Eyedocx Ransomware 🔐 (. Encrypted File) — Removal Guide

What is known about the Eyedocxvirus?

Eyedocx adds its extra .encrypted extension to every file’s name. For instance, a file named “photo.jpg” will be changed to “photo.jpg.encrypted”. In the same manner, the Excel file with the name “table.xlsx” will end up as “table.xlsx.encrypted”, and so on.

In each folder with the encoded files, a readme.information.txt file will appear. It is a ransom money note. Therein you can find information on the ways of contacting the racketeers and some other remarks. The ransom note usually contains a description of how to purchase the decryption tool from the ransomware developers. That is pretty much the scheme of the malefaction.

NameEyedocx Virus
Extension.encrypted
Ransomware notereadme.information.txt
Detection1Win32:Vitro [Inf], Backdoor:ASP/Chopper.F!dha, Ransom:Win32/Multiverze
SymptomsYour files (photos, videos, documents) have a .encrypted extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Eyedocx virus

In the screenshot below, you can see what a directory with files encrypted by the Eyedocx looks like. Each filename has the “.encrypted” extension appended to it.

An example of encrypted .encrypted files.

How did my machine catch Eyedocx ransomware?

Nowadays, there are three most popular methods for evil-doers to have the Eyedocx virus acting in your system. These are email spam, Trojan introduction and peer-to-peer file transfer.

If you access your inbox and see letters that look like familiar notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, beware of opening those letters. They are very likely to have a malicious item attached to them. Thus it is even more dangerous to download any attachments that come with letters like these.

Another thing the hackers might try is a Trojan horse scheme2. A Trojan is an object that infiltrates into your machine pretending to be something legal. For example, you download an installer for some program you want or an update for some service. However, what is unboxed turns out to be a harmful agent that encodes your data. As the installation wizard can have any name and any icon, you’d better be sure that you can trust the resource of the things you’re downloading. The optimal way is to use the software developers’ official websites.

As for the peer-to-peer networks like torrents or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded items with the anti-malware utility as soon as the downloading is finished.

David Miller

David Miller

Executive Financial & Market Analyst

David Miller brings 15 years of experience in global economics, personal finance strategy, and market dynamics. He specializes in turning complex economic trends into actionable insights for everyday readers.

Share this article
Twitter Facebook Pinterest