[[email protected]].dqb Ransomware - How to remove

Dqb files — files marked with the “.dqb” extension — are a symptom of a file-locking virus infection. The ransomware responsible has been dubbed Dqb. It renames the files by adding some letters and numbers, .id-[random].[[email protected]].dqb, to their names, but the harm doesn’t end here. File-locking ransomware encrypts the content of each file, either partially, or wholly, to make them unusable. And, while the files are fixable in theory, they don’t always get restored in practice.

A new Dharma ransomware variant, Dqb is very similar to Qbx, Adobe, and Harma, as well as a few others that use this same type of virus to extort people. Dqb in particular is distributed by people behind the email addresses [email protected] and [email protected]. Not much is known about the Dharma virus, but the people distributing it and taking money from the victims are surely criminals, even if it is difficult to catch them.

How Dqb is distributed

Dqb targets Windows computers. One of the ways that it is distributed is using Remote Desktop. If Remote Desktop is allowed, it allows a person who has the correct username and password to access your computer or server and do nearly anything: install software, set up a backdoor, read and delete files. Criminals and online extortionists can break into some systems by finding available RD connections and brute-forcing the credentials. These are targeted attacks, usually aimed at small businesses and organizations that can’t afford to lose their files.

Another way that Dqb is distributed is through infected programs and files, like software cracking programs. Downloading suspicious software is always risky because ransomware, miners, and trojans sometimes hide in these programs. No computer that has important and not-backed data on it should be experimented on by downloading and installing software that’s not guaranteed to be safe. Anyone is vulnerable to this type of distribution — businesses as well as individual users.

Options for fixing the files

Dqb uses cryptography to modify files in such a way that, while the data that makes them up is still preserved, it’s scrambled and the files become unusable — broken. Some amateur cryptovirus creators make mistakes while implementing the process and leave behind weaknesses that allow fixing the files. However, Dharma is a long-established ransomware strain that hasn’t been solved yet, which indicates that its encryption is very secure.

There is no free decryptor available for the modern Dharma variants, despite a couple of the oldest versions having them. Due to the popularity of Dharma, it’s possible that a decryptor for Dqb and the other versions is developed in the future, but it’s unlikely. Still, keep an eye on nomoreransom.org and keep copies of the broken files. They’re not dangerous, it’s fine to leave them.

A few possible strategies of restoring your files are listed in the guide below this post (data recovery, shadow copies), but they probably won’t successfully restore all of your files. If you’re tempted to contact the criminals and pay the ransom with the hope that all data is fixed, you should be extremely careful:

  • The ransom is going to be big, probably at least a few Bitcoins, which works out to a few thousand or tens of thousands of dollars.
  • The money goes to finance criminal activities, encouraging the criminals to stay in this “business” and attack more people.
  • There are many victims who don't get back their files despite paying their ransom.
  • Paying won’t remove Dqb or whatever access the criminals have to your system. They might use your willingness to pay and their knowledge of your system to reinfect your computers later.
  • Do not use the infected machines for anything important, like banking, until after you have made sure that no unknown and potentially unwanted programs are left on your computers.

However, if you have backups of the infected files, you don’t need to worry about how to fix them. Even if you lose a few hours or even days of work, there are many victims of Dqb in a much worse situation. Having good quality data backups is the main way to defend oneself against ransomware.

[btcdecoding@qq.com].dqb ransom not screenshot

How to remove Dqb ransomware

Dqb can be removed automatically (Spyhunter), but it’s very important to review any of your suspicious files. If Dqb was installed on your machine by the criminals, they likely left behind more than one malicious file. Some victims of Dharma have experienced unexpected repeat infection weeks or months after the first one because they didn’t remove it the first time thoroughly enough.

There is no way to guarantee that Dqb and other ransomware won’t every infect you. Still, a few important measures should be taken:

  • Securing your Remote Desktop connection — limiting it to certain people, securing it with VPN, etc.
  • Protecting yourself online — malvertising is also used to spread ransomware.
  • Avoiding suspicious websites and software, at least on computers that you don’t want infected.
  • Removing all malware and having a strong antivirus program installed.
  • Updating the operating system, browser, and other programs, or at least installing the important security patches.
  • Most importantly. setting up and frequently updating secure backups that are not accessible for a virus.

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,


How to recover [[email protected]].dqb Ransomware encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:


for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode
 

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again.CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before Dqb Ransomware has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3
 

Step 2. Complete removal of Dqb

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Spyhunter and remove all malicious files related to [[email protected]].dqb. You can check other tools here.  

Step 3. Restore [[email protected]].dqb Ransomware affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually Dqb Ransomware tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so. Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer. a) Native Windows Previous Versions Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.
Previous version
b) Shadow Explorer It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover Dqb encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:
  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download a data recovery program.
  • Install and scan for recently deleted files. Data Recovery Pro
Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.
Leave a Reply

Your email address will not be published. Required fields are marked *