How to Safely Detect and Remove Quax0r Ransomware

Quax0r ransomware is a new variant of file-encrypting malware that belongs to the Rozbeh family of ransomware.

Part of the Quax0r ransomware behavior is the same as other families and variants - it encrypts common file types, leaving them unusable. Commonly used file types are affected by the encryption, including media, archive and document files.

What Quax0r does differently compared to almost every other strain of ransomware is how it handles encrypted files. Almost every strain of ransomware changes the extensions and names of files, usually appending victim ID strings and new extensions to the files. With Quax0r, none of this takes place - the ransomware leaves the encrypted file looking exactly the same as it did before - without any change to the filename or extension.

Quax0r also does not drop its ransom note inside a text file but instead uses the command prompt window. The full text of the message is as follows:

All files have been encrypted by NominatusCrypto ( Quax0r ) contact the creator of this virus on discord Nominatus#9251 for more information if you restart then your account will be useless! files cannot be decrypted without paying the ransom to the creator!! live or die? make your choice now!

With no sum listed in the ransom note and what looks like a script kiddie using a Discord account for their criminal activity, trying to negotiate with the author of the Quax0r is not advisable and offline backups remain the best option for restoring files.

June 3, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.