ZAWOOO Ransomware EXPOSED: Random Names and How To Restore Your Files.txt

You open the folder you used yesterday. The vacation photo should be there. The invoice should be there. The tax spreadsheet should be there. Instead the names are gone. In their place sit strings that look like someone spilled a password generator across Documents. One file is called 5BE7D191BE162F03.NnaOfnYs. Another is A91C04E77B12D8F0.kQpLmRvt. A small text file named How To Restore Your Files.txt is sitting in the same place, as if it has always belonged there.

That is the trap, not a glitch. ZAWOOO ransomware locks the files first. Then it throws away both the original filename and the original extension. Then it drops a note that talks like a reputation-minded firm. The note wants Bitcoin. It wants a private chat. It wants you to stay away from the police. It does not print a $ figure. The missing number is not mercy. It is a blank invoice.

This page is for the moment those random names appear. It explains the rename, the note, the reputation costume, the threat to email your customers, and why zawooorecover@onionmail.org is a storefront, not a help desk. It is not a tour of ransomware in general. It is about this strain, the one that turns 1.jpg into 5BE7D191BE162F03.NnaOfnYs and leaves How To Restore Your Files.txt behind.

Encrypted files after ZAWOOO. Random names plus How To Restore Your Files.txt are the tell.
Encrypted files after ZAWOOO. Random names plus How To Restore Your Files.txt are the tell.

Overview

The first tell is the rename. ZAWOOO does not leave vacation.jpg sitting there with a new ending tacked on. It does not keep invoice-2026.pdf in front of a locker brand. It wipes the name you knew and the extension Windows used to open the file. Both halves become random strings. In one published sample, a file named 1.jpg became 5BE7D191BE162F03.NnaOfnYs. The 16-character hex chunk in front is not your old title written in code. The eight-character tail is not a hint you can reverse by guessing. The listing is now a label the locker invented.

That is why the folder still has one object per file, and why the shock lands harder. You can feel that something is still “there.” Double-clicking it does not open the photo. Windows may call the type an NNAOFNYS file, or a KQPLMRVT file, or whatever random tail landed on that object, and then offer a useless “choose an app” box. An app cannot talk those bytes back into a JPEG. Renaming 5BE7D191BE162F03.NnaOfnYs back to 1.jpg does not either.

The second tell is the note. After the files are locked, the malware drops How To Restore Your Files.txt into the same folders. Public notes in this campaign open with a line that sounds almost like branding. You have been attacked by ZAWOOO, “a ransomware that prioritizes reputation.” Then the note tells you that you must pay. It says you may have other file backups, but there is no backup of a customer’s privacy and trust. It says the writers are not a politically motivated group and want only financial rewards. It says that if they defraud even one client, other clients will not pay. That last sentence is doing sales work. It is not a warranty.

Then the note adds the second lock. If you pay, they claim they will fulfill whatever they agreed in the chat. If you do not pay, they say they may send your files, chat history, and mailbox content to all of your customers by email. That is a double-extortion claim aimed at a small business as much as at a home PC. Even a person with clean backups is supposed to sit still and think about clients, patients, or vendors reading a stranger’s dump.

The same file tells you not to go to the police or the FBI, and not to tell anyone you were attacked. It claims those people will forbid payment and will not help, and that your business will die with the files still locked. It coaches you on how to buy Bitcoin without saying why. It tells you to park the coin on a cold wallet. It tells you not to be afraid of legal consequences, because you were “very scared.” Then it offers two contact paths: the Session messenger, and the mailbox zawooorecover@onionmail.org. A published note leaves the Session ID blank. Treat that blank as empty, not as a code you should go hunt.

That is the whole storefront. A folder of random names. A note that sells reputation. A leak threat aimed at your customers. A warning to stay quiet. A Bitcoin lecture with no printed $ amount. A private chat. ESET has used the detection name Win64/Filecoder.AUW for this family. That is a scanner label. It is not a public decryptor. There is no public free decryptor known for ZAWOOO. There is no reason to write to that inbox. There is no reason to pay.

The random names are the first warning

Most lockers pick one extension so you notice the change in seconds. You still see Taxes.xlsx in front of the new ending. ZAWOOO refuses that courtesy. The familiar words leave the listing. The photo that used to be 1.jpg is now 5BE7D191BE162F03.NnaOfnYs. In the same Documents folder you may also see names such as A91C04E77B12D8F0.kQpLmRvt, 0F33AA91C6E204B7.xYwUeNds, and C7E18B4409A2F156.pHtRqMka. Those strings are not a puzzle. They are a billboard that says the original catalog is gone from the filename.

