UNC EXPOSED: .UNC Files, info.txt, and a 12-Hour Second Inbox

You open Documents the way you did yesterday. The vacation photo should still be vacation.jpg. The invoice should still be invoice-2026.pdf. The tax sheet should still be taxes.xlsx. Instead every familiar name has extra stamps tacked on. 1.jpg is now 1.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. A small text file called info.txt is sitting in the same folder, as if it has always belonged there. A window is sitting on the desktop that was not there this morning.

That is the trap, not a glitch. A locker has already finished. The names still look like yours. The files do not open. The note and the pop-up talk like a help desk. They are a storefront.

This page is for the moment those names appear. It walks the rename, the note, the pop-up, and the clock printed so you would sit still. It is not a tour of ransomware in general. It is about this strain, the one that writes .UNC on the end and leaves info.txt in the same folder.

Encrypted files after the UNC locker. The .UNC names and info.txt are the tell.
Encrypted files after the UNC locker. The .UNC names and info.txt are the tell. 9ECFA84E is a sample ID from a published example.

Overview

The first tell is the rename. This locker keeps the old name and the old extension, then writes id- plus a short code, then glues a mailbox into square brackets, then appends .UNC. In a published example, 1.jpg became 1.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. On that same pattern, vacation.jpg becomes vacation.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. invoice-2026.pdf becomes invoice-2026.pdf.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. taxes.xlsx becomes taxes.xlsx.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. family.mp4 becomes family.mp4.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. You can still read what the file used to be. You cannot open it.

9ECFA84E is a sample ID from that published example. Treat it as a sample of the format, not as your ID, and not as every victim’s ID. This page will not invent a second one. The code on your disk is the one that belongs to that machine. Windows may now call the type a UNC File and offer a useless “choose an app” box. An app cannot talk the bytes back into a JPEG. Double-clicking vacation.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC does not open the photo. Spreadsheet software does not open taxes.xlsx.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. A video player does not open family.mp4.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC.

The second tell is the note. After the files are locked, the malware drops info.txt into the same folders. The filename is ordinary on purpose. Plenty of real software drops an info file. This one uses that habit against you. It is meant to be the first thing you double-click when the folder already looks wrong. The published note is short. It says all your data has been encrypted. For decryption, it tells you to contact two mailboxes: cyberuncle@cyberfear.com and cyberuncle@tuta.io.

The third tell is the pop-up. A window appears so you cannot miss the flyer even if you never open the text file. The published copy opens with their grammar: “All your files has been encrypted.” It tells you to contact cyberuncle@cyberfear.com and to send YOUR ID. It says that if there is no answer in 12 hours, you should write cyberuncle@tuta.io. It offers a free decryption as a guarantee, up to 3 files under 3Mb, and it says those files must not be valuable. It claims some data was already downloaded. It says that if you refuse, the copy goes to third parties, with fines and reputation damage as the scare. It tells you not to rename the locked files, and not to use a third-party decryptor.

That is the whole costume. A locked folder of .UNC names with a mailbox already sitting in the filename. An info.txt that talks like a help file. A pop-up that adds a 12-hour second inbox, a three-file demo, and a leak threat. There is no printed ransom $ amount. There is no wallet string. There is no hidden site. This page will not invent those. There is no public free decryptor known for this strain. There is no reason to write those addresses. There is no reason to send three files to prove a lock they already finished.

This is a Dharma-style locker. The costume on disk is the .UNC ending, the id- stamp, and the mailbox glued into the filename. This page will not tour the rest of that family. The strain in front of you is the one that leaves info.txt, paints that pop-up, and names those two inboxes.

The .UNC name is the first warning

Most lockers pick an extension so you notice the change in seconds. This one uses .UNC and keeps the rest of the filename readable. You can still see 1.jpg inside 1.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. You can still see the invoice year. You can still see the word taxes. The familiar words are still in the folder. The files are not familiar anymore.

Do not treat that readable name as a fix. Do not strip .UNC off the end and expect Photos or Excel to open the file. Do not delete the id- chunk because it looks like junk. Do not erase the bracketed mailbox and hope the photo comes back. Do not run a bulk “extension fixer” you found in an ad. The name is a label. The lock is in the content. Editing the label can make a later trusted tool have a harder time matching the file to what it was.

The same readable names also make a later scam easier. Anyone who sees a pile of .UNC files can pretend they already “have your case.” They can quote vacation.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC back to you. They can offer a paid unlock. The extension is branding. The leftover original name is branding. The mailbox in brackets is branding. None of that is a hint that the file can be renamed back to normal.

The sample ID is a handle, not a key

The sample ID on this page is 9ECFA84E. It comes from a published example of this rename. Treat that string as a sample of the format, not as your ID. The code on your disk is the one that belongs to that machine. It is sitting in the filename so you will notice it, copy it, and feel already in a case file. The pop-up even asks for YOUR ID. That is the handle they want in the first mail.

An ID like that is useful to the people who wrote the locker. It lets them keep your thread separate from the next victim. It lets a later fake helper say “send me your info.txt” and look prepared. It lets them greet you by number so the first email feels like a ticket, not a threat. Copy the filename for your own records if you need to describe the incident. Do not paste that ID into a stranger’s form. Do not read the ID out on a phone call that started with “we can decrypt .UNC files.”

info.txt is a sales floor, not a help file

The published note is thinner than the pop-up. It says all your data has been encrypted. For decryption, contact cyberuncle@cyberfear.com and cyberuncle@tuta.io. That is the whole pitch in the text file. Short on purpose. A long manifesto can be ignored. A two-line “info” file looks like a leftover from an installer. It is meant to be opened in Notepad before you have decided this is ransomware.

Notice what the note does not give you. It does not give you a $ figure. It does not give you a wallet. It does not give you a support ticket that a real company would honor. It does not give you a refund policy. It gives you two inboxes and a tone that says this is already decided. That tone is the product. Read the file as a sales flyer that was dropped after a break-in. Then close it. Keep it on disk. Do not treat it as a set of steps you should follow.

The pop-up is the same bill, only louder

After the files are locked, a window appears. The published copy starts with their grammar: “All your files has been encrypted.” That broken line is not a translation glitch you should forgive. It is a tell. Real recovery desks do not open with that sentence. The rest of the window is a checkout script. Contact cyberuncle@cyberfear.com. Send YOUR ID. If no answer in 12 hours, write cyberuncle@tuta.io.

This is the hurry-up layer. A text file can be ignored if you are busy trying to open the photo. A window cannot. People waste the first hour on the pop-up. They screenshot it. They search every word on it. They close it and hope the files follow. The files do not follow. Keep a copy if you need evidence. Closing the window is fine for your nerves. It is not a repair. The lock lives in every .UNC file, not in the dialog sitting on top of the icons.

The 12-hour second inbox is a clock they own

The pop-up does not print a $ amount. It prints a timer. Write the first mailbox. If nobody answers in 12 hours, write the second. That is not a service-level agreement. It is a way to keep you sitting at the inbox overnight. Twelve hours is long enough to feel official and short enough to cancel sleep, a second opinion, and a calm reread of a page like this one.

There is no independent clock. There is no ticket you can escalate. If they reply in two hours, that is still the same shop. If they reply after the “window,” that is still the same shop. If they never reply, you have already told them you are the kind of victim who follows the flyer. The second address is not a backup help desk. It is a second checkout counter for people who got nervous when the first one stayed quiet.

Three files under 3Mb is not a guarantee

The pop-up offers a free decryption as a guarantee. Up to 3 files. Under 3Mb. Not valuable. That offer sounds fair. It is one of the oldest lines in this business. Unlocking a junk PDF does not unlock the payroll folder. It does not prove a claimed leak copy will be deleted. It does not prove a later tool will finish the job. “Not valuable” is their rule, not yours. A file that looks worthless to you can still hold a client name, a path, or a header they did not have.

Of course they can open a file they locked. The three-file demo is how the payment conversation starts. You do not owe them a sample. You do not need their proof. If a trusted decryptor ever appears, it will come from a project like No More Ransom, not from a mailbox that just locked your share. Do not send the three files.

