Breaking News

  • “ZEUS VIRUS DETECTED” Scam – How to Remove Fully (July 2017) July 7, 2017
  • What Are Copybinary.me Adware Pop-ups and How to Get Rid of It?
  • What is Searchfast.ru Adware and How to Remove It? (July 2017)
  • What Are Copybinary.me Adware Pop-ups and How to Get Rid of It?
  • How to Remove Aleta Ransomware Virus and Recover .aleta Files July 6, 2017
CFOC.ORG

Computers on Focus - Online Security Guide

02:02 pm
18 February 2019
  • Online Security
  • Parasites and Viruses
  • Removal options
  • Bugs and Fixes
  • Ransomware

.Merry File Ransomware Remove and Decrypt Files for Free

Ransomware | January 30, 2017 | 0 | by George Smith

Review

Danger Level

Widely Spread but Decryptable

Download an Advanced Removal Tool, to eliminate .Merry Ransomware ransomware.
For decryption instructions, it is advisable to read this article thoroughly.

A virus which was initially detected in the beginning of 2017, known as Merry Christmas has come up with it’s latest version, using the .MERRY file extension. The ransomware aims to encrypt the files on the infected computers and then ask users to read the “MERRY_I_LOVE_YOU_BRUCE.HTA” which It drops after encryption. In the file, there are instructions on how to pay the ransom fee and restore the encrypted files this way. But, do not be worried, because this ransomware type of infection is now decryptable. If you want to remove Merry X-mas ransomware and decrypt your files for free, we recommend to read our article about it.

What Does Merry Christmas .MERRY File Virus Do?

After it has already caused an infection, the ransomware virus adds it’s own ransom note and changes the wallpaper of the infected computer to the following “evil Santa” image.

ransomware-merry-x-mas-sensorstechforum-2

The note which the virus leaves is called MERRY_I_LOVE_YOU_BRUCE.HTA and it has the following content:

ALL COMPUTER DATA ENCRYPTED
TIME AFTER ALL FILES WILL BE DELETED
YOUR ID
NOW YOU NEED TO PAY TO RECOVER YOUR DATA
AFTER MONEY TRANSFER YOU WILL RECIEVE THE DECRYPTOR
CONTACTS
TELEGRAM @comodosecunty
EMAIL comodosec@yandex.com
Any attempts to return your files with the third-party tools can be fatal for your encrypted files! The most part of the third-party software change data within the encrypted file to restore it but this causes damage to the files.
Finally it will be impossible to decrypt your files! There are several plain steps to restore your files but if you do not follow them we will not be able to help you!

But this is not where the terror of this ransomware infection end. The malware is also capable of performing several other activities such as deleting the shadow copies by inserting variants of the following command:

vssadmin delete shadows /for={volume} /shadow={id} /quiet

In addition to this, after infection, the malware also cuts out any internet connection, because it deletes drivers of your local network. This type of danger is new and completely different from what has been met before. Luckily, the virus is decryptable.

How Did I Get Infected with This Virus
To get infected with this ransomware virus, one does not need much. All it takes is to open a malicious e-mail and to not have any anti-malware protection installed. Usually the .MERRY ransomware virus may come standard with the infection method – as a malicious e-mail attachment which may pretend to be a document or another type of file. Most inexperienced users are misled that this is an actual e-mail from legitimate services, like PayPal, e-Bay and other companies and open the attachment.

From there, the infection sets off. The .MERRY ransomware creates mutexes, “touches” files and modifies(deletes) or adds new registry values that make it’s executable to encrypt files on system startup, for example.

The virus may also connect to a remove C2 server and download the payload of .MERRY ransomware after which place it in crucial Windows directories, such as:

  • %AppData%
  • %Roaming%
  • %Local%
  • %LocalRow%

How To Remove .Merry Extension Virus and Decrypt The Files

In order to remove this ransomware virus, we strongly urge you to follow our removal instructions below. For maximum effectiveness and automatic and fill removal, experts recommend using an anti-malware software. Furthermore, after having removed the .Merry file extension ransomware, you may want to focus on decrypting your files, web link for which you can find in the red box below.