The pattern is easy to miss if you are hunting for a brand you already know. There is no .locked. There is no .encrypted. There is no family name on the end. A person who only glances at the folder can think a sync tool went wrong, or that a disk check renamed things, or that someone ran a “privacy” utility. The note is what makes the pile make sense. Random names plus How To Restore Your Files.txt are the tell.

Do not treat the new strings as a hint you can reverse. Do not paste the old name back onto the file and expect Photos or Excel to open it. Do not run a bulk “filename fixer” you found in an ad. The name is a label. The lock is in the content. Editing the label can make a later trusted tool have a harder time matching the file to what it was. Leave the locked copies as they are until you have a clean machine and a plan that does not start in a criminal inbox.

How To Restore Your Files.txt is a sales floor

The ransom note is a simple text file. The filename is ordinary on purpose. Plenty of real software drops a how-to. This one uses that habit against you. It is meant to be the first thing you double-click when you are already scared and the folder no longer has words you recognize.

The note walks through what they say they did, what they say they took, and what they want you to do next. It is written like a briefing. Short blocks. Arrow marks. A voice that sounds calm and inevitable. Calm is a tactic. Inevitable is a sales claim. The file is not a recovery guide. It is a script that tries to move you from panic to a private chat without a witness.

Part of the note warns you not to delete or modify encrypted files. Part of that warning is self-serving. The authors want you talking to them, not to a real incident responder. Part of it is still a useful caution in the wrong mouth. Mystery decrypt tools from ads can damage files. The useful part of that warning is smaller than the note wants. Do not take technical advice from the attacker. Do not run a paid “decrypt now” app from a search ad. Do not shred the locked copies because the names look like junk.

“Prioritizes reputation” is a costume

ZAWOOO’s note wants to sound like a firm that still has something to lose. “A ransomware that prioritizes reputation” is the line they chose. Then they argue that scamming even one client would ruin future payments. They say they are not politically motivated. They say they want financial rewards for their work. They invite you to treat the ransom as a security test. They promise they will explain the intrusion and give advice, and they say the amount may be cheaper than hiring a real company.

Read that the way you would read a street vendor who broke a lock and then offered to sell you the only spare key, plus a lecture on door hardware. The competence they are selling is the competence they created. Reputation talk is there because fear of being cheated is the main reason people hesitate. If they can talk that hesitation down, the checkout gets easier.

A reputation claim is not a contract. There is no license, no refund window, no manager, and no court you can take them to if the key never arrives. The same people who tell you they would never defraud a client also tell you not to call the police. Those two sentences do not live in the same honest world.

The police warning is isolation, not care

The note is blunt. Do not go to the police. Do not go to the FBI. Do not tell anyone you were attacked. The claimed reason is that officials will forbid payment and will not help, and that you will be left with locked files while the business dies. That story is built to keep you alone with the chat.

Isolation is useful to a seller. A relative might tell you not to pay. An insurer might tell you to preserve evidence. A lawyer might tell you that a leak claim is a crime report, not a checkout problem. A real technician might tell you to stop writing to zawooorecover@onionmail.org. The note tries to cut those people out of the room before they arrive.

Later the same file tries to soothe you about legal risk. It says you were very scared, so you followed the instructions, so it is not your fault. It says no company that paid them has had issues. It says any later excuse is just an insurance company trying not to pay. That paragraph is not legal advice. It is a script that tries to make a Bitcoin transfer feel like self-defense. Do not take law from the people who locked the disk.

The customer-email threat is the second lock

ZAWOOO does not only sell the return of your files. The note says that if you refuse, the writers may email stolen files, chat history, and mailbox content to your customers. That is a specific threat. It is not a leak-site tour. It is the idea that the people who already trust you will get a package from a stranger.

Some ransomware crews do copy files before they encrypt them. Some exaggerate. Some stage a few screenshots and let your imagination do the rest. From the victim’s chair you cannot audit their server. You can only see that they want you thinking about customers, staff, and reputation while you decide whether to open Session. The line about there being “no backup of the customer’s privacy and trust” is there for the person who already has file copies. Backups are supposed to feel useless even when they are not.

