PicMo Ransomware EXPOSED: Random Names and How To Restore Your Files.txt
Written by: Lapain Epuran
Published on:
You open Documents the way you always do. The photo should still say 1.jpg. The invoice should still have a name a person can read. Instead the listing looks like a hardware ID dump. One file is 56922DCB6BBA1DBB.jHznjwAp. The next is 3A366BA02AEE184C.jHznjwAp. Then 0C81E4F917AA2201.jHznjwAp. Then a 75,000 KB object called B7D12A90EE44C813.jHznjwAp that used to be something you actually needed. Sitting with them is a small text file named How To Restore Your Files.txt, as if a help document had always lived in that folder.
That shared tail is the trap, not a new file type you can install. PicMo ransomware locks the files first. Then it throws away the original filename. Then it stamps every locked object in that attack with the same random extension. In the sample that matches this page, that stamp is .jHznjwAp. The next victim can get a completely different shared tail. Windows may call the whole pile a JHZNJWAP File and offer a “choose an app” box. An app cannot talk those bytes back into a JPEG. The note wants Bitcoin. It wants a private chat. It wants you to treat a break-in as paid training. It does not print a $ figure. The missing number is not mercy. It is a blank invoice.
This page is for the moment those random names appear with one shared ending. It explains the rename, the note, the corporate-training costume, the Tor leak threat, and why keepvmn@onionmail.org is a storefront, not a help desk. It is not a tour of ransomware in general. It is about this strain, the one that turns 1.jpg into 56922DCB6BBA1DBB.jHznjwAp and leaves How To Restore Your Files.txt behind.
Encrypted files after PicMo. Random names plus How To Restore Your Files.txt are the tell.
Overview
The first tell is the rename plus the shared stamp. PicMo does not leave vacation.jpg sitting there with a locker brand tacked on. It does not keep invoice-2026.pdf in front of a family name you can search. It wipes the name you knew. Then it appends one random extension to every locked file from that same attack. In one analyzed sample, a file named 1.jpg became 56922DCB6BBA1DBB.jHznjwAp. The 16-character hex-like chunk in front is not your old title written in code. The .jHznjwAp tail is not a hint you can reverse by guessing. It is a batch mark. The listing is now a label the locker invented.
That is why the folder still has one object per file, and why the shock lands in two waves. First you see that the words are gone. Then you notice every locked object ends the same way. Double-clicking does not open the photo. Renaming 56922DCB6BBA1DBB.jHznjwAp back to 1.jpg does not either. The lock is in the content. The shared extension is only a flag that those objects were processed together.
The second tell is the note. After the files are locked, the malware drops How To Restore Your Files.txt into the same folders. Public notes in this campaign open with a line that sounds almost like branding. You have been attacked by PicMo, “a ransomware that prioritizes reputation.” Then the note tells you that you must pay. It includes a unique victim identifier so the chat can pretend it already knows your case. It claims data was stolen. It says a Tor site is waiting to publish that data if you do not comply. It does not print the .onion address in a form you should go hunt. Treat a missing leak URL as missing, not as a scavenger hunt.
Then the note puts on a consultant voice. It blames a misconfiguration in your corporate network. It tells you to treat the ransom as a paid training session for your system administrators. It says you can think of the paid decryption as a security test. It promises a full briefing on the intrusion, plus advice, and it hints that the bill may be cheaper than hiring a real company. That is not a tabletop exercise. That is a thief offering to sell you the only spare key and a lecture on the door.
The same file tells you not to go to the police or the FBI. It claims those people will only block recovery. It coaches you on Bitcoin and a cold wallet. It warns you not to delete or modify the locked files. Then it offers two contact paths: the Session messenger, and the mailbox keepvmn@onionmail.org. A published note leaves the Session ID as a placeholder. Treat that placeholder as empty. Do not invent an ID. Do not paste one you found on a forum.
That is the whole storefront. A folder of hex-like names that all share one random ending. A note that sells reputation and paid training. A leak threat aimed at a hidden site. A warning to stay quiet. A Bitcoin lecture with no printed $ amount. A private chat. There is no public free decryptor known for PicMo. There is no reason to write to that inbox. There is no reason to pay.
The shared random extension is the first warning
Most lockers pick one brand so you notice the change in seconds. You still see Taxes.xlsx in front of .locked or .encrypted. PicMo refuses that courtesy on the name, then reuses one invented tail across the pile. The photo that used to be 1.jpg is now 56922DCB6BBA1DBB.jHznjwAp. In the same Documents folder you may also see 3A366BA02AEE184C.jHznjwAp, 0C81E4F917AA2201.jHznjwAp, and B7D12A90EE44C813.jHznjwAp. Those hex-like strings are not a puzzle. The matching ending is not a file format. Together they are a billboard that says the original catalog is gone from the filename.
The pattern is easy to miss if you are hunting for a brand you already know. There is no .picmo on the end. There is no family name you can paste into a search box and get a clean match. A person who only glances at the folder can think a sync tool went wrong, or that a disk check renamed things, or that someone ran a “privacy” utility. The note is what makes the pile make sense. Random names plus one shared tail plus How To Restore Your Files.txt are the tell.
Do not freeze on .jHznjwAp as if it were the only PicMo ending in the world. That string is unique to an attack, not to the brand. A different incident can stamp every locked file with a different shared extension. If the names are hex-like, the tails match each other, and the note is How To Restore Your Files.txt talking about PicMo, you are still in the same shop. The stamp changed. The storefront did not.
Do not treat the new strings as a hint you can reverse. Do not paste the old name back onto the file and expect Photos or Excel to open it. Do not run a bulk “filename fixer” you found in an ad. The name is a label. The lock is in the content. Editing the label can make a later trusted tool have a harder time matching the file to what it was. Leave the locked copies as they are until you have a clean machine and a plan that does not start in a criminal inbox.
How To Restore Your Files.txt is a sales floor
The ransom note is a simple text file. The filename is ordinary on purpose. Plenty of real software drops a how-to. This one uses that habit against you. It is meant to be the first thing you double-click when you are already scared and the folder no longer has words you recognize.
The note walks through what they say they did, what they say they took, and what they want you to do next. It is written like a briefing. Short blocks. Arrow marks. A victim ID that makes the file feel personal. A voice that sounds calm and inevitable. Calm is a tactic. Inevitable is a sales claim. The file is not a recovery guide. It is a script that tries to move you from panic to a private chat without a witness.
Part of the note warns you not to delete or modify encrypted files. Part of that warning is self-serving. The authors want you talking to them, not to a real incident responder. Part of it is still a useful caution in the wrong mouth. Mystery decrypt tools from ads can damage files. The useful part of that warning is smaller than the note wants. Do not take technical advice from the attacker. Do not run a paid “decrypt now” app from a search ad. Do not shred the locked copies because the names look like junk.
“Paid training” is the costume
PicMo’s note wants to sound like a firm that still has something to lose. “A ransomware that prioritizes reputation” is the line they chose. Then they pivot into corporate language. They say a misconfiguration of your corporate network is what let them in. They invite you to treat the whole mess as a paid training session for your system administrators. They say the paid decryption is a security test. They promise to walk you through the intrusion and hand over advice. They hint that this amount may be cheaper than hiring a real company.
Read that the way you would read a stranger who walked through an unlocked side door, copied the filing cabinets, changed every label on the shelves, and then offered a lunch-and-learn. The competence they are selling is the competence they created. Reputation talk is there to lower your shoulders. Training talk is there to make a crime feel like a line item. A security test you did not schedule is still a break-in.
Home users get this pitch too. The note still talks like you run a network with administrators, even if the machine on the desk is a family PC. That is not a clue that they already studied your org chart. It is a template. The same paragraphs get dropped on a clinic, a shop, and a laptop that only holds school photos. The costume stays corporate because corporate language makes payment feel professional.
The Tor leak threat is the second lock
PicMo does not stop at locked files. The note claims data was stolen first. It says a Tor site will publish that information if you do not pay. That is double extortion. Even a person with clean backups is supposed to sit still and think about contracts, photos, mail, or payroll landing on a hidden page.
Do not go looking for that site. Do not paste a guessed .onion into a Tor browser because a forum said PicMo “always uses” a certain address. This page will not invent one. A published note can threaten a leak without handing you a working URL. Hunting for it is how people end up on fake leak pages, second scams, and malware that rides curiosity.
A leak claim can be real, exaggerated, or copied from last week’s template. You cannot settle that question from the text file alone. What you can do is treat stolen-data talk as a reason to involve people who handle incidents, not as a reason to open Session. Paying does not give you a takedown button. Silence does not either. The second lock is meant to keep you in the chat. Leave the chat closed.
The police warning is isolation, not care
The note tells you not to go to the police or the FBI. It says they will only stop you from paying. It says they will not help. It wants the next conversation to happen in a messenger with no witness and an inbox on onionmail.org.
That warning is not written for your safety. It is written so the sale stays private. Criminals who lock files do not get to pick your reporting path. A company that asks you to hide the crime is still running a crime. Official reporting paths exist because this pattern is common, not because your case is uniquely embarrassing.
The U.S. Internet Crime Complaint Center takes ransomware reports. So do local cybercrime units. The CISA Stop Ransomware pages exist for the same reason. Those rooms are allowed to hear you. The onionmail inbox is not a safer room.
keepvmn@onionmail.org and Session are the checkout aisle
Once the note has blamed your network and warned you off the police, it points at two doors. Install Session, it says, and write to a Session ID. Or send email to keepvmn@onionmail.org. That mailbox is the brand on this flyer. It is not a support queue. It is not a place where a kind technician will “verify” you and then unlock 56922DCB6BBA1DBB.jHznjwAp out of goodwill.
The Session line in published notes is a blank. Do not fill it in. Do not search “PicMo Session ID” and paste the first string a stranger posted. Do not ask a recovery shop to “look up the official ID.” A blank field is how this template travels. Filling it is how you walk into the aisle they already built.
There is no public free decryptor known for this strain. Anyone who says they already have the PicMo key, or that a generic locker tool will unwind .jHznjwAp files, is selling the lock again. Scanner names you may see later are labels. They are not keys. This page will not pretend a public family decryptor is known to work on this sample.
How The Scam Works
1. Everyday files lose the name and share one random tail
The first visible move is the catalog disappearing. Photos, invoices, spreadsheets, scans, and the giant archive you forgot was in Documents all become hex-like names. In the sample tied to this page, 1.jpg became 56922DCB6BBA1DBB.jHznjwAp. Other objects in the same folder picked up 3A366BA02AEE184C.jHznjwAp, 0C81E4F917AA2201.jHznjwAp, and B7D12A90EE44C813.jHznjwAp. The first half changes per file. The second half stays the same for that attack.
That shared tail is why Windows starts calling everything a JHZNJWAP File. It looks consistent, so a tired person can think, “I just need the right program.” There is no right program. The extension is a random stamp generated for that incident. Tomorrow’s victim can see a different shared ending on every locked file and still be looking at PicMo. Do not wait for .jHznjwAp before you treat the folder as ransomware.
Public reporting on this campaign also describes the quieter work that happens around the rename. Windows shadow copies get wiped so the built-in restore story fails. Backup-related services get touched so the obvious undo is already broken when you go looking for it. If System Restore shrugs, that is not proof the files were “only renamed.” It is a common locker habit sitting on top of a real encrypt.
2. How To Restore Your Files.txt takes over the conversation
While you are still staring at the hex names, the note is already the only readable object in the folder. The title sounds like a vendor leftover. The first lines sound like a brand. The victim ID sounds like a ticket number. The whole file is built to become the only voice in the room.
That is why the filename is plain English and the locked files are not. If every object still said Taxes.xlsx.picmo, you might search the brand and land on a calm page before you opened the note. If the names are 56922DCB6BBA1DBB.jHznjwAp, the search box is empty and the text file looks like help. Opening it is understandable. Obeying it is the scam.
Keep the note. Photograph it. Copy the mailbox onto paper if you need a record. Then stop taking instructions from it. A file that tells you how to buy coin, how to stay quiet, and how to open Session is not documentation. It is a checkout script that arrived early.
3. They rebrand a break-in as paid training
The reputation line comes first so you think you are dealing with people who still want future customers. The training line comes next so the ransom feels like tuition. “Misconfiguration of your corporate network” is the blame they hand you. “Paid training session for your system administrators” is the product name they invented for the same crime. “Security test” is the discount language.
None of that is an assessment you asked for. A real test has a contract, a scope, and a company you can call on a normal phone number. This one has a text file, a threat, and keepvmn@onionmail.org. If a later chat offers a “report” after you pay, that report is still coming from the people who locked B7D12A90EE44C813.jHznjwAp. Advice from the person holding the key is not a lesson. It is a receipt they want you to want.
Do not let the corporate tone decide whether this “looks targeted.” Templates talk like every victim is a company. A home machine can still get the administrator speech. A small office can still get it. The speech is there because it makes payment feel like a professional decision instead of a panic decision.
4. They threaten a Tor leak site you should not go looking for
The note’s second lock is publication. Stolen data, they say, will go to a Tor site if you do not pay. That sentence is meant to work even if your backups are perfect. Files can be restored. A leak claim cannot be unread by wishing.
This page will not print a .onion. Do not invent one. Do not follow a screenshot from a random thread. Fake leak blogs are a business now. Some are run by the same crews. Some are run by a second crew that only wants a deposit. Some deliver more malware. Curiosity is not containment.
If you run a business, treat the leak claim as an incident, not as a reason to negotiate. Tell the people who handle legal and insurance. Tell the people who handle customer notice rules in your country. Do that without opening Session “just to see the price.” The threat is designed to make the chat feel cheaper than a lawyer. It is not.
5. They tell you not to call the police so the sale stays private
Isolation is the next product. Do not call the police. Do not call the FBI. Do not tell anyone you were attacked. Those lines sit next to the training pitch on purpose. First they make the crime sound like a private professional matter. Then they make witnesses sound expensive.
You can ignore that. Reporting is allowed. Reporting is how patterns get tied together. The people who wrote How To Restore Your Files.txt do not get a veto. If you are in the United States, start with the IC3 complaint form and your local cybercrime unit. If you are elsewhere, use the cybercrime path your country already publishes. CISA’s Stop Ransomware guidance is written for this exact morning, including the part where the note told you not to read it.
Telling one trusted person is also allowed. A colleague, a family member, an insurer, a lawyer. The note wants you alone with Bitcoin instructions. Alone is how blank invoices get filled.
6. They sell Bitcoin theater without printing a price
The note spends more words on how to buy Bitcoin than on what you will receive. Cover stories. Brokers who “do not ask questions.” A cold wallet. A claim that paying from that wallet keeps regulators, police, and brokers out of the story. That is a lot of instruction for a file that never names the bill.
The missing $ amount is not a kindness to a broke reader. It is a blank the chat can fill. If you arrive already holding coin, you have already accepted the premise. If you arrive asking “how much,” you have already started negotiating. If a later message names a number, that number was not hiding in the note the whole time. It was invented for you.
Do not “buy a little so you are ready.” Do not ask a friend to pick up coin because you are too shaken to use an exchange. Do not treat a cold-wallet lecture as proof these people are professionals. Plenty of sloppy crews copy the same paragraph. The professionalism is in the wording, not in a guarantee. 0% of that lecture is a contract.
7. Session and onionmail are where the price gets invented
Once you are in that chat, the script is predictable even if the wording changes. They will ask you to prove you are the victim. They will ask for the victim ID from the note. They will ask for a file. They will talk about time. They may claim the price goes up if you wait. They may claim a recovery company will only take a cut and still come back to them. That last line pairs neatly with the note’s warning about police and outsiders. The whole story points at one inbox and one messenger.
None of that is a service agreement. It is a funnel. The correct response is not a clever reply. It is no reply. Do not “negotiate to buy time.” Do not send a low $ counteroffer to see if they are real. Do not ask what coin they want. Do not paste a Session ID you found on a forum because the note left that field empty. Curiosity is how the storefront stays open.
If a friend later says they will “handle the chat for you,” that friend has just volunteered to stand in the aisle the note already built. Keep the friend. Drop the chat. A person who loves you can sit with you while you unplug a machine. They cannot make keepvmn@onionmail.org honest.
8. A second shop offers the same miracle
After a ransomware incident, search results and inbox ads fill up with companies that say they can decrypt PicMo or “all random-name files.” Some of those shops are ordinary overpriced consultants. Plenty are a second scam. The original crew wants you isolated. The second crew wants you desperate enough to pay a deposit for a key they do not have.
The second scam has a friendly website and a case manager. It asks for a sample file, a remote-access session, or a $ retainer. It may even unlock one junk file, because anyone who is in contact with the original criminals can buy or borrow the same demo. Then the price rises, the chat dies, or the remote tool installs more malware.
A real public decryptor, when one exists, shows up on an official project page that already existed before your incident. The No More Ransom project is the place people check for those tools. It does not need a deposit in cryptocurrency. It does not need a Session ID. It does not need keepvmn@onionmail.org. If the pitch is “we can decrypt, pay us first,” you are still in the market the ransomware created. There is no public free decryptor known for PicMo. Anyone who says they already have the key is selling the lock again.
9. Payment closes nothing
Paying is not a guarantee. That sentence is not a slogan. It is the recorded experience of victims across ransomware families. The people who send the note can take the money and disappear. They can send a tool that only unlocks a few files. They can come back later and lock the same machine again.
Even when a key arrives, it can fail on some file types, stop halfway, or demand a second payment. The same access that delivered PicMo the first time can still be open. A payment teaches the operators that this victim pays. It does not close the hole they called a misconfiguration. It does not take a leak page down. It does not give you a contract you can enforce. It does not turn 56922DCB6BBA1DBB.jHznjwAp back into 1.jpg by magic if they decide not to finish the job.
If someone later tells you that 100% of paying victims got everything back, ask for a public source that is not the person selling the key. You will not get one that you should trust. Until a trusted project publishes a decryptor, treat any site that says “we already have the PicMo key” as a second sales pitch. Treat any site that says a public family tool already unwraps this sample the same way.
What To Do If Your Files Have Random Names
Do not pay. Do not write to keepvmn@onionmail.org. Do not install Session in order to reach the people who wrote the note. Do not invent or hunt a Session ID because the published note left that field blank. Do not hunt a Tor leak site. Do not send a “test file” to that inbox. Do not ask for a price. The chat is the attacker’s storefront. If you already sent a message before you found this page, stop there. Do not send more files. Do not pay a deposit to “hold the price.”
STEP 1: Use Rkill to terminate suspicious programs.
In this first step, we will download and run Rkill to terminate suspicious programs that may be running on your computer.
RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies that stop us from using certain tools.
Download Rkill.
You can download RKill to your computer from the below link. When at the download page, click on the Download Now button labeled iExplore.exe. We are downloading a renamed version of Rkill (iExplore.exe) because some malware will not allow processes to run unless they have a certain filename.
RKILL DOWNLOAD LINK (The above link will open a new page from where you can download Rkill)
Run RKill.
After downloading, double-click the iExplore.exe icon to kill malicious processes. In most cases, downloaded files are saved to the Downloads folder. The program may take some time to search for and end various malware programs.
When it is finished, the black window will close automatically and a log file will open. Do not restart your computer. Proceed to the next step in this guide.
STEP 2: Use Malwarebytes to remove Ransomware and Unwanted Programs
In this second step, we will install Malwarebytes to scan and remove any infections, adware, or potentially unwanted programs that may be present on your computer.
Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.
Download Malwarebytes
Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.
(The link opens in a new page where your download will start)
Install Malwarebytes
When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.
Follow the On-Screen Prompts to Install Malwarebytes
The setup wizard will walk you through a few quick screens:
Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.
Malwarebytes will now install on your device. This usually takes under a minute.
When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.
On the final screen, click Open Malwarebytes to launch the program.
Enable “Scan for Rootkits”
Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.
In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.
Done? Click “Dashboard” in the left pane to return to the main screen.
Start the Scan
Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.
Wait for the Scan to Finish
The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.
Quarantine the Detected Threats
When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.
Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.
Restart Your Computer
Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.
STEP 3: Use HitmanPro to remove Rootkits and other Malware
In this third step, while the computer is in normal back, we will download and run a scan with HitmanPro to remove Trojans, rootkits, and other malicious programs.
HitmanPro is a second-opinion scanner — it’s designed to catch what your main antivirus might have missed. Instead of relying on a single detection engine, it checks the behavior of files in the locations where malware usually hides. Anything suspicious gets sent to the cloud, where it’s analyzed by two of the best antivirus engines available: Bitdefender and Kaspersky.
Good news: scanning is completely free, with no limits. You only need a license when it’s time to remove what was found — and even then, you can activate a free one-time 30-day trial to clean your PC at no cost. (A full license is $24.95 per year for 1 PC.)
Download HitmanPro
Click the button below to download HitmanPro. Remember — the scan is free, so you have nothing to lose by checking your PC.
When the download finishes, open your Downloads folder and double-click the file: “hitmanpro.exe” on 32-bit Windows, or “hitmanpro_x64.exe” on 64-bit Windows.
If a User Account Control pop-up asks whether HitmanPro can make changes to your device, click “Yes” to continue.
Follow the On-Screen Prompts
On the HitmanPro start screen, click “Next” to begin the system scan. No lengthy setup required — it goes straight to work.
Wait for the Scan to Finish
HitmanPro will now check your computer for malicious programs. This usually takes just a few minutes thanks to its cloud-based scanning.
Review the Results and Click “Next”
When the scan is done, HitmanPro will show you everything it found. Click “Next” to remove the detected threats.
Click “Activate Free License”
To remove the malicious files, click the “Activate free license” button. This starts your free 30-day trial — no payment details needed — and unlocks the full cleanup.
When the removal is complete, HitmanPro will show a summary of everything it cleaned. Click Next, then click Reboot if prompted. If there’s no reboot prompt, just click Close — your PC is clean.
STEP 4: Use AdwCleaner to remove Malicious Browser Extensions and Adware
In this next step, we will use AdwCleaner to remove malicious browser policies and unwanted browser extensions from your computer.
AdwCleaner is a free on-demand scanner that specializes in adware, browser hijackers, and unwanted toolbars — the exact threats that mainstream antivirus programs often miss. It also includes tools that repair the damage malware leaves behind, like hijacked browser settings and malicious policies. It’s a quick scan that’s well worth running.
Download AdwCleaner
Click the button below to download AdwCleaner — it’s free, portable, and requires no installation.
Open your Downloads folder and double-click the file named “adwcleaner_x.x.x.exe“. There’s no installation — the program starts right away.
If Windows asks whether you want to allow AdwCleaner to run, click “Yes“. When the license agreement appears, click I agree to continue.
Enable “Reset Chrome policies”
This setting removes malicious browser policies — a trick malware uses to lock your browser settings so you can’t change them back. Click “Settings” on the left side of the window, then turn on “Reset Chrome policies“.
Start the Scan
Click “Dashboard” on the left side of the window, then click the “Scan” button.
Wait for the Scan to Finish
AdwCleaner will now check your computer for adware and other malware. This usually takes only a few minutes — it’s one of the fastest scanners around.
Quarantine the Detected Threats
When the scan finishes, AdwCleaner will list everything it found. Click the “Quarantine” button to remove all the malicious items at once.
Click “Continue” to Finish the Cleanup
Save any open work first — AdwCleaner needs to close your open programs before it can clean. When you’re ready, click the “Continue” button.
AdwCleaner will now delete all detected malware from your computer. If it asks you to restart your PC, allow it — your computer will be clean when you log back in.
STEP 5: Perform a final check with ESET Online Scanner
This final step involves installing and running a scan with ESET Online Scanner to check for any additional malicious programs that may be installed on the computer..
ESET Online Scanner is a free second-opinion scanner that performs a deep, full-system check for viruses, trojans, rootkits, and other malware. We use it as the final step because it’s thorough — if anything slipped past the previous scans, ESET will find it. A clean result here means your computer is malware-free.
Download ESET Online Scanner
Click the button below to download ESET Online Scanner.
When the download finishes, open your Downloads folder and double-click “esetonlinescanner.exe“.
Install ESET Online Scanner
On the start screen, select your language from the drop-down menu and click Get started.
On the Terms of use screen, click Accept.
Choose your preferences for the Customer Experience Improvement Program and the Detection feedback system (either choice is fine), then click Continue.
Start a Full Scan
Click Full Scan — this checks your entire computer, not just the common hiding spots.
Select Enable for Detection of Potentially Unwanted Applications — this lets ESET catch adware and bundled junk programs, not just viruses. Then click Start scan.
Wait for the Scan to Finish
ESET will now check every file on your computer. Because it’s a full scan, this can take a while — often an hour or more, depending on how much data you have. Leave it running in the background and check on it from time to time.
Review the Results
When the scan completes, the Found and resolved detections screen appears. Any threats found were automatically cleaned and quarantined — there’s nothing extra you need to do. Click View detailed results if you want to see exactly what was removed.
If ESET found nothing — congratulations, your computer has passed the final check and is malware-free.
STEP 6: Restore the files encrypted by ransomware
Unfortunately, in most cases, it’s not possible to recover the files encrypted by this ransomware virus because the private key which is needed to unlock the encrypted files is only available through the attackers. However, below we’ve listed three options you can use to try and recover your files.
Make sure you remove the malware from your computer first, otherwise, it will repeatedly lock your system or encrypt files. If you suspect that your computer is still infected with malware, you can run a free scan with Emsisoft Emergency Kit.
Option 1: Search a decryption tool for this ransomware
The cybersecurity community is constantly working to create ransomware decryption tools, so you can try to search these sites for updates:
Option 2: Use EaseUS Data Recovery Wizard Free to recover the encrypted files
EaseUS Data Recovery Wizard Free can restore files and repair corrupted files with simple clicks. Its powerful scanning algorithms can identify and retrieve huge file type library, including all of the popular video files, audio files, photos, and document formats. While the free version only allows you to recover 2 GB of data, this can be helpful to see if the recovery is possible and restore back the most important files from your computer.
Download EaseUS Data Recovery Wizard Free.
You can download EaseUS Data Recovery Wizard Free by clicking the link below.
Double-click on the EaseUS Data Recovery Wizard Free setup file.
When EaseUS Data Recovery Wizard Free has finished downloading, double-click on the setup file to install EaseUS Data Recovery Wizard on your computer. In most cases, downloaded files are saved to the Downloads folder.
You may be presented with a User Account Control pop-up asking if you want to allow EaseUS to make changes to your device. If this happens, you should click “Yes” to continue with the EaseUS Data Recovery Wizard Free installation.
Follow the on-screen prompts to install EaseUS Data Recovery Wizard.
When the EaseUS Data Recovery Wizard installation begins, click on the “Install Now” as seen in the image below.
When your EaseUS Data Recovery Wizard installation completes, click the “Start Now” button to start the program.
Select a location to start recovering the encrypted files.
Choose the drive or folder where you are the encrypted files that you want to recover and click “Scan“.
Wait for the EaseUS Data Recovery Wizard scan to complete.
EaseUS Data Recovery Wizard will now scan your computer files that can be restored. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
Find the files you want to recover.
When the EaseUS Data Recovery Wizard scan is finished scanning it will show a screen that displays the files that can be recovered. This tool can recover a lot of data, use the “Filter” button to quickly filter specific file types and find the files that you want to recover.
Click the “Preview” button or double-click on a file for a full preview.
Select your files and click “Recover”.
Finally, select the the files you want to recover and click “Recover“. Choose a safe location to save all the files. The free version only allow you to recover 2 GB of data, however, this will allow you to recover the most important files and see if EaseUS Data Recovery Wizard can correctly recover them.
Option 3: Try to restore your files with ShadowExplorer
This ransomware will attempt to delete all shadow copies when you first start any executable on your computer after becoming infected. Thankfully, the infection is not always able to remove the shadow copies, so you should continue to try restoring your files using this method.
Download ShadowExplorer.
You can download ShadowExplorer from the below link.
Double-click on the ShadowExplorer-x.x-setup file to start the installation process, then follow the on-screen promts to install this program.
Select snapshot date.
Open ShadowExplorer and then from the top bar select the drive where the files that you want to save are located, then select from the snapshot available one previous to this infection.
Export the files that you want to recover.
Once you have found a copy of the original file or folder, right-click on it and the select “Export”. A window will prompt you where you want to save the file or folder.
Keep every random name exactly as it is. Do not bulk-rename 56922DCB6BBA1DBB.jHznjwAp back to 1.jpg, or 3A366BA02AEE184C.jHznjwAp back to whatever you think it used to be. Guessing the old title on paper is fine if you need a list of what was hit. Writing those guesses back onto the files is not a repair. It can make a later trusted tool worse, not better.
Keep the shared extension as evidence, even if it is not .jHznjwAp on your machine. PicMo generates a fresh random tail per attack and then stamps the whole pile with it. A different ending does not make this a different problem.
Keep How To Restore Your Files.txt with the locked files. That note is how you prove this was PicMo and not a different locker that only stole a similar help-file title. The mailbox keepvmn@onionmail.org is evidence. The blank Session line is evidence. The training-and-misconfiguration speech is evidence. The Tor leak threat is evidence. They are not instructions you should carry out.
If a later email from keepvmn@onionmail.org finally names a $ figure, that is still the same shop. If a later email or a Session account offers a “real” ID because the note left that field empty, that is still the same shop. If someone claims they can already decrypt these random-name files for a fee, they are selling a guess, not a key. Do not answer. Do not complete their checkout. Do not help them fix the flyer.
The Bottom Line
PicMo ransomware is a locker that hides the catalog, stamps the pile with one random extension, and then talks like a consulting firm. It replaces the original filename with a hex-like string and appends a shared random tail for that attack. In one analyzed sample, 1.jpg became 56922DCB6BBA1DBB.jHznjwAp. The same folder can also show 3A366BA02AEE184C.jHznjwAp, 0C81E4F917AA2201.jHznjwAp, and B7D12A90EE44C813.jHznjwAp. Your ending may differ. The shared-stamp habit does not. The note is How To Restore Your Files.txt. It calls itself a ransomware that prioritizes reputation. It blames a corporate misconfiguration. It sells paid training and a security test. It tells you not to go to the police. It threatens a Tor leak site for stolen data. It wants Bitcoin and a private chat. It does not print a $ amount or a BTC amount.
The contacts in the note are Session, with no Session ID printed in the published sample, and keepvmn@onionmail.org. There is no public free decryptor known for this strain. Do not take a “we recovered PicMo” pitch at face value. Do not take a “public locker tool already works on this sample” pitch either.
Do not pay. Do not write to that mailbox. Do not install Session for them. Do not hunt a .onion. Do not rename the pile in bulk. If you take one sentence with you, take this. A folder of hex-like names that all share one random ending, plus How To Restore Your Files.txt, is ransomware on the first sighting. Treat it that way before anyone in that inbox names a $ figure.
10 Rules to Avoid Online Scams
Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.
Stop and verify before you click, log in, download, or pay.
Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).
If you already clicked: close the page, do not enter passwords, and run a malware scan.
Keep your operating system, browser, and apps updated.
Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.
If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.
Use layered protection: antivirus plus an ad blocker.
Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.
If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.
Install apps, software, and extensions only from official sources.
Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.
If you already installed something suspicious: uninstall it, restart, and scan again.
Treat links and attachments as untrusted by default.
Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.
If you entered credentials: change the password immediately and enable 2FA.
Shop safely: research the store, then pay with protection.
Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.
If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.
Crypto rule: never pay a “fee” to withdraw or recover money.
Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.
If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.
Secure your accounts with unique passwords and 2FA (start with email).
Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.
If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.
Back up important files and keep one backup offline.
Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.
If you suspect infection: do not connect backup drives until the system is clean.
If you think you are a victim: stop losses, document evidence, and escalate fast.
Move quickly. Speed matters for disputes, account recovery, and limiting damage.
Stop payments and contact: do not send more money or respond to the scammer.
Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
Scan your device: remove suspicious apps or extensions, then run a full malware scan.
Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.
These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.
Hello! I'm Lapain Epuran, your go-to source for detailed and honest product reviews. From tech gadgets to miracle cures, I provide insights to help you make informed choices. Join me as we discover what's truly worth your time and money.