holistic wellness trends, mental health awareness, and nutritional science.

Share this article
Twitter Facebook Pinterest