Sending more files to “prove” what they already have is how a locker incident becomes a larger data incident. If they truly already have the copy, they do not need you to mail it again. If they do not, your upload is a gift. Either way, the chat is not a forensic lab. Treat the leak claim as pressure, not as a status report you can verify by talking to them.

Session and onionmail.org are the checkout aisle

The note does not send you to a shop with a padlock icon and a return policy. It sends you to Session and to zawooorecover@onionmail.org. Those lines are identifiers. They tell you which campaign you are looking at. They are not a support queue.

Session is a messenger built for private chats. Onionmail is a mailbox people use when they want the address itself to be harder to tie to a name. Both are useful if you are trying to stay hidden. Neither is useful if you are a victim trying to get a receipt, a real name, or a refund. There is no chargeback window on a Session thread. There is no manager to escalate to when the key never arrives.

A published ZAWOOO note tells the victim to install Session and then leaves the Session ID field blank. That blank is not a puzzle for this page to fill in. Do not hunt forums for “the” ZAWOOO Session ID. Do not accept a Session ID from a stranger who claims they already have your case. Anyone who already knows you have random names and How To Restore Your Files.txt can greet you like a case manager. The mailbox in the note is enough of a tell. You do not need to complete their contact form.

Do not install Session “just to see.” Do not attach a file “just to ask a question.” Every message is a signal that a person is sitting in front of the locked machine and is willing to talk. That is the moment the price, the pressure, and the follow-up scams begin.

No $ figure is printed on purpose

A lot of locker notes print a coin amount so the victim can start shopping for Bitcoin before the fear cools. ZAWOOO’s published note does not do that. It says you must pay. It talks about Bitcoin. It coaches you on brokers, cover stories, and a cold wallet. It never writes a USD price. It never writes a BTC amount. The blank is the point.

A missing number lets them invent the bill after they see who you are. A home user with family photos is one conversation. A shop with customer mail is another. The note already asked you to think about clients. The chat is where they can name a $ figure that matches whatever they think you will pay. Treat any later number, in Session or in mail, as a demand. It is not a quote from a vendor with a refund policy. It is not a license fee.

The Bitcoin lecture is also a test. If you start buying coin “just in case,” you have already begun their checkout. The cover stories they suggest, gifts, consulting, inheritance, ICO noise, are there so a broker, a bank, or a relative does not hear the word ransom. Do not help them hide a crime you did not choose. Do not fund a wallet because the note sounded organized.

ESET’s name is a label, not a key

Scanners need a string to print when they see a sample. For this family, ESET has used Win64/Filecoder.AUW. That label is useful when you are trying to tell one locker from another. It is not a decryptor. It does not mean a public key is sitting in a database. It does not mean the files are a known puzzle with a known answer.

Do not collect other product names from random blogs and treat them as extra facts. Detection strings get recycled, guessed, and copied. If your own scanner prints Win64/Filecoder.AUW next to a pile of random names and How To Restore Your Files.txt, you are looking at this campaign. If it prints something vaguer, the folder still tells the story. The names and the note are the tell. The scanner line is backup, not the diagnosis you wait for.

How The Scam Works

You do not need a lab report to understand the sequence. ZAWOOO follows a consumer-facing script that many modern lockers use. It changes the files, hides the catalog, leaves a note that sounds like a firm, threatens the people who trust you, and then tries to keep you away from anyone who would tell you not to pay.

1. Everyday files lose both the name and the extension

The first thing a person notices is not a skull wallpaper. It is a folder that no longer has words. Word documents, photos, tax PDFs, and zip archives still sit in the same places. The labels that used to tell you which was which are gone.

ZAWOOO replaces the original filename and the original extension with random strings. 1.jpg is no longer readable as a one and a picture. It is 5BE7D191BE162F03.NnaOfnYs. The hex-looking front half can change from file to file. The tail can change from file to file. That is why a Documents listing after this strain looks like four or five broken passwords plus one calm text file. The icons may go generic because Windows no longer knows what to do with .NnaOfnYs or .kQpLmRvt. Double-clicking does not open the photo. It does not open the invoice.

Renaming is not decryption. Copying the file to a new folder is not decryption. Zipping the locked files and mailing them to a stranger is not decryption. The locked copies are evidence and, later, the raw material a trusted public tool would need if one ever appears. They are not puzzles you can solve by editing the filename.