“Some data downloaded” is a second lock

After the lock, the pop-up spends its best sentences on the data it says it already copied. If you refuse, that copy goes to third parties. Fines. Reputation. The threat is aimed at anyone who already has backups. A backup can replace a photo. A backup cannot unsay a leak they claim they will post. You cannot audit that claim from the desktop. You are asked to take their word for it inside a mail thread they own.

Treat the threat as real enough to take care of accounts, and fake enough that you should not pay to test it. Change passwords from a clean device. Watch bank and email alerts. Tell the people whose files lived on that PC. Writing cyberuncle@cyberfear.com and attaching three files is not useful work. It is the checkout. The CISA StopRansomware Guide is blunt about this kind of squeeze. Paying does not ensure the files come back, does not ensure the systems are clean, and does not ensure the data stays unpublished.

How The Scam Works

The shop is simple once you stop reading it as a rescue. Lock the files. Brand the names with an ID, a mailbox, and .UNC. Drop a short info.txt. Paint a pop-up that already named a second inbox. Offer three small files so the first mail feels like due diligence. Keep the $ amount off the page so the thread can set it later, in private, after you have already written. Then wave fines and reputation if you hesitate.

1. The lock keeps the old name so you recognize the loss

The locker encrypts the files it wants as leverage, then writes id- plus a code, glues cyberuncle@cyberfear.com into brackets, and appends .UNC. That is why 1.jpg is still readable as 1.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC in the published sample. The operators want you to inventory the damage in seconds. They want you to see the vacation photo, the invoice, the tax sheet, and the family video in one glance. A coded filename can confuse you. A readable filename makes you feel the theft.

If only one folder looks wrong, do not assume the rest of the disk is safe. Ransomware walks trees. It hits Documents, Desktop, Pictures, Downloads, and any drive letter it can reach, including a USB stick you forgot was plugged in. Unplug extra disks. Do not plug in the backup drive “just to check.” Checking is how the backup gets the same .UNC ending.

2. The ID in the filename is a ticket, not a key

The pop-up asks for YOUR ID. The ID is already sitting in every locked name. In the published example that ID is 9ECFA84E. On your disk it will be whatever string this build wrote after id-. That string does not decrypt anything. It is a handle so the first mail can be filed. It is also a prop. A later fake helper can ask for “your UNC ID” and sound close to the case.

Do not invent a second ID if you are writing the incident down. Do not reuse 9ECFA84E as if it belongs to you. Use the code that is already in the filename on your machine. Copy it for your own notes. Do not paste it into a form, a chat, or an email that started with a promise to unlock .UNC files.

3. info.txt turns a break-in into a help file

The note tells you the data is encrypted. Then it names the two doors: cyberuncle@cyberfear.com and cyberuncle@tuta.io. That is all it has to do. The filename info.txt does the rest. It looks boring. It looks local. It looks like something a program left behind. People open boring files when they are already scared. That click is how a break-in becomes a conversation.

Keep every copy of info.txt you still have. Do not “clean up” the notes because they feel ugly. Those files are evidence. They are how you later prove this was this strain and not a different locker that only borrowed the .UNC idea. They are not a checklist. Closing Notepad is the whole job.

4. The pop-up hurries you toward the first inbox

The window repeats the lock in bigger type, then names the first counter: cyberuncle@cyberfear.com. It asks for YOUR ID. That is the storefront. A cyberfear address looks like a brand. It looks like someone who “does this for a living.” Writing that inbox is how a locked folder becomes a negotiation. Negotiation is how a $ demand appears. Payment is how the next victim is funded. None of those steps restore a machine you can trust.

Do not write that inbox “just to see the price.” A price is how the rest of the script starts. Once you are in the thread, the 12-hour line has something to attach to. Silence is not rude here. Silence is how you stay out of their queue. If a later message arrives from a lookalike address, treat it the same way. A swapped letter, a different free host, or a “new recovery desk” is still the same aisle, or a copycat standing in the same doorway.

5. The 12-hour switch is a second checkout

If the first mailbox stays quiet, the pop-up already named the next one: cyberuncle@tuta.io. Tuta looks like a privacy product. Privacy is useful to the crew, not to you. The 12-hour line is there so you will not wait for morning, a relative, or a real technician. It is there so the second address feels like an escalation instead of the same sale.

People pay timers with attention first, then with money. If the note can own the next 12 hours, it does not need a printed $ figure. You will ask for the figure yourself. That is the design. Put the clock down. The files are already locked. Another night of panic will not change the bytes inside invoice-2026.pdf.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC.

If you already wrote the first inbox and heard nothing, do not “try the backup.” Do not send a follow-up “in case it landed in spam.” Do not switch to cyberuncle@tuta.io because the pop-up told you that is what professionals do. Both addresses are the same shop. A quiet inbox is not a failed ticket. It is a crew that already has your files, and does not owe you a reply.

6. Three files under 3Mb is how the chat starts

The free-decrypt line is dressed as a guarantee. Up to 3 files. Under 3Mb. Not valuable. The limits are the point. Small enough to feel safe. Small enough to send from a phone. Small enough that you will pick something “useless” and still hand them a live sample. A restored holiday photo, if they ever send one back, does not mean the accounting spreadsheet will return. It means someone on the other end can open a file they locked, which you already knew.

Do not shop for three junk files “just in case.” Do not zip them. Do not send one now and two later. Do not let a friend send the sample because you are too shaken to attach it. Proof, if it ever comes, should come from a trusted decryptor project, not from cyberuncle@cyberfear.com. The 3Mb cap is not a kindness. It is a filter that keeps the first exchange cheap for them and expensive for you.

7. Fines and reputation are pressure, not a docket

The pop-up claims some data was downloaded. Refuse, and that copy goes to third parties. Fines. Reputation. That sentence is doing sales work. It is not a court file. It is not a regulator notice. It is a way to pull in people who already copied the photos to a drive last year and think they are done. Home users hear “reputation” and picture family chat. A shop hears fines. Both audiences are supposed to write the same inbox.

Believe the risk enough to treat it as a possible breach. Tell counsel and your incident lead if this is a company. Do not believe the promise enough to buy a deletion you cannot verify. Do not browse random “leak blogs” looking for your name. That visit does not unlock vacation.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. If someone later sends you a link and says your files are already out, treat that message as part of the same sale. Report it. Do not start a bidding war over silence.

8. “Do not rename” is a monopoly, not advice

The pop-up warns you not to rename the locked files and not to use a third-party decryptor. Part of that warning is self-serving. The authors want you talking to them, not to a relative, an insurer, or a real technician. They want a monopoly on the next click. Part of it is still a useful caution in the wrong mouth. Mystery “one-click decrypt” apps from ads can damage files. Bulk rename tools can scramble names that a later trusted project might have used.

The safe reading is narrower than the pop-up wants. Do not take technical advice from the attacker. Do not run a paid unlocker from a search ad. Do not delete the .UNC copies “to start clean.” Keep the locked files. Keep info.txt. Keep a screenshot of the pop-up if you still have it. Those are evidence and, if a trusted decryptor ever appears, they are the raw material that tool would need. Destroying them because the window scared you is still doing the window’s work.

9. Payment closes nothing

Paying is not a guarantee. The people who send the note can take the money and disappear. They can send a tool that only unlocks a few files. They can come back later and lock the same machine again. A cyberfear thread and a tuta follow-up make that outcome easier, not harder. You cannot leave a review on a criminal inbox.

Even when a key arrives in some other campaign, it can fail on some file types, stop halfway, or demand a second payment. The same access that delivered this locker the first time can still be open. A payment teaches the operators that this victim pays. It does not close the hole that let them in. It does not give you a contract you can enforce. People who pay sometimes get a second bill for “deletion.” The 12-hour switch does not change that math. A second mailbox is not a warranty.

After a ransomware incident, search results fill up with companies that say they can decrypt UNC or “all .UNC files.” Some of those shops are ordinary overpriced consultants. Plenty are a second scam. They will quote 9ECFA84E so they sound close to the case, even when that sample ID is not yours. They will mention the 12-hour tuta line as if they already called the original crew. They will ask for a sample file, a remote-access session, or a deposit. They may even open one junk file, because anyone who is in contact with the original criminals can borrow the same three-file demo. Then the price rises, the chat dies, or the remote tool installs more malware.

What To Do If Your Files End in .UNC

Do not write cyberuncle@cyberfear.com. Do not write cyberuncle@tuta.io. Do not treat the 12-hour line as a sale you have to catch. Do not send YOUR ID. Do not send three files under 3Mb, valuable or not. Do not pay a $ figure they name after you arrive. Do not invent a payment the note never printed. The leak line is pressure, not a reason to start that mail. If you already sent a message before you found this page, stop there. Do not send more files. Do not “try the second inbox” to hold the window. Do not pay a deposit to “hold the price.”

STEP 1: Use Rkill to terminate suspicious programs.

In this first step, we will download and run Rkill to terminate suspicious programs that may be running on your computer.

RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies that stop us from using certain tools.

  1. Download Rkill.

    You can download RKill to your computer from the below link. When at the download page, click on the Download Now button labeled iExplore.exe. We are downloading a renamed version of Rkill (iExplore.exe) because some malware will not allow processes to run unless they have a certain filename.

    RKILL DOWNLOAD LINK

    (The above link will open a new page from where you can download Rkill)
  2. Run RKill.

    After downloading, double-click the iExplore.exe icon to kill malicious processes. In most cases, downloaded files are saved to the Downloads folder.
    The program may take some time to search for and end various malware programs.

    RKILL Window

    When it is finished, the black window will close automatically and a log file will open. Do not restart your computer. Proceed to the next step in this guide.

STEP 2: Use Malwarebytes to remove Ransomware and Unwanted Programs

In this second step, we will install Malwarebytes to scan and remove any infections, adware, or potentially unwanted programs that may be present on your computer.

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

STEP 3: Use HitmanPro to remove Rootkits and other Malware

In this third step, while the computer is in normal back, we will download and run a scan with HitmanPro to remove Trojans, rootkits, and other malicious programs.

HitmanPro is a second-opinion scanner — it’s designed to catch what your main antivirus might have missed. Instead of relying on a single detection engine, it checks the behavior of files in the locations where malware usually hides. Anything suspicious gets sent to the cloud, where it’s analyzed by two of the best antivirus engines available: Bitdefender and Kaspersky.

Good news: scanning is completely free, with no limits. You only need a license when it’s time to remove what was found — and even then, you can activate a free one-time 30-day trial to clean your PC at no cost. (A full license is $24.95 per year for 1 PC.)

  1. Download HitmanPro

    Click the button below to download HitmanPro. Remember — the scan is free, so you have nothing to lose by checking your PC.

    DOWNLOAD HITMANPRO (FREE SCAN)
    (The link opens in a new page where your download will start)
  2. Install HitmanPro

    When the download finishes, open your Downloads folder and double-click the file: “hitmanpro.exe” on 32-bit Windows, or “hitmanpro_x64.exe” on 64-bit Windows.

    Double-click on the HitmanPro file

    If a User Account Control pop-up asks whether HitmanPro can make changes to your device, click “Yes” to continue.

    Windows asking for permissions to run the HitmanPro setup

  3. Follow the On-Screen Prompts

    On the HitmanPro start screen, click “Next” to begin the system scan. No lengthy setup required — it goes straight to work.

    Click Next to install HitmanPro on your PC

    HitmanPro final installer screen

  4. Wait for the Scan to Finish

    HitmanPro will now check your computer for malicious programs. This usually takes just a few minutes thanks to its cloud-based scanning.
    HitmanPro scans your computer for any infections, adware, or potentially unwanted programs that may be present

  5. Review the Results and Click “Next”

    When the scan is done, HitmanPro will show you everything it found. Click “Next” to remove the detected threats.

    HitmanPro scan summary. Click Next to remove malware

  6. Click “Activate Free License”

    To remove the malicious files, click the “Activate free license” button. This starts your free 30-day trial — no payment details needed — and unlocks the full cleanup.
    Click on the Activate free license button

    When the removal is complete, HitmanPro will show a summary of everything it cleaned. Click Next, then click Reboot if prompted. If there’s no reboot prompt, just click Close — your PC is clean.

STEP 4: Use AdwCleaner to remove Malicious Browser Extensions and Adware

In this next step, we will use AdwCleaner to remove malicious browser policies and unwanted browser extensions from your computer.

AdwCleaner is a free on-demand scanner that specializes in adware, browser hijackers, and unwanted toolbars — the exact threats that mainstream antivirus programs often miss. It also includes tools that repair the damage malware leaves behind, like hijacked browser settings and malicious policies. It’s a quick scan that’s well worth running.

  1. Download AdwCleaner

    Click the button below to download AdwCleaner — it’s free, portable, and requires no installation.

    DOWNLOAD ADWCLEANER (FREE)

    (The link opens in a new page where your download will start)
  2. Run AdwCleaner

    Open your Downloads folder and double-click the file named “adwcleaner_x.x.x.exe“. There’s no installation — the program starts right away.
    Download AdwCleaner on your computer

    If Windows asks whether you want to allow AdwCleaner to run, click “Yes“. When the license agreement appears, click I agree to continue.

    Windows ask if you want to run AdwCleaner

  3. Enable “Reset Chrome policies”

    This setting removes malicious browser policies — a trick malware uses to lock your browser settings so you can’t change them back. Click “Settings” on the left side of the window, then turn on “Reset Chrome policies“.

    Enable Reset Chrome policies to remove malicious browser policies

  4. Start the Scan

    Click “Dashboard” on the left side of the window, then click the “Scan” button.

    Click on Scan to start a AdwCleaner scan

  5. Wait for the Scan to Finish

    AdwCleaner will now check your computer for adware and other malware. This usually takes only a few minutes — it’s one of the fastest scanners around.

    AdwCleaner scanning for adware and other malware

  6. Quarantine the Detected Threats

    When the scan finishes, AdwCleaner will list everything it found. Click the “Quarantine” button to remove all the malicious items at once.

    Click on Quarantine to remove malware

  7. Click “Continue” to Finish the Cleanup

    Save any open work first — AdwCleaner needs to close your open programs before it can clean. When you’re ready, click the “Continue” button.
    Click Continue to remove malicious files

    AdwCleaner will now delete all detected malware from your computer. If it asks you to restart your PC, allow it — your computer will be clean when you log back in.

STEP 5: Perform a final check with ESET Online Scanner

This final step involves installing and running a scan with ESET Online Scanner to check for any additional malicious programs that may be installed on the computer..

ESET Online Scanner is a free second-opinion scanner that performs a deep, full-system check for viruses, trojans, rootkits, and other malware. We use it as the final step because it’s thorough — if anything slipped past the previous scans, ESET will find it. A clean result here means your computer is malware-free.

  1. Download ESET Online Scanner

    Click the button below to download ESET Online Scanner.

    DOWNLOAD ESET ONLINE SCANNER (FREE)

    (The link opens in a new page where your download will start)
  2. Run the Installer

    When the download finishes, open your Downloads folder and double-click “esetonlinescanner.exe“.
    Image - Double-click on the ESET Online Scanner setup file

  3. Install ESET Online Scanner

    On the start screen, select your language from the drop-down menu and click Get started.

    Image - Click Get Started to install ESET Online Scanner

    On the Terms of use screen, click Accept.
    Image - Accept Terms to Install ESET Online Scanner

    Choose your preferences for the Customer Experience Improvement Program and the Detection feedback system (either choice is fine), then click Continue.
    Image - Follow the on-screen prompts

  4. Start a Full Scan

    Click Full Scan — this checks your entire computer, not just the common hiding spots.

    Start a Full Scan with ESET Online Scanner

    Select Enable for Detection of Potentially Unwanted Applications — this lets ESET catch adware and bundled junk programs, not just viruses. Then click Start scan.

    Image - Enable PUA Detection and Start Scan

  5. Wait for the Scan to Finish

    ESET will now check every file on your computer. Because it’s a full scan, this can take a while — often an hour or more, depending on how much data you have. Leave it running in the background and check on it from time to time.

    Image- Wait for the ESET Online Scanner scan to finish

  6. Review the Results

    When the scan completes, the Found and resolved detections screen appears. Any threats found were automatically cleaned and quarantined — there’s nothing extra you need to do. Click View detailed results if you want to see exactly what was removed.
    Image - ESET Online Scanner malware removal

    If ESET found nothing — congratulations, your computer has passed the final check and is malware-free.

STEP 6: Restore the files encrypted by ransomware

Unfortunately, in most cases, it’s not possible to recover the files encrypted by this ransomware virus because the private key which is needed to unlock the encrypted files is only available through the attackers. However, below we’ve listed three options you can use to try and recover your files.

Make sure you remove the malware from your computer first, otherwise, it will repeatedly lock your system or encrypt files. If you suspect that your computer is still infected with malware, you can run a free scan with Emsisoft Emergency Kit.

Option 1: Search a decryption tool for this ransomware

The cybersecurity community is constantly working to create ransomware decryption tools, so you can try to search these sites for updates:

Option 2: Use EaseUS Data Recovery Wizard Free to recover the encrypted files

EaseUS Data Recovery Wizard Free can restore files and repair corrupted files with simple clicks. Its powerful scanning algorithms can identify and retrieve huge file type library, including all of the popular video files, audio files, photos, and document formats.
While the free version only allows you to recover 2 GB of data, this can be helpful to see if the recovery is possible and restore back the most important files from your computer.

  1. Download EaseUS Data Recovery Wizard Free.

    You can download EaseUS Data Recovery Wizard Free by clicking the link below.

    EASEUS DATA RECOVERY WIZARD FREE DOWNLOAD LINK

    (The above link will open a new page from where you can download EaseUS Data Recovery Wizard)
  2. Double-click on the EaseUS Data Recovery Wizard Free setup file.

    When EaseUS Data Recovery Wizard Free has finished downloading, double-click on the setup file to install EaseUS Data Recovery Wizard on your computer. In most cases, downloaded files are saved to the Downloads folder.

    Image: EaseUS Data Recovery Wizard Free Installer

    You may be presented with a User Account Control pop-up asking if you want to allow EaseUS to make changes to your device. If this happens, you should click “Yes” to continue with the EaseUS Data Recovery Wizard Free installation.

  3. Follow the on-screen prompts to install EaseUS Data Recovery Wizard.

    When the EaseUS Data Recovery Wizard installation begins, click on the “Install Now” as seen in the image below.
    EaseUS Data Recovery Wizard Free Install Now

    When your EaseUS Data Recovery Wizard installation completes, click the “Start Now” button to start the program.
    Image: Click Start Now

  4. Select a location to start recovering the encrypted files.

    Choose the drive or folder where you are the encrypted files that you want to recover and click “Scan“.
    Select a location to start recovering the encrypted files

  5. Wait for the EaseUS Data Recovery Wizard scan to complete.

    EaseUS Data Recovery Wizard will now scan your computer files that can be restored. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Image: Wait for the EaseUS Data Recovery Wizard scan to complete.

  6. Find the files you want to recover.

    When the EaseUS Data Recovery Wizard scan is finished scanning it will show a screen that displays the files that can be recovered. This tool can recover a lot of data, use the “Filter” button to quickly filter specific file types and find the files that you want to recover.
    Filter the Files by Type

    Click the “Preview” button or double-click on a file for a full preview.
    Image: Click Preview to view the file

  7. Select your files and click “Recover”.

    Finally, select the the files you want to recover and click “Recover“.
    Select your files and click Recover
    Choose a safe location to save all the files.
    Select a safe location
    The free version only allow you to recover 2 GB of data, however, this will allow you to recover the most important files and see if EaseUS Data Recovery Wizard can correctly recover them.
    Image: View Recovered Files

Option 3: Try to restore your files with ShadowExplorer

This ransomware will attempt to delete all shadow copies when you first start any executable on your computer after becoming infected. Thankfully, the infection is not always able to remove the shadow copies, so you should continue to try restoring your files using this method.

  1. Download ShadowExplorer.

    You can download ShadowExplorer from the below link.

    SHADOW EXPLORER DOWNLOAD LINK
    (This link will open a new web page from where you can download “ShadowExplorer”)
  2. Install ShadowExplorer.

    Double-click on the ShadowExplorer-x.x-setup file to start the installation process, then follow the on-screen promts to install this program.
    Install Shadow Defender

  3. Select snapshot date.

    Open ShadowExplorer and then from the top bar select the drive where the files that you want to save are located, then select from the snapshot available one previous to this infection.

    Select drive and date to recover the files encrypted by this ransomware

  4. Export the files that you want to recover.

    Once you have found a copy of the original file or folder, right-click on it and the select “Export”. A window will prompt you where you want to save the file or folder.
    Find copy then click on Expor to recover the files encrypted by this ransomware

Keep every .UNC name exactly as it is. Do not bulk-rename 1.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC back to 1.jpg, or vacation.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC back to vacation.jpg, or invoice-2026.pdf.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC back to a normal PDF. Do not delete the id- chunk. Do not erase the bracketed mailbox because it looks ugly. Stripping the extra ending is not a repair. It can make a later trusted tool worse, not better. The original name is already sitting in front of .UNC.

Keep info.txt with the locked files. Do not “clean up” every copy of the note. Do not invent a new ID if you are writing the incident down. Use the ID that is already in the filename on your disk. 9ECFA84E is only the sample from a published example, used on this page and in the screenshot. Keep a copy of the pop-up if you still have it. Those artifacts are how you prove this was this strain and not a different locker that only sounds similar. They are evidence. They are not instructions you should carry out.

The 12-hour switch is not a reason to rush a payment. It is not a reason to skip a report. It is not a reason to stay on the infected machine so you can “make the window.” Both inboxes are the same shop. cyberuncle@cyberfear.com is the first counter. cyberuncle@tuta.io is the second counter. Neither one is a recovery team. The clock is theirs. The files are already locked. Another 12 hours of panic will not change the bytes.

If a later message quotes your ID and offers “the real tuta desk,” that is still the same shop. If a later message skips mail and asks for a $ figure over a messenger, that is still the same shop, or a copycat standing in the same doorway. If someone claims they already saw your data with third parties and can take the listing down for a fee, that is still the same market. Do not answer. Do not help them set a price the original note left blank on purpose.

Do not run a third-party decryptor you found in an ad, a YouTube description, or a Telegram “recovery” channel. The pop-up already warned you those tools can wreck the files. On that one point the criminals and the honest advice agree, for opposite reasons. They want you exclusive. You want the bytes untouched. Leave the locked copies alone until a trusted project publishes a tool for this family. None is public now.

A three-file demo in that inbox is not a reason to skip the CISA ransomware reporting page or a report at the FBI IC3 desk. If Windows still offers to pick an app for the .UNC type, decline it. There is no player for that ending.

The Bottom Line

This is a Dharma-style locker with a readable filename, a short note, and a pop-up that already named a second inbox. It keeps the old name, writes id- plus a code, glues a mailbox into brackets, and appends .UNC. In the published sample, 1.jpg becomes 1.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. vacation.jpg becomes vacation.jpg.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. invoice-2026.pdf becomes invoice-2026.pdf.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. taxes.xlsx becomes taxes.xlsx.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. family.mp4 becomes family.mp4.id-9ECFA84E.[cyberuncle@cyberfear.com].UNC. 9ECFA84E is a sample ID from that published example. The ID on your disk is the one that matters. The note is info.txt.

The note says all your data has been encrypted, and to contact cyberuncle@cyberfear.com and cyberuncle@tuta.io for decryption. The pop-up adds their grammar, “All your files has been encrypted,” then the 12-hour switch to the second inbox, a free decrypt of up to 3 files under 3Mb that must not be valuable, a claim that some data was downloaded, a refuse-and-third-parties scare about fines and reputation, and a warning not to rename files or use a third-party decryptor. The note does not print a ransom $ amount. This page will not invent a wallet or a hidden site. There is no public free decryptor known for this strain.

Do not pay. Do not write those inboxes. Do not send the three files. Do not wait 12 hours as if a real desk is on the clock. Do not rename the pile in bulk. If you take one sentence with you, take this. A folder of names ending in .UNC, plus info.txt and a pop-up that already named a second mailbox, is ransomware on the first sighting. Treat it that way before anyone in that inbox names a $ figure.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Cloud Services Alert EXPOSED: Recover Messages Steals the Inbox

Next

LQTOREQ EXPOSED: .lqtoreq Files, README_LQTOREG.txt, and an Empty Decrypt Box