Home Malware Programs Ransomware XiaoBa 2.0 Ransomware

XiaoBa 2.0 Ransomware

Posted: July 27, 2018

Threat Metric

Threat Level: 10/10
Infected PCs: 166
First Seen: October 30, 2017
Last Seen: May 2, 2022
OS(es) Affected: Windows

The XiaoBa 2.0 Ransomware is the newest variant of XiaoBa Ransomware, a file-locker which, unfortunately, has proven to be uncrackable and its victims can't rely on free decryption software to assist them. The situation with the XiaoBa 2.0 Ransomware is identical, and any user who has had their files locked up by the XiaoBa 2.0 Ransomware will need to look for alternative file recovery software and methods that might not always yield a complete success.

It is likely that the XiaoBa 2.0 Ransomware is being spread via fake e-mail messages, which are distributed via mass e-mail spam campaigns. The messages might contain a file attachment whose execution could lead to the launch of the XiaoBa 2.0 Ransomware, therefore allowing the file-locker to carry on with the attack. Naturally, the XiaoBa 2.0 Ransomware's authors want to cause as much damage as possible, and that's why it isn't a surprise that their file-encryption Trojan targets a broad range of file formats. It is capable of encrypting documents, images, archives, backups, databases, videos, songs, and also more obscure file formats such as the ones associated with professional software suites. Whenever a file is encrypted by the XiaoBa 2.0 Ransomware, the threat will add the '.[xiaoba_666@163.com]Encrypted[RANDOM ID].XIAOBA' extension to its name.

Naturally, the authors of the XiaoBa 2.0 Ransomware are ready to offer a remedy, and their offer is found in the file 'HELP_SOS.ht,' which states that the victims must send 0.5 Bitcoins to the attacker's wallet, and then contact xiaoba_666@163.com for further details. They also offer to unlock one file for free to prove that they're trustworthy, and while we advise you to take advantage of this offer, we assure you that sending money to cybercriminals is a terrible idea.

The suggestion is to take care of the problem via legitimate methods. Start by removing the XiaoBa 2.0 Ransomware with the use of a trustworthy and up-to-date anti-malware application. After this, you should try to use 3rd-party file restoration software suites that might be able to get some of your data back.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to XiaoBa 2.0 Ransomware may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Windows\CurrentVersion\Run\XiaoBa
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.