2. How To Restore Your Files.txt takes over the conversation

Once the names are gone, the only file that still reads like English is the note. That is by design. A person who cannot find vacation.jpg will open the file that promises restoration. The filename does the first half of the sale before the body does any talking.

The body then does three jobs at once. It names the crew, ZAWOOO. It frames the crew as careful about reputation. It tells you payment is the path, silence is the rule, and a private channel is the next click. A note that starts with “how to restore” and ends with an onionmail address is not confused about its purpose. It is a flyer that borrowed a help-file title.

Keep that file. Screenshot it if you want a second copy. Do not follow it. The difference matters later, when an investigator, an insurer, or a trusted public project asks what you saw. The note is evidence. The contacts inside it are not a to-do list.

3. They sell reputation as if it were a guarantee

The reputation paragraph is the heart of the costume. Other lockers threaten. This one also flatters itself. It says a cheated client would cost them future clients. It says they want money, not politics. It invites you to imagine a shop that still needs reviews.

That story is aimed at a tired owner who is already doing the math. If these people need the next victim to pay, maybe they will unlock this one. If the chat feels professional, maybe the key is real. The note is written to make those maybes feel like due diligence. They are still maybes offered by the person who took the files.

The “security test” line is the same costume in a nicer jacket. Paid decryption, they say, can include a story about how they got in, plus advice, plus a price that might beat a real assessment. A real assessment does not start by locking the disk. A real assessment does not ask you to hide a Bitcoin buy from a broker. A real assessment does not tell you to stay away from the police.

4. They threaten the people who already trust you

The leak half of the note is aimed at anyone who has customers. Files, chat history, mailbox content, sent by email to the people you work with. That list is chosen because it sounds like a small office. Inbox. Chat. Attachments. The fear is not only “my photos are gone.” The fear is “my clients will think I failed them.”

You cannot settle that fear inside the attacker’s chat. Asking them what they stole gives them a map of what you care about. Asking them not to email a specific client tells them which name hurts. Offering a sample mailbox “so they can delete it” hands them a cleaner copy. The people who should hear a leak claim are the ones the note told you not to call.

If you run a shop, a clinic, a firm, or a side business out of the same PC that holds family photos, treat both lives as in scope. The locker does not sort those folders for you. The note is happy to talk about customers even when the machine is a home desktop that also has a work mailbox signed in.

5. They tell you not to call the police so the sale stays private

Silence is part of the product. If nobody else knows, nobody else can stop the transfer. If nobody else knows, the leak threat feels like your private emergency. The note’s FBI line is there for U.S. readers. The same paragraph works on anyone who has a local cybercrime desk and is already ashamed.

Shame is useful to them. Ransomware still carries a stigma that the victim did something foolish, clicked something, failed a backup. The note leans on that feeling and then offers a private way to “fix it” before anyone finds out. A crime that asks you to hide the crime is still a crime. Official reporting paths exist because this pattern is common, not because your case is uniquely embarrassing.

The U.S. Internet Crime Complaint Center takes ransomware reports. So do local cybercrime units. The CISA Stop Ransomware pages exist for the same reason. Those rooms are allowed to hear you. The onionmail inbox is not a safer room.

6. They sell Bitcoin theater without printing a price

The note spends more words on how to buy Bitcoin than on what you will receive. Cover stories. Brokers who “do not ask questions.” A cold wallet. A claim that paying from that wallet keeps regulators, police, and brokers out of the story. That is a lot of instruction for a file that never names the bill.

The missing $ amount is not a kindness to a broke reader. It is a blank the chat can fill. If you arrive already holding coin, you have already accepted the premise. If you arrive asking “how much,” you have already started negotiating. If a later message names a number, that number was not hiding in the note the whole time. It was invented for you.

Do not “buy a little so you are ready.” Do not ask a friend to pick up coin because you are too shaken to use an exchange. Do not treat a cold-wallet lecture as proof these people are professionals. Plenty of sloppy crews copy the same paragraph. The professionalism is in the wording, not in a guarantee.

7. Session and onionmail are where the price gets invented

Once you are in that chat, the script is predictable even if the wording changes. They will ask you to prove you are the victim. They will ask for a file. They will talk about time. They may claim the price goes up if you wait. They may claim a recovery company will only take a cut and still come back to them. That last line pairs neatly with the note’s warning about police and outsiders. The whole story points at one inbox and one messenger.

