Flash Ransomware 🔐 (. Flash File) — Removal Guide

Flash Ransomware 🔐 (. Flash File) — Removal Guide

Flash virus: what is known so far?

The renaming will be done according to this pattern: [contact_email].flash. In the process of encryption, a file entitled, for instance, “report.docx” will be changed to “report.docx.[].flash”.

In each folder containing the encoded files, a ReadMe_Decryptor.txt text file will be found. It is a ransom money note. It contains information on the ways of contacting the racketeers and some other remarks. The ransom note most probably contains a description of how to purchase the decryption tool from the racketeers. You can obtain this decryptor after contacting via email. That is it.

NameFlash Virus
Ransomware family1Dcrtr ransomware
Extension.flash
Ransomware noteReadMe_Decryptor.txt
Contact
Detection2Win32/Packed.BlackMoon.A suspicious, BScope.TrojanDownloader.Deyma, Mal/Kryptik-BX
SymptomsYour files (photos, videos, documents) have a .flash extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Flash virus

The ReadMe_Decryptor.txt document coming in package with the Flash malware states the following:

To recover data, write here:



Do not modify files - this will damage them.
Test decryption - 1 file 

In the screenshot below, you can see what a directory with files encrypted by the Flash looks like. Each filename has the ".flash" extension added to it.

An example of encrypted .flash files.

How did my computer get infected with Flash ransomware?

There are currently three most popular ways for criminals to have ransomware acting in your digital environment. These are email spam, Trojan introduction and peer-to-peer file transfer.

If you open your mailbox and see letters that look like familiar notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose mailer is strange to you, be wary of opening those emails. They are very likely to have a ransomware file enclosed in them. So it is even riskier to open any attachments that come with emails like these.

Another option for ransom hunters is a Trojan horse scheme3. A Trojan is a program that gets into your PC pretending to be something else. For example, you download an installer for some program you want or an update for some program. But what is unboxed reveals itself a harmful program that compromises your data. As the installation package can have any name and any icon, you have to make sure that you can trust the resource of the things you're downloading. The best thing is to use the software companies' official websites.

As for the peer-to-peer file transfer protocols like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. So you'd better be using trustworthy websites. Also, it is a good idea to scan the folder containing the downloaded objects with the anti-malware utility as soon as the downloading is finished.

Maya Lin-Takahashi
Author

Maya Lin-Takahashi

Maya is a hardware enthusiast who tests and reviews smart home devices, smartphones, wearables, and audio gear. She focuses on practical consumer value and build quality.