TheDRM Ransomware ([email protected]) - How to remove

TheDRM is a relatively new family of ransomware. It was discovered in December 2019. It includes variants named DMR64, Clown, Notfound, and a few other ones. This ransomware changes the names of your files and encrypts them to make them unreadable. Then it asks you for money to fix those files.

TheDRM symptoms and removal:

Classification Ransomware.
TheDRM infection symptoms Files are renamed to a pattern [email][id-{random}]{old file name}.{old extension}.{new extension},

files don’t open with or without a normal extension,

ransom notes can be found in various folders.

How to remove TheDRM Delete the file that infected your computer,

remove malware with antivirus programs (like SpyHunter).

Fix the files Restore from backups,

use shadow volume copies,

use data recovery programs,

put the encrypted files away and wait to see if a free decrypter is developed.

TheDRM infection symptoms

After encrypting your files, TheDRM changes their names to include the criminals’ email address and the new extension. For example, if your file used to be called filename.txt, TheDRM will change that to [[email protected]][id=12345678]filename.txt.notfound or something similar. If many of your files were renamed this way, your computer may have been infected with TheDRM.

TheDRM should put ransom notes in many of your folders. These notes are named HOW TO RECOVER ENCRYPTED FILES.txt and !!! READ THIS !!!.hta. They urge you to contact the people who made this ransomware. So far, the addresses used by TheDRM include [email protected], [email protected], and [email protected]. The notes also promise to decrypt one small file for free and tell victims to buy Bitcoins – because cryptoextortionists usually take their ransoms in Bitcoin.

Make copies of a few of the renamed files. Then change the file’s name to normal – the old file name and the old extension. If the file doesn’t open, it’s been encrypted by TheDRM.

As long as TheDRM is not removed, it could continue to mess with your computer and encrypt new files that you create.

How ransomware infects computers

Even if you have good antivirus protection, it may not save you form TheDRM. Clown (VirusTotal link) and Notfound (VirusTotal link) viruses are recognized by antivirus programs, but that recognition is not as good as it could be yet. Antiviruses sometimes don’t immediately recognize new infections. So, it’s possible that your antivirus program could have let TheDRM slip through. Especially if you don’t have the newest updates installed.

TheDRM uses ransom notes similar to Dharma's but they're not related.

TheDRM can spread in a few different ways:

  • malicious spam emails,
  • pirated files and programs,
  • fake updates and installers distributed by malicious ads.

Malicious spam is one of the main ways that ransomware, as well as some trojans, can infect computers. These could be emails telling you that they’re carrying an invoice or a new bill. Or they could be urgent bank statements or documents from your job – supposedly. These emails don’t contain details like your name because they’re spam that’s sent out to thousands of people. The attached files aren’t important documents, they’re malware, like a TheDRM installer.

Pirate sites have been used to spread ransomware, as well. Especially Djvu, one of the most popular ransomware families in the world in 2019. With this method, ransomware is uploaded online as some useful file or program. People download and then get their computer infected.

Malicious ads could also be responsible for your TheDRM infection. For example, they were used for Matrix. Ads like that could appear on infected sites and automatically download and execute TheDRM.

How to remove TheDRM and fix your files

A competent anti-malware program, such as SpyHunter, can remove TheDRM and other malware. You should make sure that whatever file infected your device won’t be run again by accident, so you might need to delete it or put in your antivirus program’s quarantine.

As for restoring your files, it’s not advised to contact the cryptoextortionists on your own. The creators of TheDRM may be able to decrypt your files, but that doesn’t mean that they will. They only care about getting money and with Bitcoin, there is no money-back guarantee. So, don’t put on the line more than you’re willing to lose and still not have your files.

Try restoring your files from a backup if you had one. Try using Shadow volume copies to get back the versions of your files from before the infection. More detailed instructions are below this article. Try out the free options before you consider paying.

Even if you can’t get back your files, you don’t have to give up on them. Put them on a backup and wait. Check Nomoreransom.org from time to time. Encryption is a pretty secure way to hide information, so TheDRM might be impossible to break without each victim getting their unique decryption key from the creators – and paying a lot of money for it. But sometimes, security researchers find a flaw, develop a free decrypter, and release it for free. It’s possible (though unlikely) that, in the next few months, TheDRM will be cracked, too.

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,


How to recover TheDRM Ransomware ([email protected]) encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:


for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode
 

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again.CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before TheDRM Ransomware ([email protected]) has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3
 

Step 2. Complete removal of TheDRM Ransomware ([email protected])

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Spyhunter and remove all malicious files related to TheDRM Ransomware ([email protected]). You can check other tools here.  

Step 3. Restore TheDRM Ransomware ([email protected]) affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually TheDRM Ransomware ([email protected]) tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so. Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer. a) Native Windows Previous Versions Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.
Previous version
b) Shadow Explorer It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover TheDRM Ransomware ([email protected]) encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:
  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download a data recovery program.
  • Install and scan for recently deleted files. Data Recovery Pro
Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.
Leave a Reply

Your email address will not be published. Required fields are marked *