How to remove Proton ransomware

Proton ransom note:

				~~~ Proton ~~~
    What happened?
    We encrypted and stolen all of your files.
    We use AES and ECC algorithms.
    Nobody can recover your files without our decryption service.

    How to recover?
    We are not a politically motivated group and we want nothing more than money.
    If you pay, we will provide you with decryption software and destroy the stolen data.

    What guarantees?
    You can send us an unimportant file less than 1 MG, We decrypt it as guarantee.
    If we do not send you the decryption software or delete stolen data, no one will pay us in future so we will keep our promise.

    How to contact us?
    Our Telegram ID: @ransom70
    Our email address: Kigatsu@tutanota.com
    In case of no answer within 24 hours, contact to this email: Kigatsu@mailo.com
    Write your personal ID in the subject of the email.

Your personal ID: [REDACTED]

    Warnings!
  - Do not go to recovery companies, they are just middlemen who will make money off you and cheat you.
    They secretly negotiate with us, buy decryption software and will sell it to you many times more expensive or they will simply scam you.
  - Do not hesitate for a long time. The faster you pay, the lower the price.
  - Do not delete or modify encrypted files, it will lead to problems with decryption of files.

This is the end of the note. Below you will find a guide explaining how to remove Proton ransomware and decrypt .kigatsu files.

What is Proton ransomware?

Proton ransomware, sometimes also known as Kigatsu ransomware, is a computer virus that encrypts all files on your computer. This behavior is characteristic to ransomware. This type of viruses holds your files ransom, that is to say, demand payment to decrypt them.
Proton renames the files after encrypting them. It appends the hacker’s e-mail, the victim’s unique ID, and .kigatsu file extension to the end of each name. For example, a file named “income.xlsx” could be renamed to “income.xlsx.[Kigatsu@tutanota.com][3A67DF03].kigatsu”. This is why this virus is also known as Kigatsu ransomware.
The virus also leaves a ransom note, “README.txt”, which contains instructions for the victim. You may read it on the image above, however, you will not find anything particularly noteworthy there. Unfortunately, the hackers chose not to reveal how much money they want for decryption; they simply tell the victim to contact them.
Generally speaking, it is not recommended to pay these criminals, and even contacting them could be risky. Quite often, the hackers simply disappear after receiving payment, without decrypting anything at all. Alternatively, they might return the files, but attack you again sometime later.
This is why we encourage you to learn about other ways to remove Proton ransomware and decrypt .kigatsu files. The guide below is a good place to start.

Scroll to top