. Non Files Encrypted (Non Virus) — How to Remove?

What is Non virus?

The renaming will be done according to the following pattern: victim’s_ID.contact_email.Non. During the encryption, a file named, for example, “report.docx” will be changed to “report.docx.id[9ECFA84E-3268].[].Non”.

In each folder that contains the encrypted files, a info.txt file will be found. It is a ransom money note. It contains information on the ways of paying the ransom and some other remarks. The ransom note usually contains a description of how to buy the decryption tool from the racketeers. You can obtain this decoding tool after contacting by email. That is it.

NameNon Virus
Ransomware family1Phobos ransomware
Extension.Non
Ransomware noteinfo.txt
Contact
Detection2Trojan:Win32/FormBook.RR!MTB, Ransom:Win32/Cerber, Trojan-Ransom.Win32.Wanna.apno
SymptomsYour files (photos, videos, documents) get a .Non extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Non virus

The info.txt file coming in package with the Non malware provides the following discouraging information:

!!!All of your files are encrypted!!!
To decrypt them send e-mail to this address: .
If we don\'t answer in 24h., send e-mail to this address:  

In the screenshot below, you can see what a directory with files encrypted by the Non looks like. Each filename has the “.Non” extension appended to it.

An example of encrypted .Non files.

How did Non ransomware end up on my PC?

There are currently three most popular methods for malefactors to have ransomware working in your system. These are email spam, Trojan injection and peer-to-peer networks.

If you access your mailbox and see emails that look just like notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose sender is unknown to you, beware of opening those emails. They are very likely to have a malicious file enclosed in them. Therefore, it is even riskier to open any attachments that come with emails like these.

Another option for ransom hunters is a Trojan file model3. A Trojan is an object that gets into your machine pretending to be something legal. For example, you download an installer of some program you need or an update for some program. However, what is unboxed reveals itself a harmful agent that encodes your data. As the installation file can have any name and any icon, you’d better be sure that you can trust the resource of the files you’re downloading. The best thing is to use the software developers’ official websites.

As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded items with the anti-malware utility as soon as the downloading is done.

Alexander Ross

Alexander Ross

Gaming, Esports & Interactive Media Writer

Alexander Ross has covered the video game industry for a decade, writing deep dives on game design, esports tournaments, VR developments, and gaming culture.

Share this article
Twitter Facebook Pinterest