None of that is a service agreement. It is a funnel. The correct response is not a clever reply. It is no reply. Do not “negotiate to buy time.” Do not send a low $ counteroffer to see if they are real. Do not ask what coin they want. Do not paste a Session ID you found on a forum because the note left that field empty. Curiosity is how the storefront stays open.

If a friend later says they will “handle the chat for you,” that friend has just volunteered to stand in the aisle the note already built. Keep the friend. Drop the chat. A person who loves you can sit with you while you unplug a machine. They cannot make zawooorecover@onionmail.org honest.

8. A second shop offers the same miracle

After a ransomware incident, search results and inbox ads fill up with companies that say they can decrypt ZAWOOO or “all random-name files.” Some of those shops are ordinary overpriced consultants. Plenty are a second scam. The original crew wants you isolated. The second crew wants you desperate enough to pay a deposit for a key they do not have.

The second scam has a friendly website and a case manager. It asks for a sample file, a remote-access session, or a $ retainer. It may even unlock one junk file, because anyone who is in contact with the original criminals can buy or borrow the same demo. Then the price rises, the chat dies, or the remote tool installs more malware.

A real public decryptor, when one exists, shows up on an official project page that already existed before your incident. The No More Ransom project is the place people check for those tools. It does not need a deposit in cryptocurrency. It does not need a Session ID. It does not need zawooorecover@onionmail.org. If the pitch is “we can decrypt, pay us first,” you are still in the market the ransomware created. There is no public free decryptor known for ZAWOOO. Anyone who says they already have the key is selling the lock again.

9. Payment closes nothing

Paying is not a guarantee. That sentence is not a slogan. It is the recorded experience of victims across ransomware families. The people who send the note can take the money and disappear. They can send a tool that only unlocks a few files. They can come back later and lock the same machine again.

Even when a key arrives, it can fail on some file types, stop halfway, or demand a second payment. The same access that delivered ZAWOOO the first time can still be open. A payment teaches the operators that this victim pays. It does not close the hole that let them in. It does not make the customer-email claim go away. It does not give you a contract you can enforce. It does not turn 5BE7D191BE162F03.NnaOfnYs back into 1.jpg by magic if they decide not to finish the job.

If someone later tells you that 100% of paying victims got everything back, ask for a public source that is not the person selling the key. You will not get one that you should trust. Until a trusted project publishes a decryptor, treat any site that says “we already have the ZAWOOO key” as a second sales pitch.

What To Do If Your Files Have Random Names

Do not pay. Do not write to zawooorecover@onionmail.org. Do not install Session in order to reach the people who wrote the note. Do not invent or hunt a Session ID because the published note left that field blank. Do not send a “test file” to that inbox. Do not ask for a price. The chat is the attacker’s storefront. If you already sent a message before you found this page, stop there. Do not send more files. Do not pay a deposit to “hold the price.”

STEP 1: Use Rkill to terminate suspicious programs.

In this first step, we will download and run Rkill to terminate suspicious programs that may be running on your computer.

RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies that stop us from using certain tools.

  1. Download Rkill.

    You can download RKill to your computer from the below link. When at the download page, click on the Download Now button labeled iExplore.exe. We are downloading a renamed version of Rkill (iExplore.exe) because some malware will not allow processes to run unless they have a certain filename.

    RKILL DOWNLOAD LINK

    (The above link will open a new page from where you can download Rkill)
  2. Run RKill.

    After downloading, double-click the iExplore.exe icon to kill malicious processes. In most cases, downloaded files are saved to the Downloads folder.
    The program may take some time to search for and end various malware programs.

    RKILL Window

    When it is finished, the black window will close automatically and a log file will open. Do not restart your computer. Proceed to the next step in this guide.

STEP 2: Use Malwarebytes to remove Ransomware and Unwanted Programs

In this second step, we will install Malwarebytes to scan and remove any infections, adware, or potentially unwanted programs that may be present on your computer.

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

STEP 3: Use HitmanPro to remove Rootkits and other Malware

In this third step, while the computer is in normal back, we will download and run a scan with HitmanPro to remove Trojans, rootkits, and other malicious programs.

HitmanPro is a second-opinion scanner — it’s designed to catch what your main antivirus might have missed. Instead of relying on a single detection engine, it checks the behavior of files in the locations where malware usually hides. Anything suspicious gets sent to the cloud, where it’s analyzed by two of the best antivirus engines available: Bitdefender and Kaspersky.

Good news: scanning is completely free, with no limits. You only need a license when it’s time to remove what was found — and even then, you can activate a free one-time 30-day trial to clean your PC at no cost. (A full license is $24.95 per year for 1 PC.)

  1. Download HitmanPro

    Click the button below to download HitmanPro. Remember — the scan is free, so you have nothing to lose by checking your PC.

    DOWNLOAD HITMANPRO (FREE SCAN)
    (The link opens in a new page where your download will start)
  2. Install HitmanPro

    When the download finishes, open your Downloads folder and double-click the file: “hitmanpro.exe” on 32-bit Windows, or “hitmanpro_x64.exe” on 64-bit Windows.

    Double-click on the HitmanPro file

    If a User Account Control pop-up asks whether HitmanPro can make changes to your device, click “Yes” to continue.

    Windows asking for permissions to run the HitmanPro setup

  3. Follow the On-Screen Prompts

    On the HitmanPro start screen, click “Next” to begin the system scan. No lengthy setup required — it goes straight to work.

    Click Next to install HitmanPro on your PC

    HitmanPro final installer screen

  4. Wait for the Scan to Finish

    HitmanPro will now check your computer for malicious programs. This usually takes just a few minutes thanks to its cloud-based scanning.
    HitmanPro scans your computer for any infections, adware, or potentially unwanted programs that may be present

  5. Review the Results and Click “Next”

    When the scan is done, HitmanPro will show you everything it found. Click “Next” to remove the detected threats.

    HitmanPro scan summary. Click Next to remove malware

  6. Click “Activate Free License”

    To remove the malicious files, click the “Activate free license” button. This starts your free 30-day trial — no payment details needed — and unlocks the full cleanup.
    Click on the Activate free license button

    When the removal is complete, HitmanPro will show a summary of everything it cleaned. Click Next, then click Reboot if prompted. If there’s no reboot prompt, just click Close — your PC is clean.

STEP 4: Use AdwCleaner to remove Malicious Browser Extensions and Adware

In this next step, we will use AdwCleaner to remove malicious browser policies and unwanted browser extensions from your computer.

AdwCleaner is a free on-demand scanner that specializes in adware, browser hijackers, and unwanted toolbars — the exact threats that mainstream antivirus programs often miss. It also includes tools that repair the damage malware leaves behind, like hijacked browser settings and malicious policies. It’s a quick scan that’s well worth running.

  1. Download AdwCleaner

    Click the button below to download AdwCleaner — it’s free, portable, and requires no installation.

    DOWNLOAD ADWCLEANER (FREE)

    (The link opens in a new page where your download will start)
  2. Run AdwCleaner

    Open your Downloads folder and double-click the file named “adwcleaner_x.x.x.exe“. There’s no installation — the program starts right away.
    Download AdwCleaner on your computer

    If Windows asks whether you want to allow AdwCleaner to run, click “Yes“. When the license agreement appears, click I agree to continue.

    Windows ask if you want to run AdwCleaner

  3. Enable “Reset Chrome policies”

    This setting removes malicious browser policies — a trick malware uses to lock your browser settings so you can’t change them back. Click “Settings” on the left side of the window, then turn on “Reset Chrome policies“.

    Enable Reset Chrome policies to remove malicious browser policies

  4. Start the Scan

    Click “Dashboard” on the left side of the window, then click the “Scan” button.

    Click on Scan to start a AdwCleaner scan

  5. Wait for the Scan to Finish

    AdwCleaner will now check your computer for adware and other malware. This usually takes only a few minutes — it’s one of the fastest scanners around.

    AdwCleaner scanning for adware and other malware

  6. Quarantine the Detected Threats

    When the scan finishes, AdwCleaner will list everything it found. Click the “Quarantine” button to remove all the malicious items at once.

    Click on Quarantine to remove malware

  7. Click “Continue” to Finish the Cleanup

    Save any open work first — AdwCleaner needs to close your open programs before it can clean. When you’re ready, click the “Continue” button.
    Click Continue to remove malicious files

    AdwCleaner will now delete all detected malware from your computer. If it asks you to restart your PC, allow it — your computer will be clean when you log back in.

STEP 5: Perform a final check with ESET Online Scanner

This final step involves installing and running a scan with ESET Online Scanner to check for any additional malicious programs that may be installed on the computer..

