How to remove Mobef-Salam Ransomware and decrypt files

What is Mobef-Salam ransomware

A Mobef-Salam is a terrible ransomware, which may cause many troubles for user. The malicious program, also called file encryptor. First of all it codes all data files on users PC and inserts into filenames a random extension. Files with next extensions: JPG, DOC, MP3 others are opened in coded unreadable form. Be careful, Mobef-Salam ransomware can encode all new files, that you try to copy on infected system. Besides, virus creates RED.4YOU file, where cybercriminal requires money for decoding:
COMPUTER: [redacted] LOGIN: [redacted] *******
salam. haha sorry i kript ur filez. they safe, so no needs w0rring. but u cant break my l33t cipher, if u wanna back filez email me quick 0k? you pay me bitcoins...
maktoob786@takfir24.net
byezzzzz
c:\windows\2xxxxx.log

Antivirus programs without online scanner usually miss the moment of infiltration. Unfortunately, there are no universal tools capable of restoring all files, encrypted by a Mobef-Salam ransomware. Despite this, we urged you not to pay to cybercriminals, because it can increase a number of new PC threats, that you can met in future. Our advice is creating back up of all important data on your PC to prevent damage from a virus. Mobef-Salam ransomware is very similar to Mobef ransomware. In our guide, we will subscribe how to remove Mobef-Salam ransomware and decrypt files.
Mobef-Salam ransomware

How Mobef-Salam ransomware gets on your PC?

This type of virus can be infiltrated through a freeware software, spam messages, trojans, software from dangerous sources, etc. A process of installation can start hidden and automatically. Besides that, some malware programs can mark Mobef-Salam Ransomware as a trusted software program.

Symptoms of Mobef-Salam ransomware infection

It’s difficult not to notice ransomware since it often has one of the processes responsible for displaying a notification message. Besides, some files will be inaccessible, a virus creates notes named How Recovery Files.txt.The message contains following text:

Hello!
All your files have been encrypted by us
If you want restore files write on e-mail - frenkmoddy@tuta.io

In latest version of virus can be modified message:

Hello!
All your files have been encrypted by us
If you want restore files write on e-mail - paymeme@cock.li or paymeme@india.com
Your ID:
***
Send me your ID and 1-3 small encrypted files(The total size of files must be less than 1Mb (non archived)) for free decryption.
After that, I'll tell you the price for decryption all files.

What to do if your PC is infected with Mobef-Salam ransomware

As soon as you notice the presence of the ransomware on your system, you should turn your computer off. If it is possible to try to create a backup or image of your hard drive info. This may let you to reserve the state of your drives in case a decryption method would be created afterward.

How to remove Mobef-Salam ransomware?

To make sure that the adware won’t reappear, you need to delete Mobef-Salam ransomware completely. For this you need to remove the files and registry entries of the ransomware. We should warn you that performing some of the steps may require above-average skills, so if you don’t feel experienced enough, you may apply to automatic removal tool.

Download SpyHunter

Performing an antimalware scan with Norton would automatically search out and delete all elements related to Mobef-Salam ransomware. It is not only the easiest way to eliminate Mobef-Salam ransomware, but also the safest and the most assuring one.

Steps of Mobef-Salam ransomware manual removal

Restart Windows in Safe Mode

For Windows XP:

  1. Restart the system
  2. While computer is rebooting press F8 several times
  3. In the appeared list of options choose Safe Mode

For Windows 7 and Vista:

  1. Restart the system
  2. While computer is rebooting press F8 several times
  3. In the appeared list of options choose Safe Mode

For Windows 8 and 8.1:

  1. Restart the system
  2. While computer is rebooting press F8 several times
  3. In the appeared list of options choose Safe Mode

For Windows 10:

  1. In the Start menu click on the power button
  2. Hold Shift and choose Restart
  3. Choose Troubleshoot
  4. In the Advanced Options choose Startup Settings
  5. Click Restart
  6. Select Enter Safe Mode

How to decrypt and restore files

Use the decrypting tool

Unfortunately, currently a tool able to decrypt files is not released yet. You may try applying to the methods described below, however, they might not work with the latest versions of Mobef-Salam ransomware.

Restore files with an automatic tool

For those types of ransomware viruses that rather remove files than encrypt them we would suggest using Recuva program.
recuva tool

  1. Download Recuva tool and launch it
  2. Within the on-screen wizard choose the type of the files you want to recover
  3. Choose the location of the files
  4. Wait until the application finishes scanning
  5. Select the required files and click the Recover button

Nevertheless there are no other tools able to restore and decrypt files, you may try applying to the manual methods described below, however, they might not work with the latest versions of Mobef-Salam ransomware.

Restore the system

  1. Initiate the search for system restore
  2. Click on the result
  3. Choose the date before the infection appearance
  4. Follow the on-screen instructions

Roll the files back to the previous version

  1. Right-click the file and choose Properties
  2. Open the Previous Version tab
  3. Select the latest version and click Copy
  4. Click Restore

If the above-mentioned methods didn’t help in eliminating the threat, then it’s better to rely on an automatic way of deleting Mobef-Salam ransomware.

Download SpyHunter

We also recommend to download and use Norton to scan the system after Mobef-Salam ransomware removal to make sure that it is completely gone. The antimalware application will detect any vicious components left among system files and registry entries that can recover Mobef-Salam ransomware.

Leave a Reply

Your email address will not be published. Required fields are marked *