How to Remove Craze Ransomware
Craze ransomware is the name of a newly discovered strain of file-encrypting malware. There are no indications that the ransomware belongs to any of the big ransomware families.
Once it encrypts affected files, the Craze will append a string of four randomly chosen alphanumeric characters past the original extension. This means that a file originally named "picture.jpg" will transform into something similar to "picture.jpg.ki8q" once it has been encrypted.
The ransomware affects the same filetypes as most of its ilk - popular media formats, archive files and documents, as well as databases. Once encryption completes, the ransom note is dropped inside a plain text file named "RESTORE-MY-FILES.TXT".
The full text of the ransom note is as follows:
All of your important files are encrypted!
Any attempts to restore your files with the third-party software will be fatal for your files.
YOU CAN ONLY RESTORE YOUR FILES AND DATA BY BUYING THE PRIVATE KEY FROM US.
For more details, you must follow these steps to decrypt your files:
Write to our email: encrypt-craze at protonmail dot com (If you want to test the decryption, also send with your 3 files as an example, so we can decrypt and restoring it for you. Expect reply from us in 24-48 hours.)
Send 20 ETH (Ethereum) to this address: [alphanumeric string]
If you have transferred the ETH, send us confirmation email. After we have confirmed the funds on the blockchain, we will send the private key so you can fully decrypt/restore all of your files by yourself. (We will also include the tutorial how to do it.)
You have 7 days to restore your encrypted files. If in 7 days we still didn't receive the funds, the files will be permanently encrypted, our private key will then no longer work.
Negotiate are accepted, just write to our email above.
Of course, negotiating with criminals is never a smart move and restoring files from an offline backup remains the best option.