ESET Online Scanner is a free second-opinion scanner that performs a deep, full-system check for viruses, trojans, rootkits, and other malware. We use it as the final step because it’s thorough — if anything slipped past the previous scans, ESET will find it. A clean result here means your computer is malware-free.

  1. Download ESET Online Scanner

    Click the button below to download ESET Online Scanner.

    DOWNLOAD ESET ONLINE SCANNER (FREE)

    (The link opens in a new page where your download will start)
  2. Run the Installer

    When the download finishes, open your Downloads folder and double-click “esetonlinescanner.exe“.
    Image - Double-click on the ESET Online Scanner setup file

  3. Install ESET Online Scanner

    On the start screen, select your language from the drop-down menu and click Get started.

    Image - Click Get Started to install ESET Online Scanner

    On the Terms of use screen, click Accept.
    Image - Accept Terms to Install ESET Online Scanner

    Choose your preferences for the Customer Experience Improvement Program and the Detection feedback system (either choice is fine), then click Continue.
    Image - Follow the on-screen prompts

  4. Start a Full Scan

    Click Full Scan — this checks your entire computer, not just the common hiding spots.

    Start a Full Scan with ESET Online Scanner

    Select Enable for Detection of Potentially Unwanted Applications — this lets ESET catch adware and bundled junk programs, not just viruses. Then click Start scan.

    Image - Enable PUA Detection and Start Scan

  5. Wait for the Scan to Finish

    ESET will now check every file on your computer. Because it’s a full scan, this can take a while — often an hour or more, depending on how much data you have. Leave it running in the background and check on it from time to time.

    Image- Wait for the ESET Online Scanner scan to finish

  6. Review the Results

    When the scan completes, the Found and resolved detections screen appears. Any threats found were automatically cleaned and quarantined — there’s nothing extra you need to do. Click View detailed results if you want to see exactly what was removed.
    Image - ESET Online Scanner malware removal

    If ESET found nothing — congratulations, your computer has passed the final check and is malware-free.

STEP 6: Restore the files encrypted by ransomware

Unfortunately, in most cases, it’s not possible to recover the files encrypted by this ransomware virus because the private key which is needed to unlock the encrypted files is only available through the attackers. However, below we’ve listed three options you can use to try and recover your files.

Make sure you remove the malware from your computer first, otherwise, it will repeatedly lock your system or encrypt files. If you suspect that your computer is still infected with malware, you can run a free scan with Emsisoft Emergency Kit.

Option 1: Search a decryption tool for this ransomware

The cybersecurity community is constantly working to create ransomware decryption tools, so you can try to search these sites for updates:

Option 2: Use EaseUS Data Recovery Wizard Free to recover the encrypted files

EaseUS Data Recovery Wizard Free can restore files and repair corrupted files with simple clicks. Its powerful scanning algorithms can identify and retrieve huge file type library, including all of the popular video files, audio files, photos, and document formats.
While the free version only allows you to recover 2 GB of data, this can be helpful to see if the recovery is possible and restore back the most important files from your computer.

  1. Download EaseUS Data Recovery Wizard Free.

    You can download EaseUS Data Recovery Wizard Free by clicking the link below.

    EASEUS DATA RECOVERY WIZARD FREE DOWNLOAD LINK

    (The above link will open a new page from where you can download EaseUS Data Recovery Wizard)
  2. Double-click on the EaseUS Data Recovery Wizard Free setup file.

    When EaseUS Data Recovery Wizard Free has finished downloading, double-click on the setup file to install EaseUS Data Recovery Wizard on your computer. In most cases, downloaded files are saved to the Downloads folder.

    Image: EaseUS Data Recovery Wizard Free Installer

    You may be presented with a User Account Control pop-up asking if you want to allow EaseUS to make changes to your device. If this happens, you should click “Yes” to continue with the EaseUS Data Recovery Wizard Free installation.

  3. Follow the on-screen prompts to install EaseUS Data Recovery Wizard.

    When the EaseUS Data Recovery Wizard installation begins, click on the “Install Now” as seen in the image below.
    EaseUS Data Recovery Wizard Free Install Now

    When your EaseUS Data Recovery Wizard installation completes, click the “Start Now” button to start the program.
    Image: Click Start Now

  4. Select a location to start recovering the encrypted files.

    Choose the drive or folder where you are the encrypted files that you want to recover and click “Scan“.
    Select a location to start recovering the encrypted files

  5. Wait for the EaseUS Data Recovery Wizard scan to complete.

    EaseUS Data Recovery Wizard will now scan your computer files that can be restored. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Image: Wait for the EaseUS Data Recovery Wizard scan to complete.

  6. Find the files you want to recover.

    When the EaseUS Data Recovery Wizard scan is finished scanning it will show a screen that displays the files that can be recovered. This tool can recover a lot of data, use the “Filter” button to quickly filter specific file types and find the files that you want to recover.
    Filter the Files by Type

    Click the “Preview” button or double-click on a file for a full preview.
    Image: Click Preview to view the file

  7. Select your files and click “Recover”.

    Finally, select the the files you want to recover and click “Recover“.
    Select your files and click Recover
    Choose a safe location to save all the files.
    Select a safe location
    The free version only allow you to recover 2 GB of data, however, this will allow you to recover the most important files and see if EaseUS Data Recovery Wizard can correctly recover them.
    Image: View Recovered Files

Option 3: Try to restore your files with ShadowExplorer

This ransomware will attempt to delete all shadow copies when you first start any executable on your computer after becoming infected. Thankfully, the infection is not always able to remove the shadow copies, so you should continue to try restoring your files using this method.

  1. Download ShadowExplorer.

    You can download ShadowExplorer from the below link.

    SHADOW EXPLORER DOWNLOAD LINK
    (This link will open a new web page from where you can download “ShadowExplorer”)
  2. Install ShadowExplorer.

    Double-click on the ShadowExplorer-x.x-setup file to start the installation process, then follow the on-screen promts to install this program.
    Install Shadow Defender

  3. Select snapshot date.

    Open ShadowExplorer and then from the top bar select the drive where the files that you want to save are located, then select from the snapshot available one previous to this infection.

    Select drive and date to recover the files encrypted by this ransomware

  4. Export the files that you want to recover.

    Once you have found a copy of the original file or folder, right-click on it and the select “Export”. A window will prompt you where you want to save the file or folder.
    Find copy then click on Expor to recover the files encrypted by this ransomware

Keep every random name exactly as it is. Do not bulk-rename 5BE7D191BE162F03.NnaOfnYs back to 1.jpg, or A91C04E77B12D8F0.kQpLmRvt back to whatever you think it used to be. Guessing the old title on paper is fine if you need a list of what was hit. Writing those guesses back onto the files is not a repair. It can make a later trusted tool worse, not better.

Keep How To Restore Your Files.txt with the locked files. That note is how you prove this was ZAWOOO and not a different locker that only stole a similar help-file title. The mailbox zawooorecover@onionmail.org is evidence. The blank Session line is evidence. They are not instructions you should carry out.

If a later email from zawooorecover@onionmail.org finally names a $ figure, that is still the same shop. If a later email or a Session account offers a “real” ID because the note left that field empty, that is still the same shop. If someone claims they can already decrypt Win64/Filecoder.AUW files for a fee, they are selling a scanner name, not a key. Do not answer. Do not complete their checkout. Do not help them fix the flyer.

The Bottom Line

ZAWOOO ransomware is a locker that hides the catalog and then talks like a firm. It replaces both the original filename and the original extension with random strings. In one published sample, 1.jpg became 5BE7D191BE162F03.NnaOfnYs. The same folder can also show names such as A91C04E77B12D8F0.kQpLmRvt, 0F33AA91C6E204B7.xYwUeNds, and C7E18B4409A2F156.pHtRqMka. The note is How To Restore Your Files.txt. It calls itself a ransomware that prioritizes reputation. It tells you not to go to the police. It threatens to email stolen files, chat history, and mailbox content to your customers. It wants Bitcoin and a private chat. It does not print a $ amount or a BTC amount.

The contacts in the note are Session, with no Session ID printed in the published sample, and zawooorecover@onionmail.org. ESET has used Win64/Filecoder.AUW. That is a detection name. It is not a public decryptor. There is no public free decryptor known for this strain. Do not take a “we recovered ZAWOOO” pitch at face value.

Do not pay. Do not write to that mailbox. Do not install Session for them. Do not rename the pile in bulk. If you take one sentence with you, take this. A folder of random names plus How To Restore Your Files.txt is ransomware on the first sighting. Treat it that way before anyone in that inbox names a $ figure.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

FLocker Ransomware EXPOSED: .Flock Files and FLOCK_DECRYPT.txt

Next

Toafex.com EXPOSED – Fake or Real Casino? Our Findings