Duck Ransomware ๐Ÿ” (. Duck File) โ€” Removal Guide

What is known about the Duckvirus?

The renaming will be done by the following pattern: id[xxxxxx].[contact_email].duck. In the course of encryption, a file entitled, for example, โ€œreport.docxโ€ will be renamed to โ€œreport.docx.id[9ECFA84E-3316].[].duckโ€.

In every directory containing the encrypted files, a info.txt text file will appear. It is a ransom money note. It contains information about the ways of contacting the racketeers and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. You can obtain this tool after contacting by email. That is how they do it.

NameDuck Virus
Ransomware family1Phobos ransomware
Extension.duck
Ransomware noteinfo.txt
Contact
Detection2Win32/TrojanDownloader.FlyStudio.AY, Trojan:Win32/Vundo!AU, Trojan:Win32/Redline.MKW!MTB
SymptomsYour files (photos, videos, documents) have a .duck extension and you canโ€™t open them.
Fix ToolSee If Your System Has Been Affected by Duck virus

The info.txt file accompanying the Duck malware states the following:

!!!All of your files are encrypted!!!
To decrypt them send e-mail to this address: 
In case of no answer in 24 hours write us to this e-mail:
Our online operator is available in the messenger Telegram: @supprecovery

In the screenshot below, you can see what a folder with files encrypted by the Duck looks like. Each filename has the โ€œ.duckโ€ extension added to it.

That is how encrypted โ€œ.duckโ€ files look.

How did my machine catch Duck ransomware?

Nowadays, there are three most exploited methods for malefactors to have ransomware working in your system. These are email spam, Trojan injection and peer-to-peer networks.

If you open your mailbox and see emails that look like familiar notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose sender is strange to you, be wary of opening those emails. They are most likely to have a ransomware file attached to them. So it is even more dangerous to download any attachments that come with letters like these.

Another thing the hackers might try is a Trojan horse scheme3. A Trojan is a program that gets into your computer pretending to be something different. For example, you download an installer for some program you need or an update for some software. But what is unpacked turns out to be a harmful agent that encodes your data. Since the installation package can have any name and any icon, youโ€™d better be sure that you can trust the source of the stuff youโ€™re downloading. The optimal way is to use the software developersโ€™ official websites.

As for the peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So youโ€™d better be using trustworthy websites. Also, it is reasonable to scan the folder containing the downloaded objects with the antivirus as soon as the downloading is finished.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest