Everbe 2.0 ransomware is a file-encrypting malware program that has several variants out in recent times.

Threat Description:

Everbe 2.0 is a crypto-malware that encrypts files on the target computer system and demands ransom for unlocking the files. It is the latest version of Everbe ransomware which was first attacked in March 2018 and uses “.everbe” extension to lock the files.

Like its other variants, Everbe 2.0 is also using strong encryption algorithms AES and RSA to encrypt data and lock them. But this time the extension used is “.NOT_OPEN”. Like if the original file named as “brightside.jpg” then after encryption it will become “brightside.jpg.NOT_OPEN”. This means your file is encrypted and no more accessible for any applications.

A ransom note named as “txt _HOW_RECOVERY_FILES” is dropped on the desktop and the folders where encryption is been done. This text file contains the ransom message and the contact email address of the hackers here is “notopen@cock.li” or “tryopen@cock.li” via which victims can communicate. For now there is no any decryption possible for the file encrypted by Everbe 2.0 Ransomware.

Everbe 2.0 ransomware Ransom note reads as:


Your files are NOT damaged! Your files are modified only. This modification is reversible.
The only 1 way to decrypt your files is to receive the decryption program.

To receive the decryption program write to email: notopen@cock.li
And in subject write your ID: ID-[redacted 10 hex]
We send you full instruction how to decrypt all your files.
If we do not respond within 24 hours, write to the email: tryopen@cock.li

Free decryption as guarantee.
We guarantee the receipt of the decryption program after payment.
To believe, you can give us up to 3 files that we decrypt for free.
Files should not be important to you! (databases, backups, large excel sheets, etc.)

Everbe 2.0 Distribution methods:

Ransomware are mostly spreading through spam mail attachments that may contains macros, malicious links or auto-activation codes. These mails appear to be very sophisticated as they may entitled as any invoice, job application, fax or so on.

Once the user open the links or download the attachment then the payloads of the virus gets downloaded to the computer system. And silently initiates it activities from background. Besides this, there are many other sources through which ransomware-laden malware program can attack your computer or device. To known more about them in details read What is Ransomware and how it works?

What to do when infected with Everbe 2.0 Ransomware?

Many security experts have analysed the samples of Everbe 2.0 ransomware and is detected by some renowned anti-malware programs like Ransomware Defender. Well some of the AV detections have found “NOT OPEN LOCKER” virus as a variant of Everbe ransomware. And various other detections carried on different infected systems were:

  • Generic.Ransom.Everbe.3D90239A;
  • HEUR/AGEN.1031998
  • Win32:Malware-gen;
  • Trojan.Win32.Generic!BT;
  • W32/Filecoder.NQU!tr;
  • W32/Trojan.YOEK-2696.

Everbe 2.0 ransomware is a severe threat as its decryption code is still not found by the experts. Despite that, security experts are recommending victims not to pay the ransom in lure get the decryption key. As there is no any guarantee that even after paying the ransom the hackers unlock the files. Doing so will lead to both money and data loss. Also paying the ransom only encourages such ransom authors to carry out more such conducts.

The better way to deal with Everbe 2.0 crypto-malware is to remove it using anti-malware tool and them attempt recovery of encrypted data. As till the infection is present on the system, it will not let you perform any recovery. And even it will keep on encrypting any new files or data inserted through USB drives. To avoid this, experts recommend not to use the infected system as it can lead to more damage.

How To Remove Everbe 2.0 Ransomware virus Without Paying Ransom

In this guide, you will find removal instruction of Everbe 2.0 Ransomware virus both manually and using anti-malware tool. At times, virus does not allow the installation or scanning of anti-virus program, so you need to switch to “safe mode with networking”. After that you can try recovery of your data if you have any backup or we have listed some methods which may help you to recover some of your data.

Use HitmanPro.Alert To Remove Everbe 2.0 Ransomware(Recommended)”


HitmanPro.Alert is an advanced anti-malware program that takes on proactive approach towards threat behavior and its activities. Running HitmanPro.Alert on your computer will provide your real-time status, checks the browser integrity and alerts or any suspicious activity. So that you can have a safe browsing and online transactions. Read the full review of HitmanPro.Alert here.

Steps To Install And Run HitmanPro.Alert

  • Click on the provided link to download HitmanPro.Alert anti-malware;
    HitManPro.Alert Step1

    HitManPro.Alert Step1

  • Now, open the download folder to locate “hmpalert3”;
    HitmanPro.Alert Step 2

    HitmanPro.Alert Step 2

  • Click on it, to begin the installation;
  • It will ask your User Account control, if prompted click on “yes”; The download should begin shortly. HitmanPro.Alert window will appear, where you need to choose the options:
HitManPro.Alert Step3

HitManPro.Alert Step3

  • Choose Protection level as Maximum
    And tick the other boxes and finally click on “Install”.
    HitmanPro.Alert only takes 5MB of your memory and is very quick to install.
HitManPro.Alert Step4

HitManPro.Alert Step4

  • After the installation is complete, the scan will start. First scan may take up some minutes, as it will scan the whole computer.
    HitmanPro.Alert step 4

    HitmanPro.Alert step 4

  • The scan results are here. Carefully look down the list. You can here, the scan has found 1 Riskware and thousands of traces which can be risky.
    HitmanPro.Alert step 5

    HitmanPro.Alert step 5

  • You can select the threat to delete, quarantine, ignore or, mark as safe. If you want to remove all the threats, then simply click on the “Next” button below.
    HitmanPro.Alert step 6

    HitmanPro.Alert step 6

  • HitmanPro.Alert first creates a restore point and then starts the removal process. This helps to recover from any damage.
    HitmanPro.Alert step 7

    HitmanPro.Alert step 7

So, by performing the above steps, you can get rid of Everbe 2.0 Ransomware.

Manually Find And Remove Everbe 2.0 (Recommended Only For Advanced Users)

The manual steps guided below are the links separately made with caution, to avoid any confusion to our readers. Please follow the links below and perform them one by one. If you are going for the manual removal process, then we recommend you to print/download these instructions. Else open it from another uninfected computer or laptop and follow step-by-step manual removal instruction. Windows OS PDF Guide.

Method 1: Remove Everbe 2.0 Ransomware and its associated files from the computer through safe mode with command prompt.

  1. Reboot your computer toSafe Mode with Command Prompt”
  2. End malicious process from “Task Manager
    1. Disable Auto-Startup Apps
    2. Remove Unwanted Programs From Scheduled Tasks
    3. Delete Temp Data and Prefetch
    4. Deleting “Registry Entries created by the Ransomware threat
  3. Deep Scan the infected computer to ensure complete removal (Recommended)

Click here to perform the step-by-step manual removal procedure.

Method 2: Remove Everbe 2.0 Ransomware virus using System Restore Procedure

After that, the ransomware threat should go, but if it is still there. Then you need to try another method which is the “System Restore”. Click here to perform System Restore in Windows OS.

How to Restore the Encrypted Files?

Here is a separate article that guides users of various methods to recover their encrypted files. However, the ransomware makes sure the files may not be unlocked by other tools, but you should try them out.

Click here to know How you can restore the encrypted file.

More From Unboxhow