Booting in Safe Mode

For Windows:
1) Hold Windows Key and R
2) A run Window will appear, in it type “msconfig” and hit Enter
3) After the Window appears go to the Boot tab and select Safe Boot

Cut out .Merry Ransomware in Task Manager

1) Press CTRL+ESC+SHIFT at the same time.
2) Locate the “Processes” tab.
3) Locate the malicious process of .Merry Ransomware, and end it’s task by right-clicking on it and clicking on “End Process”

Eliminate .Merry Ransomware‘s Malicious Registries

For most Windows variants:
1) Hold Windows Button and R.
2) In the “Run” box type “Regedit” and hit “Enter”.
3) Hold CTRL+F keys and type .Merry Ransomware or the file name of the malicious executable of the virus which is usually located in %AppData%, %Temp%, %Local%, %Roaming% or %SystemDrive%.
4) After having located malicious registry objects, some of which are usually in the Run and RunOnce subkeys delete them ermanently and restart your computer. Here is how to find and delete keys for different versions.
For Windows 7: Open the Start Menu and in the search type and type regedit –> Open it. –> Hold CTRL + F buttons –> Type .Merry Ransomware Virus in the search field.
Win 8/10 users: Start Button –> Choose Run –> type regedit –> Hit Enter -> Press CTRL + F buttons. Type .Merry Ransomware in the search field.

Automatic Removal of .Merry Ransomware

DOWNLOAD REMOVAL TOOL FOR .Merry Ransomware
The free version of SpyHunter will only scan your computer to detect any possible threats. To remove them permanently from your computer, purchase its full version. Spy Hunter malware removal tool additional information/SpyHunter Uninstall Instructions

Decrypt Files Encrypted by The .Merry Ransomware Ransomware.

For the decryption, please follow this web link:

https://decrypter.emsisoft.com/mrcr

Share on Facebook Share
0
Share on TwitterTweet
Share on Google Plus Share
0
Send email Mail
.Merry File ExtensionHow-ToMerry X-Mas VirusransomwareWindows

About the Author

George Smith

George Smith

View all posts by George Smith →
Previous
Sage 2.0 Ransomware Virus Removal Guide
Next
.CryptoShield 1.0 File Virus – Remove and Restore Data

Related Posts

  • .rumba Files Ransomware – Remove + Restore Data

  • .tfudet File Virus – Remove + Restore Files (Update 2019)

  • .tfude File Ransom Virus – How to Delete (+Restore Files)

  • GANDCRAB 5.1 Virus – Remove + Try and Restore Data

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload the CAPTCHA.

Follow us:

  • Facebook
  • Google+
  • RSS
  • Twitter
  • YouTube
google-safety-center

Categories

  • Bugs and Fixes (32)
  • Online Security (182)
  • Parasites and Viruses (91)
  • Ransomware (170)
  • Removal options (108)

Tags

ransomware malware file encryption adware PUP remove browser hijacker breaking news Trojan virus pop-ups vulnerability Microsoft Google Windows
February 2019
M T W T F S S
« Jan    
 123
45678910
11121314151617
18192021222324
25262728  

Latest Posts

  • .rumba Files Ransomware – Remove + Restore Data

    January 22, 2019 | 0
  • .tfudet File Virus – Remove + Restore Files (Update 2019)

    January 21, 2019 | 0
  • .tfude File Ransom Virus – How to Delete (+Restore Files)

    January 21, 2019 | 0
  • $1000 Walmart Gift Card Scam “Virus” – How to Get Rid of It?

    January 21, 2019 | 0
  • 1-800-772-1213 Social Security Scam – How to Stop and Remove

    January 21, 2019 | 0
All CFOC Removal Guides | Why SpyHunter Anti-Malware Tool | About us | Contact us