Deadfiles Ransomware 🔐 (. Deadfiles File) — Removal Guide

What is Deadfiles virus?

Deadfiles will add its own .deadfiles extension to the name of every encoded file. For example, an image entitled “photo.jpg” will be turned into “photo.jpg.deadfiles”. Likewise, the Excel sheet named “table.xlsx” will end up as “table.xlsx.deadfiles”, and so forth.

In each directory with the encoded files, a how_to_back_files.html file will be created. It is a ransom money note. It contains information on the ways of paying the ransom and some other information. The ransom note most probably contains instructions on how to buy the decryption tool from the Deadfiles developers. That is how they do it.

NameDeadfiles Virus
Ransomware family1MedusaLocker ransomware
Extension.deadfiles
Ransomware notehow_to_back_files.html
Detection2Backdoor:Win32/Koceg!B, Win32/GenKryptik.DCUC, Trojan:Win32/Raccoon.RI!MTB
SymptomsYour files (photos, videos, documents) have a .deadfiles extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Deadfiles virus

In the picture below, you can see what a directory with files encrypted by the Deadfiles looks like. Each filename has the “.deadfiles” extension appended to it.

That is how encrypted “.deadfiles” files look.

How did Deadfiles ransomware end up on my PC?

There are currently three most exploited ways for evil-doers to have the Deadfiles virus settled in your digital environment. These are email spam, Trojan introduction and peer file transfer.

If you access your mailbox and see emails that look like familiar notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose sender is strange to you, be wary of opening those emails. They are most likely to have a viral file enclosed in them. So it is even more dangerous to download any attachments that come with letters like these.

Another thing the hackers might try is a Trojan horse model3. A Trojan is a program that infiltrates into your machine disguised as something else. Imagine, you download an installer for some program you want or an update for some program. But what is unpacked reveals itself a harmful program that corrupts your data. As the update package can have any title and any icon, you’d better be sure that you can trust the source of the files you’re downloading. The best way is to trust the software developers’ official websites.

As for the peer file transfer protocols like torrents or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded items with the antivirus as soon as the downloading is done.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest