Godsomware v1.0 Ransomware

What is Godsomware v1.0 Ransomware?

Godsomware v1.0 Ransomware is a malicious threat that blocks user's screen and displays a ransom note asking to pay for the decryption of user's files the malware claims to have encrypted. The good news is, even if the infection's warning claims otherwise, your data may not be ruined. Our researchers at Anti-spyware-101.com report the malicious application does not encipher user's files. It means the malware only pretends to be damaging user's data to trick him into paying for its decryption. Luckily, we know how to unlock the screen without funding the cybercriminals who developed Godsomware v1.0 Ransomware, and if you want to know how to get rid of it too, you should check the steps available below this report. However, if you wish to find out more about the infection, we encourage you to read our full article too.

Where does Godsomware v1.0 Ransomware come from?

Threats like Godsomware v1.0 Ransomware can be distributed through malicious email attachments, infected software installers, fake updates, harmful pop-up ads, and so on. Consequently, our researchers recommend not to interact with any content found or received via the Internet, if you are no one hundred percent sure where it comes from or that it is harmless. Some ransomware applications enter the system by exploiting its vulnerabilities as well. Thus, we would also advise strengthening the system as much as possible if you want to guard it against similar infections. For instance, you could install a legitimate antimalware tool, change weak passwords, update outdated software, and so on.

How does Godsomware v1.0 Ransomware work?

Since the malicious application creates a value name in the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run directory, it can restart with the operating system. Besides this Registry entry, there should be the infection’s launcher. It is most likely some recently downloaded file, so users should look for it in Downloads and similar folders. As Godsomware v1.0 Ransomware does not need to create a lot of data to settle in and it should not encrypt any files, it might lock the user’s screen right away. Therefore, instead of your screen, you should see a black wallpaper with red letters. It asks to relaunch the malware if it gets closed anyhow as it is the only way to decrypt user’s files. The threat’s window has a Bitcoin address where the user is supposed to make a payment and then click the provided Decrypt button to decipher his data. Needless to say, in this case, it would be a waste of money to pay a ransom, which is why we advise erasing Godsomware v1.0 Ransomware instead.

How to eliminate Godsomware v1.0 Ransomware?

If you feel you are up to the task, you could follow the steps we placed at the end of this paragraph. They will list what you need to do to unlock the screen and remove data related to Godsomware v1.0 Ransomware. Still, if it looks too complicated, keep it in mind you can follow the steps only until you unlock the screen, and then acquire a legitimate antimalware tool that would get rid of the malicious application for you.

Remove Godsomware v1.0 Ransomware

  1. Press the Decrypt button on the malware’s window.
  2. Copy and paste this code: 29b579fb811f05c3c334a2bd2646a27a
  3. Press Ctrl+Alt+Delete when the screen unlocks.
  4. Pick Task Manager and go to Processes.
  5. Search for a process called God Crypt v1.0 or similarly.
  6. Select it and click End Task.
  7. Leave Task Manager.
  8. Click Windows key+E.
  9. Navigate to these paths:
  10. Find the malicious application’s launcher.
  11. Right-click it and select Delete.
  12. Close File Explorer.
  13. Press Windows key+R.
  14. Type Regedit and click Enter.
  15. Find this path: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  16. Search for a value name created by the threat, e.g., Godsomware v1.0.
  17. Right-click this value name and press Delete.
  18. Exit Registry Editor.
  19. Empty your Recycle Bin.
  20. Restart the computer.
    tested removal of Godsomware v1.0 Ransomware*

